Live data from Hacker News

Block Fingerprinting with Firefox

blog.mozilla.org

401–410 of 411 posts

Re: Block Fingerprinting with Firefox

#401

Earlier quoted context omitted.

>Latest methods dont even use JavaScript. Just CSS is enough to identify every device uniquely but you'd need JS to send the data back.

You said: > Wait for the new CSS version over which our team had a watch. Wont require JS after it comes out. ;D So how does that work considering what I said above?

CSS provides basically no way to hide you’re doing this. I don’t believe this is real.

Re: Block Fingerprinting with Firefox

#402

Earlier quoted context omitted.

This seems like it would be very easy to game

Its very difficult to block an extremely motivated and targeted attack. With things like this, you aren't trying to necessarily block a highly targeted attack. You mostly need to just ward off the majority of low effort bot spam and random internet trolls. Having extremely tight security can be expensive and/or difficult for most organizations.

This is exactly why something like reCAPTCHA exists and is used prevalently.

To me, it sounds like your system is just security by obscurity. It wouldn't scale, if it did become used prevalently then it would be very easy for bots to circumvent.

Re: Block Fingerprinting with Firefox

#403

Earlier quoted context omitted.

I cancelled my subscription and deleted Spotify because of that. I can do with streaming of local radio and my own music. I really hope the EU hits them hard with a GDPR investigation, the amount of identifiable data they collect with reCaptcha is unacceptable.

Some strong statements in these comments on a website with registration and login protected by Google's ReCaptcha. :)

Please explain.

I've never seen a reCaptcha on HN. Is that because I registered my account something like 10 years ago?

Re: Block Fingerprinting with Firefox

#404
post #387

Earlier quoted context omitted.

The old link you keep pasting does not support this or your other hyperbolic assertions. Stop dangling claims of secret superpowers or support them.

Have a read: https://www.ieee-security.org/TC/SP2019/papers/405.pdf

All the links you provided describe techniques that would only work on mobile devices with access to the sensors. On my desktop PC there's no GPS, no gyrometer, no webcam and no browser access to my microphone.

Re: Block Fingerprinting with Firefox

#405
post #399

Earlier quoted context omitted.

But when do we move on? When most browsers implement something the same way, or when all do? What about polyfills? What do you do when you need a new API to better support a user's device with a new form factor, interaction model, wide colour gamut, resolution, background threads, etc.? Tell them to not upgrade? Stop the world? It seems impractical to suggest "target a standard: job done, go home..."

If we target standards, then the standards are driving. The browser gets supported when it builds to the standards. Perhaps the issue will then be getting standards in place quickly around new capabilities? Then maybe the standards process needs disruption. But if we don't build to standards then we are building roads that only certain cars can drive.

This is unfortunately not true - browsers are driving. Especially when entity everyone uses (Google) also owns the most popular browser. They can, and did, implement non-standard features that only worked in Chrome. Super cool tech demos, you have to see it, just install this browsers from an advertising company. What could go wrong?

Re: Block Fingerprinting with Firefox

#406
post #405
post #399

Earlier quoted context omitted.

If we target standards, then the standards are driving. The browser gets supported when it builds to the standards. Perhaps the issue will then be getting standards in place quickly around new capabilities? Then maybe the standards process needs disruption. But if we don't build to standards then we are building roads that only certain cars can drive.

This is unfortunately not true - browsers are driving. Especially when entity everyone uses (Google) also owns the most popular browser. They can, and did, implement non-standard features that only worked in Chrome. Super cool tech demos, you have to see it, just install this browsers from an advertising company. What could go wrong?

Hence a blood oath is required :)

Re: Block Fingerprinting with Firefox

#407

Earlier quoted context omitted.

Have a read: https://www.ieee-security.org/TC/SP2019/papers/405.pdf

All the links you provided describe techniques that would only work on mobile devices with access to the sensors. On my desktop PC there's no GPS, no gyrometer, no webcam and no browser access to my microphone.

And no access to that on mobile without security dialogs. Dude originally claimed it worked via CSS. I guess he doesn't have secret superpowers.

Re: Block Fingerprinting with Firefox

#408
post #94

Google's reCAPTCHA makes it impossible to use large portions of the web once you take reasonable measures to protect your privacy. The challenge will continuously fail, despite you spending time to carefully solve it. This cruel behavior is described in a patent [1] by Kyle Adams of Juniper Networks. [1] https://patents.google.com/patent/US9407661

Wait. Patent? It's just a simple technique, quirk, workaround, something to win the arms race... Just like shadowbanning on Twitter.

Re: Block Fingerprinting with Firefox

#409

Earlier quoted context omitted.

Its very difficult to block an extremely motivated and targeted attack. With things like this, you aren't trying to necessarily block a highly targeted attack. You mostly need to just ward off the majority of low effort bot spam and random internet trolls. Having extremely tight security can be expensive and/or difficult for most organizations.

This is exactly why something like reCAPTCHA exists and is used prevalently. To me, it sounds like your system is just security by obscurity. It wouldn't scale, if it did become used prevalently then it would be very easy for bots to circumvent.

I normally agree with concerns about security through obscurity, but I disagree here: this isn’t a security feature. It is spam protection. Everything that creates more work for any attacker here helps reducing spam, on top of that Google itself uses code obsfucation (”Security through obscurity”) in their Captcha for precisely that reason.

It won’t scale, because it mustn’t scale. It is a dead simple solution to a complicated problem and works as long as it works, without selling your user data and brainpower toone of the biggest tech companies there is.

If it should happen that the spam bots overcome it or your site becomes big enough to be targeted you just change it for something stricter, stronger or more sophisticated.

Re: Block Fingerprinting with Firefox

#410

Earlier quoted context omitted.

Sorry. If I want my data somewhere else I can stay with Chrome. I switched years ago because of performance reasons. Whenever I tried to switch back I felt stabbed in the back shortly thereafter by Mozilla.

Chrome is much worse. It seems like chopping a leg off because someone stepped on a toe.

With Chrome I do not expect privacy. With FF every time I trust them the fk me over.

So - with Chrome I know what I am getting and I treat it as such. With FF I only wanted a Browser. I never aigned up for their (internal and external) advertising, Pocket stuff and other st like this.

So no - because FF brands itself as a privacy option, I hold them to a different and much higher standard - and the fail every time.

Post reply on HN