Live data from Hacker News

Facebook can track your browsing even after you've logged out, judge says

theguardian.com

181–190 of 208 posts

Re: Facebook can track your browsing even after you've logged out, judge says

#181
post #15

Firefox has a pretty neat feature I discovered recently: https://wiki.mozilla.org/Security/Contextual_Identity_Projec... It lets you run multiple sessions in one window, where each tab belongs to a specific session with separated cookies and such. I've got a bunch of tabs where I'm logged in to Facebook, another set where I'm logged in to Google and the rest of them where I'm not logged in to either. Of course they c…

The new versions of Safari in iOS 11 and High Sierra have a similar feature by default to prevent tracking. First party cookies work, but third-party cookies are put in a virtual container, so tracking networks that are on NYT and Washington Post can't correlate the cookie. It's a bit more complicated than that in practice, but that's the idea.

Re: Facebook can track your browsing even after you've logged out, judge says

#182
post #15

Firefox has a pretty neat feature I discovered recently: https://wiki.mozilla.org/Security/Contextual_Identity_Projec... It lets you run multiple sessions in one window, where each tab belongs to a specific session with separated cookies and such. I've got a bunch of tabs where I'm logged in to Facebook, another set where I'm logged in to Google and the rest of them where I'm not logged in to either. Of course they c…

Chrome has profiles for this as well. You can also use the PrivateInternetAccess addon which proxies all traffic for that profile alone, and a canvas blocker, in a dedicated Chrome profile. Font fingerprinting is still possible, but beyond that there is no way to associate that profile with anything else.

Re: Facebook can track your browsing even after you've logged out, judge says

#183
post #182
post #15

Firefox has a pretty neat feature I discovered recently: https://wiki.mozilla.org/Security/Contextual_Identity_Projec... It lets you run multiple sessions in one window, where each tab belongs to a specific session with separated cookies and such. I've got a bunch of tabs where I'm logged in to Facebook, another set where I'm logged in to Google and the rest of them where I'm not logged in to either. Of course they c…

Chrome has profiles for this as well. You can also use the PrivateInternetAccess addon which proxies all traffic for that profile alone, and a canvas blocker, in a dedicated Chrome profile. Font fingerprinting is still possible, but beyond that there is no way to associate that profile with anything else.

I wouldn't be so sure. Screen resolution, Machine time, flash version, fonts. Plus several others I forget

Re: Facebook can track your browsing even after you've logged out, judge says

#184

Earlier quoted context omitted.

Could you share a link to this site?

I suppose it was https://panopticlick.eff.org

One thing I don't really like about that site is that it gives browsers worse scores for not unblocking third parties which promise to honor do not track. Surely you're more safe when you don't trust anyone instead of trusting that third parties which honor DNT actually honor it. It kind of reeks of pushing an agenda, which would have been okay (it's the EFF after all) if the tool didn't claim to score your browser on how well it protects you from tracking.

Re: Facebook can track your browsing even after you've logged out, judge says

#185
I don't even know what their logout button does. It puts me on the login page with my profile pic, and it displays the number of notifications I've received while logged out. There is a 'remove account' X overlay placed on the top left corner. I usually click it and hope it does something.

Re: Facebook can track your browsing even after you've logged out, judge says

#186

Earlier quoted context omitted.

Isn't your IP address plus cookies enough to track you?

Yes, but they can be trivially blocked or discarded. My main point is that no advanced fingerprinting tactics can be used so the simple means work in the case of most site-breaking things. Privacy Badger eats CDN cookies - that's actually one of its main features, so it will prevent this kind of thing quite nicely without breaking websites.

The vast majority of people correlate 1:1 with IP address alone, so I'm not sure how effective this is. Nonetheless, that's pretty cool.

Re: Facebook can track your browsing even after you've logged out, judge says

#187

Earlier quoted context omitted.

Like Google Street View already does.

I don't think they were forced. Google is based in the U.S. where it is legal to photograph people in public, yet Google still blurs the faces of those on sidewalks. That and things like license plates seems to me to be them preemptively trying to appease privacy concerns so that support to censor them legally doesn't form.

I believe the principle of the expectation of privacy forced them to blur the faces.

Re: Facebook can track your browsing even after you've logged out, judge says

#188

Earlier quoted context omitted.

It's disingenuous because it reduced a social issue to that of particle physics. It's like me assaulting someone and saying "wow, they sure couldn't handle a collection of atoms exerting momentum on their face", or calling a tornado "some gusts of wind", or other ridiculous things.

That's exactly what the parent commenter means. https://en.wikipedia.org/wiki/Not_even_wrong

Oh...

Re: Facebook can track your browsing even after you've logged out, judge says

#189
post #9

That's not all. In NY state, they ruled that can artist can take pictures of you in your home through your windows: https://fstoppers.com/photojournalistic/supreme-court-rules-...

Well if you don't want photos taken of you through your windows, then why do you even have windows in the first place?

Re: Facebook can track your browsing even after you've logged out, judge says

#190
post #88

The article or the judge (not sure which) suggests using incognito mode. While this will keep browsing history private for a particular session, it's only effective locally. Tracking from the server is still possible either through being logged in or through browser fingerprinting, which is surprisingly accurate. Here's a good demo which uses fingerprinting to show how ineffective incognito mode is: http://www.nothin…

How does a user defend against this, without resorting to a nuclear option like Tor?

The Brave browser has an anti-fingerprinting feature in Preferences -> Shields. It's not enabled by default because of the likelihood of breaking some sites.
Post reply on HN