Live data from Hacker News

Show HN: Your Social Media Fingerprint (maybe NSFW)

robinlinus.github.io

41–50 of 258 posts

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#41
post #10

Nice, so now by using this I have an NSFW site logged in my workplace's DNS log. Be careful if your employer checks such things.

If you had done your job instead of reading HN, there would be no problem!

100+ days old account, love it!

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#43

Very good demonstration thank you. Some interesting (an unethical) potential marketing opportunities here. For example, at the bottom of articles only show share actions for social platforms they are logged into.

Why is showing only pertinent share options unethical? Or is it the cross-site circumvention that you found unethical?

Ethics are subjective, some people may find the fact you're identifying what websites the user is logged into creatively in this way unethical as it divulges what services the user uses without them necessarily consenting/realising you have access to this information.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#44
post #8

Very good demonstration thank you. Some interesting (an unethical) potential marketing opportunities here. For example, at the bottom of articles only show share actions for social platforms they are logged into.

Not logged in != doesn't have an account

Sure, but if you identify they are logged into FB and Reddit, maybe only show those two options. If you can't determine they are logged into any service show them all.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#45
post #20
post #12

I have uBlock Origin in 3rd party deny mode and privacy badger and it still detects me as logged in to HN, Reddit, Slack and Stack Overflow. EDIT: Following diegorbaquero's advice[0] solved it 0: https://news.ycombinator.com/item?id=12692485

I had that and enabled the "Fanboy Annoyance list" in uBlock Origin and now it says I'm on none of the platforms.

Keep in mind that this is an accidental fix due to a suboptimal naming choice by the website author.

A better solution would be to disable third-party cookies in your browser settings.

Sending the do not track request generally increases the ability to fingerprint you, as adversaries tend to ignore its purpose anyway.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#47

This is why I use 'browser isolation', which is a way to separate different types of surfing activity into different buckets. Currently the best way to do this in Firefox is to create multiple profiles, or in Chrome, you can simply add a different user/persona. Having one profile, or even an entire dedicated browser just for Twitter/FB ensures the login is not spilled over into other sites. If you're surfing the web…

I was horrified to find I'm logged in to FB with my 'common' cookie jar. At least that explains the recently increased accuracy of its targeted ads.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#48

Well its good to see its partly wrong for me. It shows HN correctly, but also shows me logged in to Facebook and Tumblr, not correct. And not logged in to gmail, which I am. Still, its a dangerous flaw.

How is being showed logged in any good when it's not true? Wasn't there also something about facebook creating accounts for people based on thier 3rd party promotion link ins and what not?

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#49

In Chrome: Settings > Privacy > Content Settings > Tick 'Block third-party cookies and site data' Also set 'Send a "Do Not Track" request with your browsing traffic' And install uBlock Origin, ofc.

3rd party cookies should be disabled by default in all browsers. It significantly improves your privacy with minimal impact.

After many years of blocking 3rd party cookies the only thing that's broken for me is my bank's bill pay system, which is an iframe of a 3rd party service.

Re: Show HN: Your Social Media Fingerprint (maybe NSFW)

#50

In Chrome: Settings > Privacy > Content Settings > Tick 'Block third-party cookies and site data' Also set 'Send a "Do Not Track" request with your browsing traffic' And install uBlock Origin, ofc.

Personally, I don't set the DNT header. You have no way of knowing if any sites are actually going to comply, and it actually provides an extra datapoint to fingerprint you with.

But isn't it better to at least ask instead of not asking at all?
Post reply on HN