Live data from Hacker News

Supercookie: Browser Fingerprinting via Favicon (2021)

github.com

101–105 of 105 posts

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#101

Nice to see Brave patched it though.

1st patch: https://github.com/brave/brave-core/commits/master/patches/c...

Rename thumbnail to favicon: https://github.com/brave/brave-core/commits/master/patches/c...

Then abandoned in favor of Chromium including favicons in the regular cache https://news.ycombinator.com/item?id=45954466

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#102
post #95

Earlier quoted context omitted.

You guys have favicons? I don't have any in my tabs, but maybe I have turned that of at some point. I'm using Mozilla Firefox.

Firefox and Safari both have favicons in the tabs.

Yes, I also have them in general, e.g. on about:newtab, but for HN, there isn't any shown on the tab (there is if I make a bookmark). Maybe I messed something up.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#103

Earlier quoted context omitted.

> As long as you're on _my (online) property_ and using _my services_ I can of course see EVERYTHING you f do That's fine, but you are not allowed to send me malware, that runs on _my property_ and snoops on _my data_. Also data doesn't stop being mine, just because you have it. You also can't take photographs of random people and claim this is yours now. That's an important difference between the USA and European co…

Well, we'd probably agree on most things... and re the photography example, afaik model release forms work similarly in the EU and US, right? Now website code does typically run on your device, but I'd say that once you're a paid logged in user you clearly accepted to run it, under the conditions of it staying in its browser sandbox so... if you think it's "malware" then just stop being a customer. Otherwise software…

> under the conditions of it staying in its browser sandbox so

I consider fingerprinting my browser, by running programs and measuring the timings and characteristics of the browser to be a side-channel attack on the browser sandbox.

> Otherwise software has a right to monitor its own operation.

If websites would only "monitor its own operation", we would hardly have any discussion.

> if you think it's "malware" then just stop being a customer.

Easier said than done, when >90% of websites do this. Show me a mainstream corporations website, that work without Javascript. You can hardly pay for a train ticket and make an appointment to government services, without these crap.

Also there must be some rules what software vendors are allowed to do, since the average user can hardly reverse-engineer all the websites they (need to) visit. This is what regulations like GDPR try to enforce.

> and re the photography example, afaik model release forms work similarly in the EU and US, right?

It's not about contracting a model, it's about doing a random photoshot in public. People have the right to their own picture here, irregardless of who takes that picture and who posses it.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#104

Earlier quoted context omitted.

The link shows Chrome patched and unpatched this.

[Now Chrome] should reset tracking through favicons on cache deletions and when entering incognito mode. - https://issues.chromium.org/issues/40136308#comment19

Should

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#105
post #97

At some point we need actual consequences for sites that intentionally hide their tracking. It should be criminal. It is stalking and has real world consequences. Just because an exploit exists doesn't mean it should be used. That logic is like saying it is OK to break into a house because the lock on the door was weak. If we don't get real protections, at what point does it become justified to go offensive against s…

The only reason these things work is because we let our browsers silently execute arbitrary code. That logic is more like saying it is OK to enter a house because the owner sent you an invitation, then greeted you at the door and said "GO NUTS!".

Trust is a powerful multiplier. By that I mean if you have trust in your city as a safe place you generally don't see bars on windows and have more open, inviting and usable spaces. You have more businesses and happier people. Right now the web is like the worst crime ridden city in the world. There is 0 trust and it means we can't have nice things. Society builds trust by being open and allowing but with enforcement when things do happen. We need to bring that to the web. Right now the enforcement either happens before-hand by blocking something or not at all. I want good browser features. I want companies to use them for my benefit but I also want social and legal repercussions when those features are abused. We need to build up both of those in a durable way. When people see offending sites they should avoid them and spread the word that those businesses are bad. When they cross the line then we need enforcement of not just civil, but also criminal penalties. Basically, we need to avoid removing features and instead start evolving society to be able to interact in this environment in a way that we can trust it.
Post reply on HN