Live data from Hacker News

Chrome client “variations” can be used to identify you (2020)

zapek.com

71–79 of 79 posts

Re: Chrome client “variations” can be used to identify you (2020)

#71

This is great and all - but what's the alternative? I've been using Firefox as my primary browser for about 2 years now - and the javascript engine on it has recently... sh*t the bed (I cannot paste links or images into facebook, I cannot paste text with line breaks into twitter, I cannot paste using reddit's "markdownmode"). I use google-chrome for netflix, recently chromium stopped working for netflix (apprently th…

I am not sure what is the issue with your system but I am using Chromium with Netflix on Linux (arch so I guess pretty much latest versions of everything) just fine

Re: Chrome client “variations” can be used to identify you (2020)

#74
post #58
post #39

Earlier quoted context omitted.

um, no? See the famous story of Hushmail [0], which used end-to-end encryption and claimed to have no access to user email until receiving a court order. Then they modified the code they send to one client to exfiltrate encryption keys to law enforcement, and decoded all the "end to end encrypted" email. Sure, they claim they are open source and that the infrastructure was audited, but this does not prevent them from…

Alright, that's fair. Guess self-hosting is the only foolproof approach for complete privacy then.

It was always like that. If your threat model is three letter agency/Mossad/etc than you have very limited options. Relevant XKCD: https://xkcd.com/538/

Re: Chrome client “variations” can be used to identify you (2020)

#75
post #39
post #20

Earlier quoted context omitted.

Bitwarden uses end-to-end encryption. So you don't have to trust them as much as Google.

um, no? See the famous story of Hushmail [0], which used end-to-end encryption and claimed to have no access to user email until receiving a court order. Then they modified the code they send to one client to exfiltrate encryption keys to law enforcement, and decoded all the "end to end encrypted" email. Sure, they claim they are open source and that the infrastructure was audited, but this does not prevent them from…

How is this a knock against them in comparison to Google? Does Google not comply with court orders?

Re: Chrome client “variations” can be used to identify you (2020)

#76
post #39
post #20

Earlier quoted context omitted.

Bitwarden uses end-to-end encryption. So you don't have to trust them as much as Google.

um, no? See the famous story of Hushmail [0], which used end-to-end encryption and claimed to have no access to user email until receiving a court order. Then they modified the code they send to one client to exfiltrate encryption keys to law enforcement, and decoded all the "end to end encrypted" email. Sure, they claim they are open source and that the infrastructure was audited, but this does not prevent them from…

> Then they modified the code they send to one client to exfiltrate encryption keys to law enforcement, and decoded all the "end to end encrypted" email

This is false. The decryption code was run on the server, which means the password was sent to the server briefly. Hushmail simply stored the password for a few accounts. No client code was modified nor any auto-update changed. In fact, if the criminals had used the Java applet, they'd likely have gotten away with it (assuming they didn't update it)

>However, installing Java and loading and running the Java applet can be annoying. So in 2006, Hushmail began offering a service more akin to traditional web mail. Users connect to the service via a SSL (https://) connection and Hushmail runs the Encryption Engine on their side. Users then tell the server-side engine what the right passphrase is and all the messages in the account can then be read as they would in any other web-based email account.

>The rub of that option is that Hushmail has -- even if only for a brief moment -- a copy of your passphrase. As they disclose in the technical comparison of the two options, this means that an attacker with access to Hushmail's servers can get at the passphrase and thus all of the messages.

Re: Chrome client “variations” can be used to identify you (2020)

#77

Earlier quoted context omitted.

tbf they're fairly competent with it, I don't think I've ever had anything Google related compromised. I'm honestly not sure what the better solution is. There's a lot of security theater around this where people will de-google their software and then run random binaries compiled by unknown people on the internet instead

> I'm honestly not sure what the better solution is. How about a browser company that syncs your data on their servers but doesn’t examine it. Even better, they couldn’t do that even if they wanted to, because your data is encrypted on their servers. That company has also never been compromised. Does that sound better?

I don't think Google does examine drive data by default, fairly sure it's encrypted.

complete E2E encryption Signal style with you having sole access to the keys and sync is technically pretty non-trivial across multiple devices (also the reason they don't sync device history on previously unlinked devices), so there's a usability / security trade-off.

Honestly not certain whether that fits the need of most users for most data they have.

Re: Chrome client “variations” can be used to identify you (2020)

#78

Earlier quoted context omitted.

> I'm honestly not sure what the better solution is. How about a browser company that syncs your data on their servers but doesn’t examine it. Even better, they couldn’t do that even if they wanted to, because your data is encrypted on their servers. That company has also never been compromised. Does that sound better?

I don't think Google does examine drive data by default, fairly sure it's encrypted. complete E2E encryption Signal style with you having sole access to the keys and sync is technically pretty non-trivial across multiple devices (also the reason they don't sync device history on previously unlinked devices), so there's a usability / security trade-off. Honestly not certain whether that fits the need of most users for…

What do you mean by drive data?

Re: Chrome client “variations” can be used to identify you (2020)

#79

Earlier quoted context omitted.

This is why China bans these companies long ago. Imagine handing your population’s intel on a silver platter to your adversary.

These companies are banned for refusing to share the data they collect with the government. Essentially the Chinese government is a competitor when comes to harvesting user data, not a privacy guard.

I don’t think it is ever intended to be a privacy guard but data exfiltration prevention and admittedly to control the narrative, as does with every country including your own for obvious reasons.
Post reply on HN