Live data from Hacker News

Websites can now fingerprint a device when multiple browser instances are used

arstechnica.co.uk

71–80 of 154 posts

Re: Websites can now fingerprint a device when multiple browser instances are used

#71
post #69

Well, if we can't have privacy, at least lets make it clear that we DO want it and do what we can to have it. Not being able to defend ourselves doesn't mean that we should give up. A crowd can gather in front of a building and demand changes, unarmed and shouting. They may be heard or not, but still they fight. Sometimes the crowd is really huge and the other side has no option but to hear. Use Firefox. Use uBlock O…

Do all of this and you'll be fingerprinted as being in the fringe minority of privacy-craving web users, so for this effort to succeed, it might help for there to be some form of orchestration/automation and education to achieve all of these together with a wide population of people. That'd be a startup or nonprofit project, not necessarily anything any of us can individually do and not stick out like a sore thumb un…

This isn't about being invisible. 99.9% of the people can't, including most of the HN crowd. It has become literally almost impossible. This is about making a statement for what you believe and fighting for digital world we want.

You can always use techniques such as blending in if you really must, tools such as Tails or QubesOS.

If they want to put a red pin on me with the words activist and "conscious of us", let them while and if they can.

Edit: changed the word "secure" to "invisible" because they are different things entangled in this scenario.

Re: Websites can now fingerprint a device when multiple browser instances are used

#72
This is one of the reasons I disable JavaScript.

The web is an interlinked web of documents called pages. It's not a distributed application platform: although it can be twisted into that, it turns out that no-one actually carefully considered all the potential security, privacy & performance implications of doing that — and it's no surprise that the security, privacy & performance of the single-page app web is abominably atrocious.

Re: Websites can now fingerprint a device when multiple browser instances are used

#73
post #64

How is this news? The adult and casino industries have been using this technology for years now to avoid fraud.

What fraud attack do those industries share which is prevented by fingerprinting?

To address your question, the technique is novel and more accurate.

Re: Websites can now fingerprint a device when multiple browser instances are used

#74
post #26
post #12

I note without surprise that most of this tracking leverages JavaScript. When do we say that enough is enough? When do we finally agree that the web was better without JavaScript tracking us everywhere we go, and when do we finally admit that not all ideas (JavaScript) were good ideas? My browser works against me these days. Sad times.

It is similar to macros in Word documents

Is it, though? To the best of my knowledge, macros don't execute by default, silently, and in so doing facilitate my being tracked by people wanting to sell me generic brand pharmaceuticals.

Re: Websites can now fingerprint a device when multiple browser instances are used

#75
post #18

Earlier quoted context omitted.

I understand the view and pains of the webdeveloper, but quite frankly I think privacy issues are way more important. Not even in the same order of magnitude. Your comment feels like a restaurant saying 'Ok, I understand cleanliness is important, but as a cook washing dishes all the time is really annoying so I only wash them if customers ask for clean dishes'

Haha, good one, but joking aside, I would rather prefer that the dishes can never get dirty, no matter what. I don't think it's in Google best interest to add anti tracking features into Chrome browser (and same with MS and Apple). So for now on we must bring our own cloth to clean out the dishes or go to another restaurant where the dishes are always clean. The problem is that it's impossible to change the current b…

> Haha, good one, but joking aside, I would rather prefer that the dishes can never get dirty, no matter what.

Using JavaScript to deploy content-focused websites is like a restaurant which uses its cookpots for urinals: sure, it can be done hygienically, but it's Just Wrong.

Re: Websites can now fingerprint a device when multiple browser instances are used

#76
post #35

Earlier quoted context omitted.

