It was at the Securedrop website. How did I end up there ? I read something about Sequoia and encryption and then wanted to see what Securedrop entailed.
Meanwhile I’ve raised the security settings. Still, today someone in this community (?) mentioned that Tor browser does not protect the remote to check for the OS, and now this. Color me surprised.
It isn’t.
Yes it should, through Javascript. https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/26146#note_2649490
Blocking UA access via JS alone is not enough.
Do you have a better source than a 5 y/o comment in an issue?
Trust me, I spent 3 years in the Tor community I know this shit, this thing comes up so often.
Alternatively: https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/41610