Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

101–110 of 524 posts

Re: Web fingerprinting is worse than I thought

#101
post #38

Earlier quoted context omitted.

Just because you can doesn't mean you should. Worst ethics ever. I hope you go broke.

The main use case that we're tackling is financial fraud, scams, account takeover and more. - Over $32billion is stolen yearly online due to financial fraud, and browser fingerprinting has proven to be one of the most reliable way to combat sophisticated fraudsters

Next you tell me this thing will be saving us from child porn or even terrorism.

Re: Web fingerprinting is worse than I thought

#102
post #96
post #75

Why is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.

A law needs a justification and needs to apply equally to everyone. Writing that about fingerprinting would not be trivial. Some site operators can make a believable argument that they use it in ways that are good for society.

"Some site operators can make a believable argument that they use it in ways that are good for society."

Example please

Re: Web fingerprinting is worse than I thought

#103
post #80

You can try https://www.amiunique.org/fp to get a view of all params can used to track you

It's interesting that they can narrow me down to less than 0.1% with just my language list (en-US,en,fr,ro). My user agent is practically unique as well, since I'm running an unusual configuration. I've never thought of that as a disadvantage when it comes to tracking, hah.

I have "prefer English, German as fallback". That alone makes me almost unique as well. Not fully (like your special config :D), but enough that other resist fingerprinting options become meaningless.

Re: Web fingerprinting is worse than I thought

#104

Earlier quoted context omitted.

> the page unnecessarily copies the image into a and then tries to upload the data from the instead of the original image. Surely there could be valid reasons for doing so? I imagine for example that: 1. It ensures the selected file is a valid image before uploading it 2. It strips meta data like GPS position from the image before uploading it 3. It could reduce the size of the image, by either scaling it down, or co…

These are valid use-cases I agree. However I don't see why should be leaky to support those use-cases. Browsers should ensure all operations produce identical results across platforms and hardware, and anything in the spec that prevents this should be removed from the spec. Now, I recognize some of that functionality is handy for certain apps. In that case do like Android and put it behind an opt-in API, so the user…

The real snag comes from putting text into a canvas. Nobody can agree on what fonts they have installed, and of course there are all kinds of subtle variations from one version of the “same” font to the next, and then everyone has different ideas about hinting, kerning, stem widths, etc, etc, etc. You can fingerprint basically everyone just from that information alone.

Re: Web fingerprinting is worse than I thought

#105

Earlier quoted context omitted.

GDPR doesn't really apply outside of Europe, despite what the EU might claim.

also, one could just roll it up into a wall of fine print or something, no? who reads these things anyway?

> also, one could just roll it up into a wall of fine print or something, no?

That also violates it. Facebook just lost in court in the first instance trying that.

Re: Web fingerprinting is worse than I thought

#106

As the years pass, I keep thinking back and realize that Richard Stallman was right all along: > For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time.

I think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built…

WGET can be pretty trivially told to send custom headers.

Re: Web fingerprinting is worse than I thought

#107

Earlier quoted context omitted.

> the page unnecessarily copies the image into a and then tries to upload the data from the instead of the original image. Surely there could be valid reasons for doing so? I imagine for example that: 1. It ensures the selected file is a valid image before uploading it 2. It strips meta data like GPS position from the image before uploading it 3. It could reduce the size of the image, by either scaling it down, or co…

These are valid use-cases I agree. However I don't see why should be leaky to support those use-cases. Browsers should ensure all operations produce identical results across platforms and hardware, and anything in the spec that prevents this should be removed from the spec. Now, I recognize some of that functionality is handy for certain apps. In that case do like Android and put it behind an opt-in API, so the user…

> I think browsers need a "web app" mode and a "surf mode"

Agree. It will be hard to define a standard for "surf mode", but in addition to privacy benefits there would be security benefits for the browser container as well.

Re: Web fingerprinting is worse than I thought

#108
post #96

Earlier quoted context omitted.

A law needs a justification and needs to apply equally to everyone. Writing that about fingerprinting would not be trivial. Some site operators can make a believable argument that they use it in ways that are good for society.

"Some site operators can make a believable argument that they use it in ways that are good for society." Example please

Credit Card Fraud, Spam, etc

Re: Web fingerprinting is worse than I thought

#109
For anyone who this is news to: This is why I always call the "I don't care about cookies" extension an adtech submarine, because it deceives you into thinking it’s all about cookies, when the permission you give automatically in many cases are about tracking, so using that extension will often have you consent that fingerprinting you and creating a profile based on that is perfectly fine.

Re: Web fingerprinting is worse than I thought

#110
post #41

Earlier quoted context omitted.

What makes you think that this is a worthwhile addition to the world?

We're focused on serving ethical use cases such as combating fraud, account takeover, scams and more.

How many clients have you refused to work with for ethical reasons after they offered you money?
Post reply on HN