Live data from Hacker News

Firefox 85 cracks down on supercookies

blog.mozilla.org

611–620 of 786 posts

Re: Firefox 85 cracks down on supercookies

#611
post #422

Earlier quoted context omitted.

Note that the root of all evil here is Javascript being opt-out instead of opt-in (and effectively mandatory for a big chunk of the internet these days). Letting any website and their friends (and the friends of their friends) run turing complete code on the client PC probably sounded reasonable when the web was created but it seems incredibly naive in hindsight. It's not as bad as ActiveX and other plugins, but it's…

> it seems incredibly naive in hindsight Oh stop with the dramatics, please. JS has brought us an immense amount of innovation on the web. It has lowered the barrier of entry to programming and introduced tens of millions of people to the world of development. If you're on HN the odds are that directly or indirectly, JS is one of the reasons you have a job today, and that you can execute it remotely. And today specif…

I agree with simias.

What does JS have to do with my VPN? What was wrong with Skype? Still beats the pants off others for quality.

I cannot think of much good agressive whitespace, hamburger menus, infinite scrolling, HID hijacking, copy-paste preventing, trackers etc, etc etc, has brought us, besides into the world of Aggressive Ad Arbitrage.

Need https://motherfuckingwebsite.com/ be mentioned?

The real powerhouse was Flash, then HTML5, and now WebAssembly, or as I like to call it, reinventing the wheel while simultaneously and conveniently blocking ad-blockers.

Re: Firefox 85 cracks down on supercookies

#612
post #525
post #470

Earlier quoted context omitted.

Often something is a multi billion dollar industry that people don’t want! Perhaps you’re invested in the ad industry. No one else wants ads buddy.

Not in ads but I know they are quite effective. Most startups can attribute their growth to the effectiveness of digital advertising. Robinhood was driving app installs for $10 each while E*TRADE and Ameritrade were paying $1000 per customer. Most of that VC cash startups raise is spent on marketing. I don’t understand why people have such negative perception of ads especially on a VC run news site. All the ycomb com…

Thanks for your considered response to my snarky comment. Personally I don't mind plain ads which are simply a commpany advertising their product/service on a billboard etc, what I find unbelievable in the digital era, is the extent of the intrusion now on finding out everything about people to market to them better (which I'm not even sure if having more data on someone has been proven to produce better results). Its really the data broking side of it - if that went away I'd have no issues.

Re: Firefox 85 cracks down on supercookies

#613
post #602

Earlier quoted context omitted.

> it seems incredibly naive in hindsight Oh stop with the dramatics, please. JS has brought us an immense amount of innovation on the web. It has lowered the barrier of entry to programming and introduced tens of millions of people to the world of development. If you're on HN the odds are that directly or indirectly, JS is one of the reasons you have a job today, and that you can execute it remotely. And today specif…

It can have been incredibly naive and have brought great benefit at the same time. In the 1990s did we foresee that in 2021, tracking our individual web activity and building profiles of our behavior would be a pillar of the business model supporting most of the online economy? Did we foresee that we would be looking to government regulation to prevent comprehensive profiles of our individual web browsing activity fr…

Not predicting what will happen thirty years hence is naive? The web was all shiny goodness and going to be a panacea for anything you could name back in the late 90s. The fact that it did not come to pass isn’t naïveté so much as a disappointing repeat of what our current economic systems of reward drive companies to do.

Re: Firefox 85 cracks down on supercookies

#614

Use uBlock Origin, Multi Account Containers, Privacy Badger, Decentraleyes and CookieAutoDelete with Firefox. Make sure you aggressively clear cache, cookies, etc., periodically (with CookieAutoDelete). You’ll probably load the web servers more and also add more traffic on your network, but it will help protect your privacy since most websites don’t care about that. When websites are user hostile, you have to take pr…

Doing this will make it trivially easy to fingerprint and track you on the web, as the set of people who use non-defaults like this list is 0.000001% of the total possible user space for their area, and your IP address probably only changes rarely or never A better way to protect yourself is to use a browser with tracking protections on by default, and leave the settings alone. You may see a few more ads but you’ll b…

The more people that install these, the less unique you become. Also if you are disabling JS execution via uBlock they aren't getting this list. What you are suggesting is essentially security by obscurity and this is failed already since it is highly unlikely my neighbor's browsing stream looks anything like mine.

What these plugins do is make the tracking job more difficult for the adtech guys, and the more complex these systems become, the higher the costs to the tracker and the higher the likelihood they screw up. It's defense in depth.

Re: Firefox 85 cracks down on supercookies

#615
post #564
post #174

Earlier quoted context omitted.

They load the image URL and observe the loading time. If it's fetched quickly, they know it was from cache. The server (controlled by the advertisers) can intentionally add delay to those image requests that makes detection reliable.

