Live data from Hacker News

Google Chrome Incognito Mode Can Still Be Detected

bleepingcomputer.com

141–150 of 201 posts

Re: Google Chrome Incognito Mode Can Still Be Detected

#141
post #26

Earlier quoted context omitted.

That used to be the case. But Google has long ago given certain sites a pass on that.

Did they? This fight against Incognito mode suggests otherwise

Shocking I know, but it seems like Google contradicting other parts of Google due to a lack of strategic leadership, which almost never happens. Daily...

Re: Google Chrome Incognito Mode Can Still Be Detected

#142
post #81

Earlier quoted context omitted.

> Where is this special list of important pages? Are the sites I want to use not important? Does your comment need to be so simultaneously defeatist and hostile? Or, as I like to call it, pragmatic. Visits are a power law distribution, 80% of people's visits go to 20% of sites, and so on, recursively. s So unless e.g. the top 1000 (which may vary depending on country) people want to use are there, e.g. the social med…

> Sites that "still work with JS disabled" are in the minority on those lists. You'd be surprised how many sites are still viewable without JS enabled.

You’d be surprised how many sites are more viewable without JS enabled.

Re: Google Chrome Incognito Mode Can Still Be Detected

#143

Earlier quoted context omitted.

No problem. All your favourite online services are no longer free though, what a bummer. Will it be a lite, regular or premium Google maps subscription? How about Facebook Messenger?

You don’t need detailed tracking to run ads. Newspapers did it in the time before the internet. What did occur, is that advertisers could not be sure of performance so placed more value on the prominence and reputation of the media source. National well reputed papers got the best deals, regardless of real world performance. It will lead to tight localization again, as advertisers can’t rely on Google just selecting…

> You don’t need detailed tracking to run ads. Newspapers did it in the time before the internet.

Newspapers did it to some extent, and they were not competitive businesses against methods where tracking does exist.

The reality is that newspapers are still very strong lobbyists, especially in newspapers, as they frequently sink politicians who don't toe their line with unrelated scandal or just plain fantasy. If Google pushes this they are likely to find legislation, particularly in the EU, mandating quite the opposite to what you want.

Re: Google Chrome Incognito Mode Can Still Be Detected

#144
post #136

The dutch cable company 'Ziggo' (owned by Liberty Global) also does Incognito mode detection in their web-based tv player and does not allow streaming. https://imgur.com/a/TacdDRm You can check it yourself here: https://www.ziggogo.tv/

I don't believe that's actually their fault, HTML5 EME implementations don't work in incognito mode in Chrome. But that is another way in which newspaper sites could do this detection is they wanted to, send an HTML5 EME clearkey to a one pixel video in the corner and get back the error response. I think Google are on to a complete loser here tbh, and I'm not sure why they're wasting development resource. As much as…

Yeah, I know, but the article seems to not know about this.

Another avenue could be that they just check the uniqueness of your signature; if it's too generic: block content, and only lift it after installing a first party extension or something, that way, for most people it will just work and for the few that are false positives, you have a workaround. The whole goal of the incognito modus is also a way to detect it.

It's the same for adblockers; just serve a unique content key with the ad and check back via the ad provider if it was loaded before proceeding to serve content.

Only serving ad-free content to crawlers is no problem either, because ip ranges for the big ones are known and you can't spoof them in TCP. It's all a question of effort Vs reward. They probably know just a very small percentage of users will abuse it, so it's not worth it for them to spend a lot of effort blocking it.

For example: in a retail store, if there's a difference in expected vs actual money of ~€4, it's not even worth it to investigate, because it will cost more than you'll get back from resolving it. It's sometimes hard for me to comply because I always want to have stuff match 100%, but it's always a effort Vs reward dilemma that you have to work with.

Re: Google Chrome Incognito Mode Can Still Be Detected

#145
Keeping local storage in memory might make sense if Incognito Mode had separate storage for every tab. However, it's just another browser session that gets wiped when the the last tab gets closed – you cannot have multiple parallel ephemeral sessions. I remember having to install Chrome Canary because I needed four separate Chrome sessions simultaneously.

Re: Google Chrome Incognito Mode Can Still Be Detected

#146
post #103

Earlier quoted context omitted.

If plenty is "a few" than I would agree (and I am glad you respect privacy). I am still searching for one site that I could give an example for GDPR and they are all blatantly violating it. In most cases they just give you fake impression they respect privacy (by setting banner to "opt-out" (which is violation on its own) after the tracking 3rd party scripts are already loaded). The whole privacy deal on the web just…

> I am still searching for one site that I could give an example for GDPR and they are all blatantly violating it. I think the reason you can't find one is likely because you are disqualifying all the ones that aren't violating it. There a lots of websites that don't violate GDPR: they don't record any information. Perhaps we can quibble about server logs and whether or not IP addresses are PII, but let's stick to at…

Ok, I wasnt talking about protecting the data part.

