Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

111–120 of 524 posts

Re: Web fingerprinting is worse than I thought

#111

As the years pass, I keep thinking back and realize that Richard Stallman was right all along: > For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time.

I think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built…

The GNU/Hurd in the IA didn’t already do it?

Re: Web fingerprinting is worse than I thought

#112

Earlier quoted context omitted.

I think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built…

WGET can be pretty trivially told to send custom headers.

It would be a lot of work to make it mimic a common profile though.

Re: Web fingerprinting is worse than I thought

#113
post #75

Why is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.

The short answer which should be obvious... regulatory doesn't work, legal doesn't currently work.

The burden of proof is on the claimant, and with proper information control you can't ever meet that burden of proof. It becomes an ant versus a gorilla instead of David vs. Goliath.

Tell me, how do you differentiate a simple random alpha-numeric string from another random string that may have been generated as a fingerprint.

Mathematically do you think there's any way to actually prove one way or the other? If not, how would that bias the system if the person is adversarial and lies.

The only way to prevent this is to make sure the information is nonsensical.

Preventing collection would identify you in a way that they can prevent access. Even though websites are public, you see this happening with any captcha service.

Re: Web fingerprinting is worse than I thought

#114

Earlier quoted context omitted.

"Some site operators can make a believable argument that they use it in ways that are good for society." Example please

Credit Card Fraud, Spam, etc

Even if this were the case - which I don’t actually believe, but… - it would be straightforward for that law to also constrain these purposes and prevent data sharing with non-worthy operations. At present it’s basically a free for all.

Re: Web fingerprinting is worse than I thought

#115
post #75

Why is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.

Because bad actors have an easy time on an actually global network. It's disturbingly hard to hold bad actors accountable, particularly if they have zero legal presence (e.g. a corporation's subsidiary) in one's jurisdiction.

But we’re talking here about major corporations who would (largely) follow the law if there was a law with teeth commensurate with the potential rewards form abuse of privacy.

Re: Web fingerprinting is worse than I thought

#116
post #113
post #75

Why is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.

The short answer which should be obvious... regulatory doesn't work, legal doesn't currently work. The burden of proof is on the claimant, and with proper information control you can't ever meet that burden of proof. It becomes an ant versus a gorilla instead of David vs. Goliath. Tell me, how do you differentiate a simple random alpha-numeric string from another random string that may have been generated as a finger…

Can you provide any proof that "regulatory doesn't work"?

Might be my European outlook, but consumer law has been stupidly effective at curbing abuses from companies here and was much more effective than playing the technology race USA is trying to fight. There's always a next side-step, the next abuse a company can invent - and you keep trying to push the responsibility of avoiding it to users (by adding more and more onerous technology) instead of punishing the abusers.

Re: Web fingerprinting is worse than I thought

#117

As the years pass, I keep thinking back and realize that Richard Stallman was right all along: > For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time.

I think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built…

I'm pretty sure wget has plenty more users in addition to Stallman

Re: Web fingerprinting is worse than I thought

#118
post #75

Why is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.

Because bad actors have an easy time on an actually global network. It's disturbingly hard to hold bad actors accountable, particularly if they have zero legal presence (e.g. a corporation's subsidiary) in one's jurisdiction.

Is it really that hard? I haven't seen anyone from US actually attempt any accountability - zero punishments for spam callers, zero punishments for data collectors, not even a semblance of attempt to punish data traffickers?

Re: Web fingerprinting is worse than I thought

#119
post #104

Earlier quoted context omitted.

These are valid use-cases I agree. However I don't see why should be leaky to support those use-cases. Browsers should ensure all operations produce identical results across platforms and hardware, and anything in the spec that prevents this should be removed from the spec. Now, I recognize some of that functionality is handy for certain apps. In that case do like Android and put it behind an opt-in API, so the user…

The real snag comes from putting text into a canvas. Nobody can agree on what fonts they have installed, and of course there are all kinds of subtle variations from one version of the “same” font to the next, and then everyone has different ideas about hinting, kerning, stem widths, etc, etc, etc. You can fingerprint basically everyone just from that information alone.

Sure fonts and text is hard. But none of that is needed for basic surfing of the web.

Re: Web fingerprinting is worse than I thought

#120
post #89

Earlier quoted context omitted.

The article describes "Fingerprinting as a Service. Some choice quotes: It doesn’t matter if you are using a VPN or Private Browsing mode, they can accurately identify you. Also note that VPNs does not help with fingerprinting. They only masks IP address.

right. but using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts. My point was that fingerprinting is much more practical and useful as a positive form of identity verification than it is as a tracking devi…

one point is that I may not have any specific sites I care about disassociating myself with. I just don’t want an aggregate picture to be built and sold freely.

Cliche example/ I want to be able to buy a pregnancy test online but don’t want that information shared and re marketed to me. There is plenty of stuff like this. The impact of privacy violation is small and often boring but on aggregate corrosive to public discourse and individual wellbeing.

Post reply on HN