Live data from Hacker News

Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

zdnet.com

121–130 of 216 posts

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#121

Every time there's something about online privacy with browsers, it's mostly Firefox or Safari. I wondered if Chrome had resisting fingerprinting on its radar (guessing that it wouldn't be in Google's interests to add any feature that would thwart profiling users online), and I found this [1] confirming my guess (emphasis mine): > Since we don't believe it's feasible to provide some mode of Chrome that can truly prev…

There is a way to stop fingerprinting. That way is serving pages via distributed network (over a WoT or torrent-like thing). All these other ways do is give people the illusion that they're safe from being tracked, when the reality is that they're tracked just the same, but by fewer people so the data is more valuable. This means that the money is centralizing around the actors with the most inexplicable methods of t…

Protocol wise, basic shared VPNs will stop most everything short of a semi-global passive adversary. The problem is running hostile code on your own machine, coupled with browser makers thinking it is a generally fantastic idea to allow that hostile code to access a whole slew of security-sensitive information.

Sure, VPN won't repudiate the region bullshit, and can even be outright blocked. But if adoption rose to the point websites didn't want to lose the traffic, those would diminish.

However, I do agree a non-immediate user-centric protocol is sorely needed though, especially to stop those global snooping adversaries.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#122
post #69

Earlier quoted context omitted.

I suspect that's the biggest reason Google was so interested in "https everywhere". That removed detailed browsing visibility from a lot of entities, but not Google.

Can you elaborate on that? Are you talking about the https everywhere extension from the EFF, because I wasn't aware Google had a part in that.

I don't agree with him but Google penalizes non-HTTPS results etc.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#123
post #15
post #13

I recommend the privacy.resistFingerpriting about:config mentioned. It's been available for a while and does other things too, like changing your user agent.

I've been using privacy.resistFingerprinting for a while and also recommend it, but there is one major "side effect": your reCAPTCHA score will drop to 0.1 making many websites really tedious to use. It's a price I'm willing to pay though...

No wonder reCAPTCHA sucks so hard. I hardly ever run into it, but it's a PITA.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#124
post #5

> The general idea is that "letterboxing" will mask the window's real dimensions by keeping the window width and height at multiples of 200px and 100px during the resize operation --generating the same window dimensions for all users-- and then adding a "gray space" at the top, bottom, left, or right of the current page. > The advertising code, which listens to window resize events, then reads the generic dimensions,…

> Would using a setTimeout() on the window resize event bypass this? Send the data 20-50ms after resize is completed giving enough time for the letterboxing stuff to go away revealing the actual dimensions, or something? They say it only blocks the dimensions during the resize event and FF removes the letterboxing "a few ms later"

No, it will be a setTimeout on the document load event that will poll the window size every 100ms from here till the page is evicted by a close or navigation event, increasing the detrimental effect of adtech.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#125
post #115

Why can't the ad industry just accept that there are some people out there who don't want to see ads and wouldn't click on one to begin with? Then they can honor Do Not Track and those who choose to work in adtech can start working on things that are more productive to their business.

The ad industry was ready to honour DNT. MS killed it by going default.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#126
post #69

Earlier quoted context omitted.

I suspect that's the biggest reason Google was so interested in "https everywhere". That removed detailed browsing visibility from a lot of entities, but not Google.

Can you elaborate on that? Are you talking about the https everywhere extension from the EFF, because I wasn't aware Google had a part in that.

They’re talking about Chrome’s (and other browsers’) marking of http sites as insecure, and Google-as-a-search-engine penalising non-HTTPS sites. These are good things.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#127
post #120

Every time there's something about online privacy with browsers, it's mostly Firefox or Safari. I wondered if Chrome had resisting fingerprinting on its radar (guessing that it wouldn't be in Google's interests to add any feature that would thwart profiling users online), and I found this [1] confirming my guess (emphasis mine): > Since we don't believe it's feasible to provide some mode of Chrome that can truly prev…

Here's a good comparison: Android Chrome's user agent: Mozilla/5.0 (Linux; Android 6.0.1; SM-G928F Build/MMB29K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Mobile Safari/537.36 Versus Android Firefox's user agent: Mozilla/5.0 (Android 9; Mobile; rv:66.0) Gecko/66.0 Firefox/66.0 Note how the Chrome browser announces your phone model and software build version to the world. With regional models with car…

Yup it's disgusting. Even in private mode sites know it's me with my build version and ip.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#128
post #15
post #13

I recommend the privacy.resistFingerpriting about:config mentioned. It's been available for a while and does other things too, like changing your user agent.

I've been using privacy.resistFingerprinting for a while and also recommend it, but there is one major "side effect": your reCAPTCHA score will drop to 0.1 making many websites really tedious to use. It's a price I'm willing to pay though...

> ne major "side effect": your reCAPTCHA score will drop to 0.1 making many websites really tedious to use.

I instantly leave a website that has this aggressive reCaptcha that uses free labour to train algorithms.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#129
post #69

Earlier quoted context omitted.

> guessing that it wouldn't be in Google's interests to add any feature that would thwart profiling users online I would actually think the opposite. Wouldn't it be better because then only Google would have that information? Only Google would be able to fingerprint. This is of course under the assumption (which is currently accurate) that Google has the majority share of browsers. But maybe it wouldn't be, because i…

I suspect that's the biggest reason Google was so interested in "https everywhere". That removed detailed browsing visibility from a lot of entities, but not Google.

I've seen this tendency on HN - if this person/entity does something, I suspect it must be bad or selfish.

On the subject of HTTPS - do you think the interests of ordinary consumers are in any way served by continuing on HTTP? Countless websites, even those accepting login credentials used to think that it was acceptable to not take the trouble to set up HTTPS. The only thing the operators of these websites cared about was being marked "insecure" by the most popular browser. The shift to HTTPS was a definite win for privacy for every person who uses the web.

But no. Apparently, the "biggest reason" for the people working at Google pushing this because it was good for Google. They didn't care about all the benefits for end users, they only cared about themselves.

It's sad that slander like this can become mainstream view in a forum like HN.

Disclaimer - no connection to Google in any way. Don't even own Google stock.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#130
post #69

Earlier quoted context omitted.

I suspect that's the biggest reason Google was so interested in "https everywhere". That removed detailed browsing visibility from a lot of entities, but not Google.

I've seen this tendency on HN - if this person/entity does something, I suspect it must be bad or selfish. On the subject of HTTPS - do you think the interests of ordinary consumers are in any way served by continuing on HTTP? Countless websites, even those accepting login credentials used to think that it was acceptable to not take the trouble to set up HTTPS. The only thing the operators of these websites cared abo…

> Apparently, the "biggest reason" for the people working at Google pushing this because it was good for Google.

I mean, when I do stuff at my job, I also do things that are good for the company that pays me. That's the job, right?

The problem is that Google has positioned itself in a way where things that are good for Google might be bad for humanity as a whole.

Post reply on HN