Live data from Hacker News

Browser Fingerprinting Without JavaScript

fingerprintjs.com

31–40 of 124 posts

Re: Browser Fingerprinting Without JavaScript

#32
post #11

Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.

Yes, let's limit creativity because some asshats have made looking at a list of fonts a negative. Let's just limit fonts altogether and only use emojis or braille like dot patterns.

Re: Browser Fingerprinting Without JavaScript

#33

Being a fervent Tor Browser user, i just tried with it and of course the fingerprinting failed. Several copies of it give me the same fingerprints: e56952dba176a47af3c051b626b64ff3 (Safer mode) 632e305f8a939e5ba6afd24eced586f0 (Safest mode) That's because the Tor Browser, contrary to urban legend, is not just a browser that routes trafic through the tor network, but a firefox reworked (most of which is being upstream…

TCP fingerprinting TOR would fingerprint the exit node

Re: Browser Fingerprinting Without JavaScript

#34
post #11

Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.

This feels like it's targeted at a very narrow view of what a browser is for. How would a site like fonts.google.com work?

Images

Re: Browser Fingerprinting Without JavaScript

#35
post #11

Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.

Yes, let's limit creativity because some asshats have made looking at a list of fonts a negative. Let's just limit fonts altogether and only use emojis or braille like dot patterns.

Obviously the browser must prompt users before displaying non-ascii characters as well. Who wants to do anything other than read mailing lists in their browser?

Re: Browser Fingerprinting Without JavaScript

#36
Like others have mentioned here the demo seems to be able to categorize users into certain groups, but it is unclear how useful it is for fingerprinting and track an individual. I would love to see some statistics on it because from the data the demo gathers it seems like it will have a hard time to make out individuals in many cases. I find the technique used in the paper "Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses" [1] more interesting, although highly impractical. I guess there might be more practical CSS-based techniques that could fingerprint an individual and track them over several sites, but I have a hard time to see the limited tracking presented in this article would be very effective.

[1] https://arxiv.org/abs/2103.04952

Re: Browser Fingerprinting Without JavaScript

#37
post #12

I used to think that privacy was a technical problem, then I thought it was a legal problem, now I think it is a reaction problem. We are not disgusted enough. I do wonder if that will change.

Well, the real problem is advertising. It is far too profitable. If we want to live in a less distorted world, start taxing digital advertising heavily. Give people the real choice to pay for services (like we do in every other area in life) instead of paying with their privacy.

Who's to say they're paying with privacy? Xbox and Playstation get 15-30% of every game sale for their consoles, since the consoles are sold near-cost or even at a loss. At least historically they were just paying on the backend, not with their privacy. Is the line tracking, advertising, or just not being able to pay everything up-front (and not based on usage)?

Re: Browser Fingerprinting Without JavaScript

#38

Earlier quoted context omitted.

Yes, let's limit creativity because some asshats have made looking at a list of fonts a negative. Let's just limit fonts altogether and only use emojis or braille like dot patterns.

Obviously the browser must prompt users before displaying non-ascii characters as well. Who wants to do anything other than read mailing lists in their browser?

Every webpage should be a 640x480 jpg hosting exclusively through a CDN separate from the originating site.

Why can't we make a better web like this that respects your privacy?

Re: Browser Fingerprinting Without JavaScript

#39
post #11

Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.

This feels like it's targeted at a very narrow view of what a browser is for. How would a site like fonts.google.com work?

It should ask permission after N fonts.

Re: Browser Fingerprinting Without JavaScript

#40

Earlier quoted context omitted.

This feels like it's targeted at a very narrow view of what a browser is for. How would a site like fonts.google.com work?

It should ask permission after N fonts.

More permissions are not the right answer. Too many and users get conditioned to blindly clicking accept.
Post reply on HN