Finding
The specification promises that fingerprints cannot link sessions, but its mechanism is independent marginal synthesis plus optional Tor routing. That does not establish a coherent whole-client identity or make an absolute unlinkability claim testable.
Evidence
docs/requirements.md:48-60 requires per-session fingerprint variation and states cross-session linkability must not be possible.
docs/decisions.md:9-10 chooses synthesized fingerprint distributions and JA rotation.
docs/requirements.md:71 makes Tor optional.
Real observers correlate joint behavior across UA/OS, TLS and HTTP signatures, JavaScript surfaces, fonts, locale, clocks, storage, DNS, egress, and account activity. Independently plausible attributes can form a globally rare or internally impossible combination. Shared network or application identity can link sessions regardless of surface randomization.
Tor’s own anti-fingerprinting guidance describes reducing distinguishable buckets and notes that making every browser identical is practically impossible; it does not support an absolute guarantee.
Why this matters
The current claim has no adversary, observation scope, baseline, or falsifiable metric. A generator can satisfy every declared marginal distribution while producing a uniquely linkable joint fingerprint.
Required mechanism
- Define the adversary and the observations included in the claim.
- Replace the absolute statement with a measurable linkability/entropy target against a named baseline.
- Generate versioned, coherent whole-client profiles spanning egress, DNS, TLS, HTTP, JavaScript, fonts, locale, clock, and storage.
- Measure cross-layer consistency and anonymity-set size, including repeated-session experiments.
- State explicitly which linkers (account identity, IP reuse, behavior, external storage) are out of scope or mitigated elsewhere.
Finding
The specification promises that fingerprints cannot link sessions, but its mechanism is independent marginal synthesis plus optional Tor routing. That does not establish a coherent whole-client identity or make an absolute unlinkability claim testable.
Evidence
docs/requirements.md:48-60requires per-session fingerprint variation and states cross-session linkability must not be possible.docs/decisions.md:9-10chooses synthesized fingerprint distributions and JA rotation.docs/requirements.md:71makes Tor optional.Real observers correlate joint behavior across UA/OS, TLS and HTTP signatures, JavaScript surfaces, fonts, locale, clocks, storage, DNS, egress, and account activity. Independently plausible attributes can form a globally rare or internally impossible combination. Shared network or application identity can link sessions regardless of surface randomization.
Tor’s own anti-fingerprinting guidance describes reducing distinguishable buckets and notes that making every browser identical is practically impossible; it does not support an absolute guarantee.
Why this matters
The current claim has no adversary, observation scope, baseline, or falsifiable metric. A generator can satisfy every declared marginal distribution while producing a uniquely linkable joint fingerprint.
Required mechanism