Live data from Hacker News

EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

panopticlick.eff.org

11–20 of 37 posts

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#11
post #6

Earlier quoted context omitted.

Spoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.

How about we get together and decide on a common string that all of us can use? We can set our browsers to use that, and our friends' as well. Theoretically, the more people that use the same string, the harder we'll be to track, correct?

That's right, though it's a bit more difficult. Lots of sites use the User-Agent header to determine how to render a page, and may not render it at all if it's an unexpected value. Pages that allow you to install addons to your browsers also use this string to figure out if you're really running the target browser.

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#12
I browse with cookies disabled by default, and when I ran the browser test it said this:

Are Cookies Enabled? No

one in x browsers have this value 3.94

...so according to the EFF's data, almost 1 in 4 people also browse with cookies disabled? I thought I was in an extreme minority, and I know I come across a TON of sites that don't work without cookies or localStorage enabled (which is understandable for when you need to log in or if it's a more "app"-y thing, but for just reading content it's a ridiculous requirement).

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#14
post #6

Earlier quoted context omitted.

For Firefox, you can automatically spoof the UA with a tool like https://addons.mozilla.org/en-US/firefox/addon/random-agent-...

Spoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.

Okay, has someone made an extension that lets me pretend to have the most common set of plugins on the most common version of firefox?

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#15

I browse with cookies disabled by default, and when I ran the browser test it said this: Are Cookies Enabled? No one in x browsers have this value 3.94 ...so according to the EFF's data, almost 1 in 4 people also browse with cookies disabled? I thought I was in an extreme minority, and I know I come across a TON of sites that don't work without cookies or localStorage enabled (which is understandable for when you nee…

It's presumably 1 in 4 people who have tried Panopticlick, which isn't a representative sample of general browsers (for example, a lot of people might try it with Tor Browser or with private browsing mode).

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#16
post #6

Earlier quoted context omitted.

Spoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.

How about we get together and decide on a common string that all of us can use? We can set our browsers to use that, and our friends' as well. Theoretically, the more people that use the same string, the harder we'll be to track, correct?

Tor Browser does that:

https://www.torproject.org/projects/torbrowser/design/

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#17

That was weird, the no-js version didn't work. It just sat there spinning. >Does your browser unblock 3rd parties that promise to honor Do Not Track? X no What, why would I unblock those? Edit: Thanks HN for deleting the fancy X unicode!

With certain rare configurations (if you have a domain-based blacklist blocker and javascript disabled) this may occur. I suggest turning your js back on just for the test.

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#18

That was weird, the no-js version didn't work. It just sat there spinning. >Does your browser unblock 3rd parties that promise to honor Do Not Track? X no What, why would I unblock those? Edit: Thanks HN for deleting the fancy X unicode!

> That was weird, the no-js version didn't work. It just sat there spinning.

What extensions do you have installed? There's a known and unfixable issue with browsers that both block JS and absolutely block all requests to tracking domains (eg AdAway, which modifies /etc/hosts).

> What, why would I unblock those?

To incentivise better behaviour by web publishers and advertisers!

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#19
post #6

Earlier quoted context omitted.

Spoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.

Okay, has someone made an extension that lets me pretend to have the most common set of plugins on the most common version of firefox?

Yes, everyone knows you can change the user agent string, but how do you change the list of plugins returned by the browser? Do you have to actually patch the binary?!

Re: EFF's Panopticlick 2.0 Launches with Tracker Protection Tests

#20
post #6

Earlier quoted context omitted.

Spoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.

How about we get together and decide on a common string that all of us can use? We can set our browsers to use that, and our friends' as well. Theoretically, the more people that use the same string, the harder we'll be to track, correct?

Yes! How would you say "I'm a generic modern browser that can interpret HTML5. Do not send me flash."
Post reply on HN