Live data from Hacker News

We found a stable Firefox identifier linking all your private Tor identities

fingerprint.com

101–110 of 306 posts

Re: We found a stable Firefox identifier linking all your private Tor identities

#101

I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?

Browser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult t…

I fantasize having a browser that I can use only for viewing content.

No applications. No mail. No need for cookies.

I can use a "regular" browser for more enhanced stuff. But for simple content consumption, we can just have a "dumb" browser that can't do much.

> A user agent that says the browser's version? Reasonable enough.

No user agent. I'm guessing it will need it for JavaScript or HTML features, and dynamically update if using an old browser, but let's just not supply a user agent and let it be the reader's burden to have a reasonably decent browser.

> Being able to ask for fonts, if the system has them? Difficult to have font support without that.

What's the fallback if the system doesn't have them?

> Getting the user's timezone, language and keyboard layout? Reasonable.

Keyboard layout is irrelevant for viewing content. For timezone and language: Yeah, I can see the use cases, but these are in a small minority. Let there be a popup when requested, and the user can specify the timezone/language as requested.

> The size of the screen, and the size of the browser window? Difficult to lay things out without that.

Let's let this new browser return only from a (small) discrete set of sizes. It will pick the size closest to the actual browser window size and send that.

> Of course a video or audio player needs to know which video formats your browser supports - how else to provide the right video?

Same answer as user agent. Either let the user pick from a selection of video formats, or just hard code a reasonable one and put the onus on the user to have a browser that supports it.

> Obviously javascript can get the time, and it's trivial to figure out the system's clock error by comparing that to the time on a server.

This hypothetical browser could just not send the time :-) For 99% of content consumption, this function is not needed.

What I'm describing should be part of "Private mode". Or browsers should have an "Ultra-private" mode that is the above. If it's too complex/risky maintaining it all in one codebase ... fine. Just have a separate browser.

Right now, if I built such a browser, I'm sure a lot of sites meant for content would break. But in my fantasy world, using "Ultra-private" would be the default, and people who make sites will target them first.

I think much of the complexity in making a web browser is all the "other" stuff. Being able to run apps, cookie/privacy management, etc.

Re: We found a stable Firefox identifier linking all your private Tor identities

#102

> Because the behavior is process-scoped rather than origin-scoped Hmm, I'm a little confused, since in 2021 Mozilla released experimental one-process-per-site: > This fundamental redesign of Firefox’s Security architecture extends current security mechanisms by creating operating system process-level boundaries for all sites loaded in Firefox for Desktop https://blog.mozilla.org/security/2021/05/18/introducing-sit..…

https://news.ycombinator.com/item?id=47868736 helps me understand that there's a sliver of behaviour that happens to be global, and this thus allows fingerprinting.

If so, cool!

Re: We found a stable Firefox identifier linking all your private Tor identities

#103
post #80

Earlier quoted context omitted.

Instead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread? On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?

There's a pretty big difference between: 1) wanting functionality that isn't provided and working around that and 2) restoring such functionality in the face of countermeasures The absence of functionality isn't a clear signal of intent, while countermeasures against said functionality is. And then there is the distinction between the intent of the software publisher and the intent of the user. There is a big ethical…

The presence of the "Do Not Track" header was a pretty clear indicator of the intent of the user. Fingerprinting persisted exactly in the face of such countermeasures.

Re: We found a stable Firefox identifier linking all your private Tor identities

#104

Honestly it seems that most of Web Standards are used mostly for fingerprinting - I think a small number of websites uses IndexedDB (who even needs it) for actually storing data rather than fingerprinting. That's why expansion of web standards is wrong. Browser should provide minimal APIs for interacting with device and features like IndexedDB can be implemented as WebAssembly library, leaking no valuable data. For e…

[deleted]

Re: We found a stable Firefox identifier linking all your private Tor identities

#105

Earlier quoted context omitted.

Responsible disclosure and commercial fingerprinting aren't contradictory.

[flagged]

It's a little bit disingenuous to call intentional wont-fix features "vulnerabilities".

Re: We found a stable Firefox identifier linking all your private Tor identities

#106
post #15
post #3

Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting? Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors bur…

We don't use vulnerabilities in our products.

All fingerprinting is a vulnerability, unless the client opts-in.

Re: We found a stable Firefox identifier linking all your private Tor identities

#107

Earlier quoted context omitted.

What are you even saying? It's like getting upset at somebody who criticizes a criminal because they once helped some grandma across the street. I'm not upset at the criminal because they helped a grandma across the street obviously that's not the fucking point.

I'm not upset, I just don't think we should criticize someone for doing something good. Maybe they're a terrible org, maybe they deserve criticism most of the time, but not in this instance. It's not like you can't point out that they did a good deed, but that they're still in the shitty business of fingerprinting users. Also, if people only get the stick no matter what they do, then eventually some will embrace the…

The inverse is also true, letting them whitewash their image by pretending they care about your privacy and seek to protect you will be good for their public relations, but only if we let them. I refuse to be this gullible and run to their defense for no apparent reason.

Re: We found a stable Firefox identifier linking all your private Tor identities

#108

I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?

Browser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult t…

All of these could have a set of standard non identifiable answers (eg. firefox reports the same 20 fonts, couple video formats, one among a few standard window sizes etc.) and for anything more extensive/precise, it would require the user's authorization and the user should have the option of feeding fake info (eg. fake timezone)

Re: We found a stable Firefox identifier linking all your private Tor identities

#109

Earlier quoted context omitted.

Most stock android phones don't either. You usually get to control precise location, notifications, some background activity, SMS, Calls, Mic, Camera, SD Card, etc. But most ROMs don't allow controls for WiFi, Cell data, Phone ID, Phone number, User ID, local storage, etc...

all these permission you have to accept?

Yes. A few apps have been caught doing nefarious stuff using advertising sdks, like meta, but on android most apps are well sandboxed and can only access what you approve.

Re: We found a stable Firefox identifier linking all your private Tor identities

#110

Earlier quoted context omitted.

Browser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult t…

I fantasize having a browser that I can use only for viewing content. No applications. No mail. No need for cookies. I can use a "regular" browser for more enhanced stuff. But for simple content consumption, we can just have a "dumb" browser that can't do much. > A user agent that says the browser's version? Reasonable enough. No user agent. I'm guessing it will need it for JavaScript or HTML features, and dynamicall…

Unfortunately you've now made an incredibly niche browser, and the lack of those metrics is a good fingerprint by itself. How browsers render SVGs can be used for fingerprinting (even the underlying OS affects this, and I assume you'll want to see those), combine with ISP from IP address, and unless theres hundreds users in every city you're now pretty easily trackable.
Post reply on HN