Live data from Hacker News

Google Chrome Incognito Mode Can Still Be Detected

bleepingcomputer.com

171–180 of 201 posts

Re: Google Chrome Incognito Mode Can Still Be Detected

#171
post #142

Earlier quoted context omitted.

> Sites that "still work with JS disabled" are in the minority on those lists. You'd be surprised how many sites are still viewable without JS enabled.

You’d be surprised how many sites are more viewable without JS enabled.

Damn straight! Disabling JS fixes more websites than it breaks.

Re: Google Chrome Incognito Mode Can Still Be Detected

#172
post #102
post #64

Earlier quoted context omitted.

I feel as though your argument is predicated on browsers that leak tracking data such as cookies, etc. If the browser vendors would tighten their products up and start considering things like profiling the user's installed fonts as a security vulnerability, then we might see some progress. Unfortunately Google has a financial incentive to make Chrome trackable to advertisers.

Don't forget that the advertisers don't get income directly from tracking you. They get income based on how good they have a profile of your interests (and things that you would buy). If they can get a good enough profile without tracking then maybe they'll stop tracking. Or maybe it would be easier to block the few that continue taking than wave war on an entire industry.... There's already been some talk about chan…

>they can easily get the processor speed, GPU version, local IP, and other details

This is what I'm referring to. The browser should not leak this info to random websites.

Re: Google Chrome Incognito Mode Can Still Be Detected

#173
post #150

Earlier quoted context omitted.

I whitelist cookies; only sites that I have a known relationship to (e.g., HN, for login) get to set cookies. The overwhelming majority of the web still works just fine. It's trivial to pick out what doesn't, as it either tends to: a. require cookies for some inane task that doesn't need them, and it tells me this b. breaks horribly. Typically, JS trying to access LocalStorage, but not checking whether the call was s…

Or you can just freely allow all cookies from any website that wants to set them (sites will be happy and working), but only for current browser session. You have to remember to restart the browser every now and then, though. Then use whitelist to selectively allow cookies from some "friendly" sites to be stored permanently.

If the intent is no tracking, then this defeats the purpose.

Often the browser stays open for hours and you'll have identifying tracking cookies very quickly.

A great, really underused feature in Firefox is first party cookie isolation: it isolates all cookies set by a site to the same domain, preventing all cross site tracking.

Set privacy.firstparty.isolate to true in about:config.

Some more info: https://www.ghacks.net/2017/11/22/how-to-enable-first-party-...

Re: Google Chrome Incognito Mode Can Still Be Detected

#174

Earlier quoted context omitted.

How about passing laws which forbid tracking users like this and levying steep, business-ending fines against the companies who don't step in line?

No problem. All your favourite online services are no longer free though, what a bummer. Will it be a lite, regular or premium Google maps subscription? How about Facebook Messenger?

That'd be a dream coming true! But I'm sure it wouldn't be the end of "free", ad-ridden content.

Re: Google Chrome Incognito Mode Can Still Be Detected

#175

Earlier quoted context omitted.

How about passing laws which forbid tracking users like this and levying steep, business-ending fines against the companies who don't step in line?

No problem. All your favourite online services are no longer free though, what a bummer. Will it be a lite, regular or premium Google maps subscription? How about Facebook Messenger?

It's not as if Google maps is the only game in town. Really the only thing I use it for over openstreetmaps is business hours and transit directions, but there is no reason the later couldn't be done. I use osmand on my phone and have offline maps for everywhere I've been. Grabbing some gtfs files wouldn't be difficult.

As for messenger, there will probably always be some "free" messaging service out there. Free in quotes as it'll come with phone, isp, or email subscriptions.

Re: Google Chrome Incognito Mode Can Still Be Detected

#176
post #174

Earlier quoted context omitted.

No problem. All your favourite online services are no longer free though, what a bummer. Will it be a lite, regular or premium Google maps subscription? How about Facebook Messenger?

That'd be a dream coming true! But I'm sure it wouldn't be the end of "free", ad-ridden content.

Ads aren't the problem. Tracking, malware, and other user-hostile activities are the problem.

Re: Google Chrome Incognito Mode Can Still Be Detected

#177
post #174

Earlier quoted context omitted.

That'd be a dream coming true! But I'm sure it wouldn't be the end of "free", ad-ridden content.

Ads aren't the problem. Tracking, malware, and other user-hostile activities are the problem.

I dislike both things for different reasons.

Re: Google Chrome Incognito Mode Can Still Be Detected

#178
post #30

This is annoying so I just use fresh browser profile every time I encounter such site, i.e. have a short-cut for: $ cat ~/bin/chrome-new #!/bin/sh TMPDIR=`mktemp -d /dev/shm/chrome-XXXXX` google-chrome --user-data-dir=$TMPDIR --no-first-run --no-make-default-browser "$@" rm -rf $TMPDIR

Firefox Containers¹ are nice for that. Put the website in its own sandbox.

1: https://addons.mozilla.org/firefox/addon/multi-account-conta...

My only gripe is that the containers won't be in sync accross systems, which is already time-consuming to setup..

Re: Google Chrome Incognito Mode Can Still Be Detected

#179
post #15

Can this fight ever be won? If you've been browsing the internet for more than 5 minutes you already have cookies from some of the major ad networks. Therefore if you do not have cookies from the major ad networks, you're either a brand-new device or an incognito browser. All that is left to do is get in bed with the ad network to ask them if they have good cookies for this session. As it so happens most of the compa…

Yes, Google is committed to patching out anything used to detect incognito mode. If they make good on that promise detection will become harder and harder until it becomes practically impossible. Incognito mode can be made to look exactly as if you opened your browser after creating a new profile and immediately opening the site. As long as they can’t afford to block these users it can be made to work.

You can remove the as long out of the last sentence and it still makes sense.

Re: Google Chrome Incognito Mode Can Still Be Detected

#180
post #146

Earlier quoted context omitted.

Ok, I wasnt talking about protecting the data part. >The question is not whether or not many (most? virtually all?) companies will try to get around GDPR (they will) They arent getting around, they are violating it, based on GDPR beeing doe as a concept, you cant workaround it. The question is, when it will be enforced. I dont have anything against tracking, targeted ads etc. but if GDPR is followed, which means opt-…

But, "lets stuff everything under legitimate interest" is totally valid if it is actually legitimate interest. Opt-in consents under GDPR is probably your worst strategy. The lawful basis you want to be under is contract basis: you gather the information you need for the contract. You hold it until the contract is up and then you delete the information. That's the best for everyone. Legitimate interest is the next be…

You got the legitimate interest wrong. I wont bother explaining, as I am sick of downvoting (would love to discuss recitals), here is presentation from Tim Walters, check the legitinate interest (or the whole, you might be surprised): https://www.youtube.com/watch?v=-stjktAu-7k

Bottom line, "the grain" of GDPR is user interest. Not "user expirience", not bussines interest.

Users interest.

And it is HARD to decide instead of him, I would rather pop up consent dialog with opt-in than showel everything under legitimate interest.

As it is so easy to make it wrong: sure, you are sending a packet to the customer, you need (legitimate interes) address, phone number comes handy (requiring it is fishy), forcing it to protect login on a social network? I wouldnt do it. For me, as a security aware person, you would crawl trying to prove I am in danger with 15 letter random generated passwords generated for each and every site. Unlike for John Doe. So, it becomes optional, while forcing it, in my case, violates GDPR. It was just one example.

But anyway, check Tim Walters.

Post reply on HN