Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

11–20 of 524 posts

Re: Web fingerprinting is worse than I thought

#12
I don't understand the test on this page. It says we should be worried because a fingerprinting website generates the same hash even after you clear your cache and site-data, and even if you go into a private tab. But I'm not overly concerned by this, provided I share that hash with other people.

The worry would be that the hash is unique to me (i.e. a fingerprint), but I don't see the evidence that it is.

Re: Web fingerprinting is worse than I thought

#15

I wish browsers did more to combat this. There should be ways to randomize or normalize every bit of information they try to gather.

It’s a double edged sword you need to walk the edge of. Almost everything they use to fingerprint you has a fully legitimate use case which is why it was added.

The more you do to prevent fingerprinting the more you hobble the web as a platform. A lot of restrictions that got placed on the canvas tag to help prevent fingerprinting for instance really limited its functionality.

In my opinion a workable solution would be to make more of these things opt-in by the end user to high accuracy data for the page.

Re: Web fingerprinting is worse than I thought

#16
post #2

If you don't pay attention to it you might be surprised how non dynamic your residential internet last mile DHCP assigned IP really is. It's not uncommon to go many months or a year with having it always renew to the same address. That, combined with all the fingerprinting mentioned in the article...

Indeed. The IP looks like a strong signal in the overall game of fingerprinting.

Re: Web fingerprinting is worse than I thought

#17
post #7
post #2

If you don't pay attention to it you might be surprised how non dynamic your residential internet last mile DHCP assigned IP really is. It's not uncommon to go many months or a year with having it always renew to the same address. That, combined with all the fingerprinting mentioned in the article...

This would be one of the things about IPv6, we'd have lifetime fixed IP addresses (or address ranges at least). Wouldn't we?

Then IPv6 adoption must be frustrated at all costs, in the name of liberty ...of course.
Post reply on HN