Let me address the "normal" web developers then: Don't use cookies. Don't use Javascript. And to use your own words: "It would be better to add the functionality you are suggesting as an option and not by default, so people, who understand the "risks" of not viewing some sites properly in favor of more privacy, will turn it on by themselves." Turning off all the cruft makes websites MORE usable not less. Plain text,…

Given that popular uses for the Web today include social networking, e-commerce, web apps, and online access to services like banking, I think the idea that sites should just display static information and should work better without JS and cookies is at least a decade out of date. Pushing for a very limited web is a battle that was lost long ago. What needs to stop is the idea that just because JS is useful for inter…

> Given that popular uses for the Web today include social networking, e-commerce, web apps, and online access to services like banking, I think the idea that sites should just display static information and should work better without JS and cookies is at least a decade out of date.

Do you realise that every item on your list wasn't just possible but flourished without JavaScript, and works fine without third-party cookies?

JavaScript is a cancer on the web, a metastasised extension language which is swallowing up what was a thriving hypertext infrastructure.

Re: Websites can now fingerprint a device when multiple browser instances are used

#77
post #18

Earlier quoted context omitted.

I understand the view and pains of the webdeveloper, but quite frankly I think privacy issues are way more important. Not even in the same order of magnitude. Your comment feels like a restaurant saying 'Ok, I understand cleanliness is important, but as a cook washing dishes all the time is really annoying so I only wash them if customers ask for clean dishes'

Haha, good one, but joking aside, I would rather prefer that the dishes can never get dirty, no matter what. I don't think it's in Google best interest to add anti tracking features into Chrome browser (and same with MS and Apple). So for now on we must bring our own cloth to clean out the dishes or go to another restaurant where the dishes are always clean. The problem is that it's impossible to change the current b…

The majority of the web works fine without any Javascript at all.

Re: Websites can now fingerprint a device when multiple browser instances are used

#78
post #12

I note without surprise that most of this tracking leverages JavaScript. When do we say that enough is enough? When do we finally agree that the web was better without JavaScript tracking us everywhere we go, and when do we finally admit that not all ideas (JavaScript) were good ideas? My browser works against me these days. Sad times.

Throwing web-interactivity (via Javascript) away today is like throwing your computer away. Computers help you be more productive, but it also helps the people who want to profile you. What's the alternative? If it's not Javascript, any functionality that offers access to the hardware (via however many layers) to "apps" from the "cloud" can be exploited this way. Maybe we should disallow hardware access, how will You…

> What's the alternative?

The alternative is cleanly separating web browsing (a passive activity requiring no code execution) and using distributed apps.

I'm not at all against the idea of a common, cross-platform execution environment; I'm 100% against the idea of executing cross-platform code when all I want to do is read an article.

Re: Websites can now fingerprint a device when multiple browser instances are used

#79
post #64

How is this news? The adult and casino industries have been using this technology for years now to avoid fraud.

What fraud attack do those industries share which is prevented by fingerprinting? To address your question, the technique is novel and more accurate.

Charge backs. For a long time those industries were dominated by affiliate programs, and so affiliates would hire firms in other countries to use stolen credit cards to inflate memberships, then charge back after the affiliate got their payout. By using shared networks of the finger prints we were able to identify computers already used for fraud on other sites or our own sites and refuse them the chance to even sign up.

EDIT: Sorry, to be clear, the people using the stolen credit cards didn't charge back, the actual owners of the cards would. But this affected the industries two-fold, first in constantly having to battle with credit card and billing companies that didn't want to provide services for an industry with such a high charge back rate, but it also hurt us in paying out to affiliates who cost us money instead of bringing it in.

Re: Websites can now fingerprint a device when multiple browser instances are used

#80
post #55
post #39

Earlier quoted context omitted.

It makes many more completely usable. Floating headers and footers? Dead. Survey pop-ups? Dead. Pop-ups begging for your email address? Dead. Dumb fading in text and images? Dead. Needless whiz-bang animations? Dead. Site load times? Dramatically reduced. Browsing the web with NoScript is far more pleasant, even if I have to sometimes open a menu to enable a couple domains to make a poorly developed website usable. I…

TIL utilizing the most widely available programming language in the world makes a website "poorly developed."

abusing the most widely available language to destroy the UX makes a website poorly developed.
Post reply on HN