Live data from Hacker News

Privacy Analysis of FLoC

blog.mozilla.org

1–10 of 167 posts

Re: Privacy Analysis of FLoC

#2
> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk

The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons, tweaking about:config and hardening it, etc

Call me a power user if you want, but all this hardening stuff should ship out-of-the-box.

Re: Privacy Analysis of FLoC

#3
post #2

> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons,…

> all this hardening stuff should ship out-of-the-box.

I mean, Brave kinda does that. It’s much more “hardened” by default.

Re: Privacy Analysis of FLoC

#5
post #2

> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons,…

Disabling canvas...

Re: Privacy Analysis of FLoC

#6
post #2

> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons,…

The funny thing is that customizing your browser in this way can be its own kind of fingerprint.

Re: Privacy Analysis of FLoC

#7
post #2

> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons,…

The funny thing is that customizing your browser in this way can be its own kind of fingerprint.

That's the number 1 reason it should be the default.

Re: Privacy Analysis of FLoC

#8
post #2

> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons,…

The funny thing is that customizing your browser in this way can be its own kind of fingerprint.

Yes but disabling JS as a default wipes out whole classes of attacks against your browser.

On top of disabling JS, just a simple AD blocker like uBlock Origin greatly diminishes the amount of profiling. There is no silver bullet however. It depends on your threat model.

If you really don't want to be tracked and profiled, using the Tor Browser Bundle is worthwhile, but even that is problematic since it's heavily surveilled (both at the entry node and exit nodes).

Re: Privacy Analysis of FLoC

#9

Earlier quoted context omitted.

The funny thing is that customizing your browser in this way can be its own kind of fingerprint.

That's the number 1 reason it should be the default.

Not happening. All those anti-tracking measures break websites more often than not.
Post reply on HN