Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.
Who is behind the web browsers that most people use. Companies whose businesses rely on subjugating user privacy have few if any incentives to make these types of changes. These complex browsers do not exist for their users, they exists for the advertising company or other company that collects user data.
Browser Fingerprinting Without JavaScript
61–70 of 124 posts
Re: Browser Fingerprinting Without JavaScript
#62Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.
Yes, let's limit creativity because some asshats have made looking at a list of fonts a negative. Let's just limit fonts altogether and only use emojis or braille like dot patterns.
Yes.
Security and privacy come at the expense of other things. It's not totally unreasonable to prioritize them though.
It would limit creativity, but not by very much.
Re: Browser Fingerprinting Without JavaScript
#63Browsers should limit every webpage to displaying a maximum of two fonts, and should silently ignore any font face rules after the first two. Maybe three if you're feeling generous. With variable fonts available in every browser it wouldn't impact typography much. It would stop this sort of privacy attack, and it'd have the additional benefit of making the web look a lot nicer.
Different languages often require you to use different fonts, there are very few fonts that contain characters for all languages. Ranges using specific languages are tagged with the 'lang' attribute so the browser can use the appropriate font. If you aren't allowed to include any font face rules you lose the ability to handle multiple languages (unless all the languages you care about use codepoints below 255). Itali…
Bold and italic were different fonts in the past, but variable fonts have solved loading separate fonts for different weights and italics. This change would require developers swap to use those in many cases, and to create variable versions of brand fonts if necessary. I don't see that as a problem. The benefit makes it worthwhile.
Re: Browser Fingerprinting Without JavaScript
#64Earlier quoted context omitted.
Rooting your phone and it being secure are two completely different things my friend.
I can't tell if you're trying to say unrooted phones with stock carrier roms are somehow understood to be secure, or if rooting is mutually incompatible with security, or something else. Want to expound?
Re: Browser Fingerprinting Without JavaScript
#65Being a fervent Tor Browser user, i just tried with it and of course the fingerprinting failed. Several copies of it give me the same fingerprints: e56952dba176a47af3c051b626b64ff3 (Safer mode) 632e305f8a939e5ba6afd24eced586f0 (Safest mode) That's because the Tor Browser, contrary to urban legend, is not just a browser that routes trafic through the tor network, but a firefox reworked (most of which is being upstream…
Did you see the spefific CSS hack they use to tell if you're using the Tor Browser as opposed to normal Firefox?
Re: Browser Fingerprinting Without JavaScript
#66Earlier quoted context omitted.
Yes, let's limit creativity because some asshats have made looking at a list of fonts a negative. Let's just limit fonts altogether and only use emojis or braille like dot patterns.
Obviously the browser must prompt users before displaying non-ascii characters as well. Who wants to do anything other than read mailing lists in their browser?
Re: Browser Fingerprinting Without JavaScript
#67Earlier quoted context omitted.
Rooting your phone and it being secure are two completely different things my friend.
I can't tell if you're trying to say unrooted phones with stock carrier roms are somehow understood to be secure, or if rooting is mutually incompatible with security, or something else. Want to expound?
Basically, you don't log in to your Linux box (or Windows, Mac, etc) as root for day to day use and same thing goes for your phone.
Re: Browser Fingerprinting Without JavaScript
#68Earlier quoted context omitted.
I can't tell if you're trying to say unrooted phones with stock carrier roms are somehow understood to be secure, or if rooting is mutually incompatible with security, or something else. Want to expound?
Here's a link to a more complete explanation from the primary developer of GrapheneOS: https://teddit.net/r/GrapheneOS/comments/du23la/rooted_or_ro... Basically, you don't log in to your Linux box (or Windows, Mac, etc) as root for day to day use and same thing goes for your phone.
Rooting is not incompatible with security. Trusting carrier distributed software on a locked down device is far less secure than using a custom install of something like Calyx or GrapheneOS.
In my view, trusting Google, Apple, Verizon, t-mobile, or at&t is incompatible with security.
The idea that people having administrative access to their own devices is inherently insecure is vicious anti-consumer nonsense.
Re: Browser Fingerprinting Without JavaScript
#69Earlier quoted context omitted.
The "Safest" mode gives me different fingerprints each time. The "Standard" and "Safer" modes give the same fingerprint tho.
So how crippled does regular web browsing become using Tor safest mode? I'm tempted to give it a whirl for a week. Root my phone, flash something secure, leave VPN always on, and limit web browsing to Tor to get a feel for how bad or good it is. The self inflicted contortions developers go through to justify the need to spy drive me crazy. Modern devices and bandwidth are more than sufficient to handle a vast majorit…
Re: Browser Fingerprinting Without JavaScript
#70Earlier quoted context omitted.
I thought Smarter Every Day's analogy to carbon emissions was great for this exact reason. It's hard to feel like it is a problem because it is difficult to see the pollutant and small amounts don't cause major problems. But when that pollutant reaches a critical mass then it becomes a very large problem for everyone, not just a particular individual.
Though I think it's fishy he's trying to get VC funding for a privacy product that does similar stuff to current FOSS projects. How on Earth do you expect to make profit for investors on a privacy product?
They also try to be kinda snapchat with self-destructing file shares. That this is impossible at the very least thanks to the analog hole is a given, but at least they mention that and mention how they intent to fight it (by using watermarks to discourage people from screenshots, etc). They seem to overstate their capabilities in their main marketing material, tho. They are a bit sparse on the details and very "marketingey" - which is understandable given the target audience of this campaign - but they promise a proper white paper and open source (not necessarily free) code soon.
All I see is that they have a kickstarter for a measly $150K, not really VC funding? So "make a profit for investors" might be a kind non-goal at least for now. It doesn't sound like they aim to be the next unicorn, just to be sustainable and maybe eventually make the major investors their money back and then some.
I wouldn't call this thing "fishy". It has a high likelihood of failure in the market and/or not quite delivering on the promises, sure, but that's true for all early startups. But they might come out with a real product valuable enough for some niche of people to pay for it and sustain it.
The Smarter Every Day guy also put his reputation on the line. He doesn't seem stupid enough to back complete vaporware or worse, grab the money and run. His reputation is likely more valuable mid to long term than the $500K (of $150K they asked for).
My personal guess: it will fail to be big (the space is too crowded in "good enough" apps, and they will have a hard time building enough network effect that their "sharing files" mission requires), it will fail to deliver everything they aspire to deliver, but they will deliver something that a niche of people will like and use. If that will be enough to sustain the thing... maybe not. They kinda have to go as a freemium app, like lastpass or mega.nz or protonmail to even have a chance to build up momentum, or find themselves some "sugardaddies" and "sugarmommies" as signal did or mozilla did (tho the latter is in trouble now thanks to the codependence - as well as bad management). They could even become a mega or even a dropbox competitor. Or they will fail to acquire enough users and fade away or have to pivot to a secure and private file management/backup solution, and still face a lot of competitors.
[1] Obligatory: https://news.ycombinator.com/item?id=8863