Live data from Hacker News

Block Fingerprinting with Firefox

blog.mozilla.org

341–350 of 411 posts

Re: Block Fingerprinting with Firefox

#341

I worked in the ad industry. Every web-browser including brave, tor,safari is uniquely identifiable even on same hardware. All the public computer researchers and browser vendors are years behind the techniques to fingerprint devices (probably 5+). Canvas, WebGl etc are techniques of the past. There are much more advanced ones, than can identify devices with completely uniquely (on both desktop and mobile) Also we kn…

Are you talking about CSS-based fingerprinting? https://browserleaks.com/css#explanation

No, not this is some amateur work. State of the art techniques css fingerprinting can uniquely identify 1 device from billions.

Also this is nothing but getting dimension of screen and other browser attributes which are useless now. The current state of the art cannot be mitigated unless you put a 95% penalty on performance on the CSS engine AFAIK.

Re: Block Fingerprinting with Firefox

#342
post #72

Earlier quoted context omitted.

You can draw with different fonts and background colors, then grab the raw pixel values and hash them. The hash will be different depending on the versions of fonts installed, the OS, the GPU, the browser's text rendering algorithms, and the subpixel order/orientation of the display. See https://en.wikipedia.org/wiki/Canvas_fingerprinting for more info.

tldr: drawings aren't pixel perfect. Longer: this is actually a viable way to do many types of fingerprinting, not just canvas. I'll give an example. In a graphics class I took our professor gave us output images to compare to. Two people with the same model computer, same specs, would frequently have a pixel or two different from one another. Change the specs and you're easily a dozen off. Worse than that, the pixel…

Random, probably uninformed thought: I wonder if the solution could be LESS determinism rather than more. If you could make it so the same hardware rendered pixels in a slightly different (random) way each time, it would no longer be possible to determine if you were looking at the same machine.

Re: Block Fingerprinting with Firefox

#343
post #225

What about them selling their data on the darkweb? They claimed that there was no breach, but yet all of their database is being sold on the darkweb. Is it so easy to gather their database and publish it?

Who is them? Whose database?

Truecaller: https://techunalt.com/truecaller-data-sold-on-dark-web/

Re: Block Fingerprinting with Firefox

#344
post #175

Earlier quoted context omitted.

What’s wrong with using the resources of evil (freely given, oddly enough) to destroy evil? If someone you hate offers you a billion dollars, you should take it—because in doing so you’ve made someone you hate a billion dollars poorer! It’s like stealing the money from them, with less work! Imagine, analogously: a lottery whose proceeds go to a charity supporting statistics education.

If someone you hate gives you $1 million though, and says "I'll pay you again next year if you do well for me, you might even get more" then you're going to find that if you take the money in a few years all your decisions are centred around the happiness of the person you once hated. If you keep taking their money you're morally complicit in their actions too.

> all your decisions are centred around the happiness of the person you once hated

You’re essentially talking about the https://en.wikipedia.org/wiki/Cobra_effect. (The government sets a bounty on snakes? Bounty hunters realize that the cheapest way to get snakes to turn in to the government, is by breeding them themselves. Now you’ve got more live snakes, not fewer.) When greed or need-for-money is an incentive (such as in a for-profit corporation), you’ll be driven to do whatever perpetuates the income stream; and, if someone is paying you to do something, it’s cheaper to just do that thing because you get to continue working with them in the future (so your marketing costs for finding new work are zero.)

But, importantly, the Cobra effect doesn’t apply if your goal (as a person, or as an organization) isn’t to make money, but rather to use up money (i.e. to bankrupt your ‘patron.’) If you’re not a bounty hunter, but simply someone who hates snakes, you won’t ever bother to breed them. You’re not in it for the money. You’re in it for there being fewer cobras.

There are, of course, organizations which are not for-profit corporations. Mozilla itself is a non-profit, despite there also existing a Mozilla Corporation.

As well, even with a for-profit corporation, the income of such an organization can be completely divorced from how it deals with an arbitrary stream of money. Banks, for example, despite being for-profit corporations, do not spend the money you deposit with them. Your money is not an asset on their balance sheet; in fact, it’s a liability.

Mozilla Corporation could, for example, just donate all the money it receives from unsavoury sources over to Mozilla-the-nonprofit, and keep none for itself. This would remove its profit motive vis. this income source.

Analogies:

Police confiscate stuff from criminals, and then sell that stuff at auction. They aren’t driven to confiscate as much stuff as possible, because they don’t directly see the proceeds from those auctions (it goes into the city budget, which does eventually fund them back, but in some inscrutable, non-motivating way.) Instead, the police department usually just has a mandate to take the stuff and sell it. (There is a broken incentive around police confiscation of drugs and cash, because these are so hard to trace that police can and do directly profit from these confiscations. But money wired between corporations as a result of an invoice is not untraceable like cash, so the confiscation of cash isn’t really analogous. A closer analogy is the confiscation of pimped-out cars—the police do not, and cannot, make personal use of these. So they don’t really care how many they find.)

Oil-and-gas engineers aren’t driven to flare as much natural gas out of oil fields as possible, because there’s no useful purpose to flaring natural gas (for now); they’re just trying to use it up and get it out of the way of the stuff they do want.

Building renovation contractors aren’t driven to collect as much asbestos as possible. They only collect and remove it because they can’t certify the building until it’s all gone. (Imagine an alternative world where you could turn in asbestos to the government for a reward. We’d get a Cobra effect so fast.)