I don't see how that helps you persist a tracking ID. If you generate a random URL, you'll always get a cache miss. If you use a static URL, you'll know if you have a new session or not, but that doesn't tell you what the tracking ID was. The only thing I can imagine is the server serve several images /byte1.png /byte2.png etc. and make them all X by 1 pixels, encoding a random value in the dimensions, assuming that'…

Assuming js can retrieve pixel data, you could have the server generate unique images and use the rgb values as a unique ID. The unique image would be cached.

Re: Firefox 85 cracks down on supercookies

#616

If only DNT had been enforced and respected, so much effort could have been avoided. I appreciate these protections, but it’s unfortunate this whole cat and mouse game is necessary.

Who would enforce it?

Who enforces anything? The government. Something similar to health records is the usual example.

I suppose coordinated action by citizens would have the same effect, but online privacy is such a complicated obfuscated issue that will never happen.

Re: Firefox 85 cracks down on supercookies

#617
post #519

Earlier quoted context omitted.

So different website features per country? Or do you mean regulation decides how a browser implements it? Either way I don't see how that would ever work.

You are aware there are country-specific (or even more local) regulations covering companies today right? In fact essentially all regulations are. So why are you acting like my proposition is somehow unprecedented?

Isn’t it obvious? Most companies subject to regulations are physically located somewhere. It’s much harder to enforce regulations against companies that operate in every global jurisdiction at once.

Re: Firefox 85 cracks down on supercookies

#618

Use uBlock Origin, Multi Account Containers, Privacy Badger, Decentraleyes and CookieAutoDelete with Firefox. Make sure you aggressively clear cache, cookies, etc., periodically (with CookieAutoDelete). You’ll probably load the web servers more and also add more traffic on your network, but it will help protect your privacy since most websites don’t care about that. When websites are user hostile, you have to take pr…

Any reason to not go all-in and just use Tor? That's what I've been doing lately, although I'm not a web engineer, so I may not be doing the optimal thing.

Re: Firefox 85 cracks down on supercookies

#619
post #375

Earlier quoted context omitted.

There is no such thing as an ethical ad. Advertising is a cynical deployment of our knowledge of crowd wisdom, media manipulation, and statistics to make people part with their money for things they wouldn't think they needed. Our economy can't handle this kind of reckless consumerism anymore. Worse yet, we don't need advertising to bolster our media. Unfortunately, the media execs don't realize this yet. All your me…

I am really confused by this position. How do you propose that companies should promote their products and services, if not through advertising? Are you somehow suggesting that they should just sit there and hope that people who have never heard of their product independently decide they happen to want or need that product and seek it out, unprompted? You say "people part with their money for things they wouldn't thi…

Look at how much of a web you have to spin for yourself, just to conclude that it is indeed fine to have others tell you what you need to buy.

The false dichotomy you pose is ridiculous. People seek out information on what to buy all the time. But when I am listening to music, watching television or film, or reading a fucking news article, that is not the time I want to be given that information. It is unsolicited and I don't care about it.

Re: Firefox 85 cracks down on supercookies

#620

Earlier quoted context omitted.

This. If you are loading some scripts that are actually required for your app or page to work right, why would you get them from someone else's infrastructure? Terminal laziness? Or is the assumption that XYZ corp has more incentive than you do to keep your page working? This never made much sense to me except for developer toys & tutorials.

It makes sense from a $$ and resource usage stand point. I have to assume the best here and believe that the people arguing on there being no merit to CDN hosting of shared libraries all forgetting the two most important things a business must consider. Every byte sent will cost the business. If you can save that 2MB per user per cache life, you pay that much less on the internet bill for your hosting. Every byte sen…

> If you can save that 2MB per user per cache life, you pay that much less on the internet bill for your hosting

Ah yes - I remember those _dark days_ of being a shared webhosting customer over a decade ago and stressing about breaking my 500GB/mo data transfer limit.

Today, Azure's outbound data costs on the order of $0.08/GB, so 1MB is $0.000078125, so the cost of 2MB of JS is $0.00015625.

Supposing you have one million new visitors every month (i.e. nothing's cached at their end so they'll download the full 2MB) - those one million visitors will cost you $156.25 in data-transfer.

Compare that to the immediate cost to the business of paying their SWEs and SREs to trim down the site's resources to a more realistic few-hundred-KB, supposing that's a good 2-3 week project for 3-4 people - assuming a W/Best Coast company, that's ( $250k / 52 ) * 3 * 4 == $57,000.

From looking at those numbers, there is absolutely no business case in optimizing web content - it's now significantly cheaper (on paper) to have a crappy UX and slow load-times than it is to fix it.

Post reply on HN