How easily can two Tor Browser visits be linked to the same pseudonym in Standard or Safer mode

I read a lot and yet still can’t answer such a simple question: “How easily can two Tor Browser visits[1] be linked to the same pseudonym when it is Standard or Safer mode, where the two visits are using a new clean VM (DispVM from clean default whonix-workstation-dvm).” Or is it even possible (when Qubes OS and the template are not compromised)?

I always use Safest mode. Sadly now a need arised for using a website of a service provider, and that website needs javascript enabled to work. I fear that vising that website with javascript enabled will finally let the fingerprint of my browser to be known, which I always used to keep by using Safest mode. That then in the future, if any need arised for using Tor Browser with javascript enabled, it will be possible for both acts to be linked to the same person.
Keep in mind that the website will be used regularly (couple of times a week), although I will use it with caution and it is also a few minutes a time.

Info: During the visit, only the mouse is used (kloak is now enabled in Qubes R4.3) to press buttons on the website, keyboard is never used and anything is written first on an offline VM then copied and pasted, and acting is not quickly and in a most normal manner.


  1. to the same website or to two different websites that use the same trackers or so “contact each other”. ↩︎

There are a few possible risks I can think of:

  • Your machine’s physical screen size is leaked to the VM. This is something that is solved in non-Qubes-Whonix but is still an issue in Qubes-Whonix. Therefore if you’re using an unusually sized screen (say an ultrawide monitor), that could be used to form a partial fingerprint.
  • Qubes event buffering (the equivalent of Kloak in Qubes OS) is not able to prevent mouse movements from being fingerprinted. Improving this is on the roadmap, but it’s not done yet. See:

https://github.com/QubesOS/qubes-issues/issues/10292\

  • If you have any modifications made to the whonix-workstation-18 template, those could affect your fingerprint, especially if the site is able to compromise your browser and do things like enumerate the list of installed packages. For best results, you should use a whonix-workstation-18 template with no modifications made to it other than the regular installation of software updates.
1 Like