In all these cases, you’re not driven by your need to collect the thing; and there’s no element of greed driving you to collect the thing; it’s just part of your job to collect the thing. As you diminish the number of illegal weapons out there, or amount of natural gas in the oil field, or the amount of asbestos left in buildings... you can simply do less sequestering. Nobody is put out when criminals run out of guns, not even the police. The oil-and-gas engineers who did the burn-offs are done their work at that oil field, sure, but they just move on to another oil field. The renovators have plenty of other jobs to do, and the people who specifically handle asbestos removal will just retrain to remove the next thing people want gone from buildings, toxic mould or what-have-you.

——

What we’re essentially talking about, here, is a ‘parasitic’ nonprofit—the organizational equivalent of a mosquito, something that wanders around sucking its ‘hosts’ dry, but which doesn’t expect (or attempt) to subsist indefinitely on a single ‘host’. It expects to either kill its host; be killed by its host; or be “swatted away” by its host, at which point it can find a new host.

And, because a parasitic organization serves no useful purpose to its host—it offers no attempt at symbiosis—the host will eventually become aware of its nature, though how fast this happens can vary dramatically, depending on how bureaucratic the host is, and the time-scale of the deal the host and parasite originally made. (Imagine how long it would take the US government to figure out that a weapons subcontractor is a foreign-government led operation with the aim of “siphoning money out of the US defense budget while avoiding actually satisfying the demand for a given weapon”, purely through the regular business-side interactions between the government and the contractor, without the assistance of the government’s background-checking process. Unlike governments, private companies do not generally do background checks on their contractors’ employees, so an IBM, or a GE, is not safe from this attack.)

Of course, unlike in the animal realm where every animal at some point deals with a parasite from a state of complete ignorance, parasitic organizations can get reputations that precede them everywhere. This is what I’d call the host “killing” the parasite nonprofit.

But, well, the same people can form as many organizations as they want... and perhaps even use successive organizational vehicles to drain the same host companies repeatedly, if they just ensure to put a different face (different figurehead CEOs, etc.) on the parasite each time.

These are the same proven strategies that “fake” charities use every day to line their own pockets! Just turned to a purpose other than selfishness.

Re: Block Fingerprinting with Firefox

#345

Earlier quoted context omitted.

The fact that CAPTCHA sweatshops exist is a testament to it's failure as a protocol, let alone the privacy implications (just run X.exe to continue).

Seems like spammers wouldn't hire humans if they could fully automate it? That's about the best you could do as a defense.

Why do you assume they aren't automating it. The obvious thing if I'm a spammer is to hire humans to solve the problem, collect their output and feed it into my ML training. I now have the same dataset that google is using, for my ML.

Actually I'm not sure I need to go to full ML: after a few rounds I can probably just use image compare (not ML) and just feed humans images that I haven't seen before.

Of course round two of the above is to expand on the above. Doing ML for image recognition isn't hard (other than CPU cost). I can also collect statistics, images humans take longer on I will take longer on as well (I can potentially collect eye movement so I have better data than google here - this can feed into ML). Images that humans are unsure of I will fake unsure of by sometimes clicking sometimes not at similar rates to humans.

I don't know what ML google has that isn't public, but we also don't know what scammers have. Ultimately google needs to expose enough data to scammers (who see more captchas than anyone else by nature of their operations) that their ML algorithms have a large training set. Once a scammer realizes the types of data good is looking for it isn't hard to collect other samples for your private training set. Go outside in any city and you will find stoplights and street signs... you now have a training set of data that isn't googles to test on - you need a few cities and seasons worth of course, but that is an implementation detail.

Re: Block Fingerprinting with Firefox

#346

Earlier quoted context omitted.

If this is the case, then the millions if not billions of adfraud is put through by the ad companies knowingly and defrauding the ad-buyers surely?

Large companies have fixed ad spend budgets. If they dont spend they lose. Doesn't matter if its lost to fraud. Google, Facebook advertiser have more specific budgets, especially Facebook which has a large number of small advertisers. Large adnetworks however get large advertisers with advertising budgets in tens of millions on average. There is a larger pressure on Google and Facebook to be competitive then say smal…

> Also right now many adtech companies are going bankrupt.

As someone currently working in IT for an adtech company, I can at least provide one data point in that the company I work for is slowly (but surely) dying.

Re: Block Fingerprinting with Firefox

#348
post #56

Earlier quoted context omitted.

> 9.93 bits of identifying information. with this new setting turned on + uBlock Origin + NoScript

You can disable JS with uBlock Origin. No need for NoScript.

I'd rather have finer control on a site by site basis than wholly disabling js though.

Re: Block Fingerprinting with Firefox

#349
post #336

As much as I hate more legislation I think the only way to solve this is to make it very onerous to own and compile this data and to level heavy fines (as in criminal charges and/or force the company into bankruptcy via 90% revenue fines) in cases when the database is breached. Everything else will just turn into an arms race between those who don't wanna be tracked and those who wanna track. If the US did something…

These companies then lobby the government, asking to be relieved of the fines, because if they go down, so many workers will be out of jobs, and that they will comply (pinky promise), so the fines should be lifted to help these innocent people...

Re: Block Fingerprinting with Firefox

#350

Earlier quoted context omitted.

You have to stick with known popular user agents. To mitigate tracking by UA you need a randomized user agent that changes periodically. Panopticlick won't be able to account for that in its stats. It's not a good idea to switch UA on every request since it will be hard to diagnose breakage caused by a site that rejects particular UAs.

Unless you use some obscure browser, it is better to use your real user agent. If you keep your browser and operating system up to date, chances are it will be one of the most popular ones. Your UA will correlate with other means of fingerprinting you making you more common. Being clever can make things worse. For example, the most common UA is from an iPhone, but the most common screen width is 1920 pixel. If you de…

Most people don't keep their browsers up to date, let alone their OS. I'd say using FF is rare enough that switching to a chrome based UA would help.
Post reply on HN