>The question is not whether or not many (most? virtually all?) companies will try to get around GDPR (they will)

They arent getting around, they are violating it, based on GDPR beeing doe as a concept, you cant workaround it.

The question is, when it will be enforced.

I dont have anything against tracking, targeted ads etc. but if GDPR is followed, which means opt-in consents, no "lets stuff everthing under legitimate interest" and so on. Under GDPR conditions I am even prepared to turn off ad blockers.

And I wont even start talking about mobile applications.

Re: Google Chrome Incognito Mode Can Still Be Detected

#147
post #133
post #15

Can this fight ever be won? If you've been browsing the internet for more than 5 minutes you already have cookies from some of the major ad networks. Therefore if you do not have cookies from the major ad networks, you're either a brand-new device or an incognito browser. All that is left to do is get in bed with the ad network to ask them if they have good cookies for this session. As it so happens most of the compa…

I remember around 10 years ago people were calling Stallman paranoid for this. Now he seems more like a prophet: >I generally do not connect to web sites from my own machine, aside from a few sites I have some special relationship with. I usually fetch web pages from other sites by sending mail to a program (see https://git.savannah.gnu.org/git/womb/hacks.git ) that fetches them, much like wget, and then mails them b…

Well, that is a bit paranoid.

Re: Google Chrome Incognito Mode Can Still Be Detected

#148
post #146

Earlier quoted context omitted.

> I am still searching for one site that I could give an example for GDPR and they are all blatantly violating it. I think the reason you can't find one is likely because you are disqualifying all the ones that aren't violating it. There a lots of websites that don't violate GDPR: they don't record any information. Perhaps we can quibble about server logs and whether or not IP addresses are PII, but let's stick to at…

Ok, I wasnt talking about protecting the data part. >The question is not whether or not many (most? virtually all?) companies will try to get around GDPR (they will) They arent getting around, they are violating it, based on GDPR beeing doe as a concept, you cant workaround it. The question is, when it will be enforced. I dont have anything against tracking, targeted ads etc. but if GDPR is followed, which means opt-…

But, "lets stuff everything under legitimate interest" is totally valid if it is actually legitimate interest. Opt-in consents under GDPR is probably your worst strategy. The lawful basis you want to be under is contract basis: you gather the information you need for the contract. You hold it until the contract is up and then you delete the information. That's the best for everyone.

Legitimate interest is the next best for everyone. You collect the data for contract purposes and you retain it beyond the contract period, or you use it for something other than the contract, but it's for a legitimate reason. You must tell the user that you are using the data for the legitimate reason and what that legitimate reason is!!! It's a very good way to use data. If the user objects, then they can object and you can't use the data (you have 1 month to respond).

After that (and ignoring lawful basis, etc) you have consent. Consent is an awful reason to collect and retain data. You don't need it for the contract. You have no legitimate reason to have the data or to use it. You just want it. So you ask the user if it's OK.

No company should choose consent. It's horrible, even for the business. As I've written before, if the user opts out, there doesn't seem to be a way to opt them back in if they change their mind. So if there is any way for you to turn consent into contract basis, you really, definitely should! If there is some reason that the user would like to consent, they you shouldn't be using consent. You should offer them a service.

It's super frustrating to me that people harp on about consent, because that it really going against the grain for GDPR.

Re: Google Chrome Incognito Mode Can Still Be Detected

#149
post #134

Earlier quoted context omitted.

>If you've been browsing the internet for more than 5 minutes you already have cookies from some of the major ad networks. I don't, as I block all third party cookies. No exceptions.

Interesting. Are there any legitimate uses for third party cookies (i.e. functionality that you as the user actually care about) or are they only ever used for tracking?

As someone who also blocks third party cookies - Captchas. But nothing else important IME.

Re: Google Chrome Incognito Mode Can Still Be Detected

#150
post #24

Earlier quoted context omitted.

So, don't use the internet? Because that's what you're describing. Better cut the power cord, too, just to be safe.

I whitelist cookies; only sites that I have a known relationship to (e.g., HN, for login) get to set cookies. The overwhelming majority of the web still works just fine. It's trivial to pick out what doesn't, as it either tends to: a. require cookies for some inane task that doesn't need them, and it tells me this b. breaks horribly. Typically, JS trying to access LocalStorage, but not checking whether the call was s…

Or you can just freely allow all cookies from any website that wants to set them (sites will be happy and working), but only for current browser session. You have to remember to restart the browser every now and then, though.

Then use whitelist to selectively allow cookies from some "friendly" sites to be stored permanently.

Post reply on HN