Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

121–130 of 524 posts

Re: Web fingerprinting is worse than I thought

#121

Earlier quoted context omitted.

WGET can be pretty trivially told to send custom headers.

It would be a lot of work to make it mimic a common profile though.

That work was probably done once, years ago. Might need a few string tweaks every few years, which could be automated.

Re: Web fingerprinting is worse than I thought

#122
post #89

Earlier quoted context omitted.

The article describes "Fingerprinting as a Service. Some choice quotes: It doesn’t matter if you are using a VPN or Private Browsing mode, they can accurately identify you. Also note that VPNs does not help with fingerprinting. They only masks IP address.

right. but using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts. My point was that fingerprinting is much more practical and useful as a positive form of identity verification than it is as a tracking devi…

Your point might even be that "fingerprinting is much more practical and useful as a positive form of identity verification" but we all know how fingerprinting tech is and will be used: to track users even more and try sell even more crap to them because that's what almost the entire internet is all about.

And as for this

> using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts

How do you plan to do all that on your mobile device for example? Fingerpirinting is a problem exactly like invasive tracking is a problem.

Re: Web fingerprinting is worse than I thought

#123
post #75

Why is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.

Laws only apply in some countries. The internet is global. Technical measures are faster, more effective, and can be applied in all places.

Re: Web fingerprinting is worse than I thought

#124

Earlier quoted context omitted.

... on a new computer, each time ordered from a different brand and reseller, paid with a unique type of cryptocurrency and delivered each time to a new dead drop in a different country.

I tried live boot of ubuntu. Every time it can detect accurately. Looks like the whole privacy thing is OVER. Unless lawmakers do something - (i.e) not going to happen! Atleast they can use this to prevent reCaptcha - and make passwords disappear!

Ubuntu has a lot of unique information that is readily accessible.

Machine-ID in /etc being one, but there's various other items that can be used in the same way from d-bus activation, and something like 20 different other places, another large number in snap.

Re: Web fingerprinting is worse than I thought

#125
post #55
post #15

Earlier quoted context omitted.

It’s a double edged sword you need to walk the edge of. Almost everything they use to fingerprint you has a fully legitimate use case which is why it was added. The more you do to prevent fingerprinting the more you hobble the web as a platform. A lot of restrictions that got placed on the canvas tag to help prevent fingerprinting for instance really limited its functionality. In my opinion a workable solution would…

Well, we could fingerprint the fingerprint detection code ...

uBlock Origin in default deny of 3p scripts basically achieves this already.

Re: Web fingerprinting is worse than I thought

#126
post #89

Earlier quoted context omitted.

The article describes "Fingerprinting as a Service. Some choice quotes: It doesn’t matter if you are using a VPN or Private Browsing mode, they can accurately identify you. Also note that VPNs does not help with fingerprinting. They only masks IP address.

right. but using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts. My point was that fingerprinting is much more practical and useful as a positive form of identity verification than it is as a tracking devi…

And you count that as "trivial" for regular user? 90% of users don't know difference between a tab and browser, and you think they would know to setup vpn, vm, and what else to avoid getting tracked.

Re: Web fingerprinting is worse than I thought

#128

Earlier quoted context omitted.

It would be a lot of work to make it mimic a common profile though.

That work was probably done once, years ago. Might need a few string tweaks every few years, which could be automated.

No, because any “RMS” set of headers would only be shared by the small number of nerds who care, fingerprinting us more accurately again.

Re: Web fingerprinting is worse than I thought

#129

I use the usual adblocker UBlock and: * https://addons.mozilla.org/de/firefox/addon/canvasblocker/ which prevents fingerprinting via Canvas elements, additionally warns you if a site does it. There are more sites out there than you would assume. Some stupid blogs even. * https://addons.mozilla.org/en-US/firefox/addon/multi-account... This splits your tabs into different categories, each with their own cookie storage.…

The fingerprinting website in the article didn't manage to correlate me visiting the website concurrently from two distinct container tabs.

But that's merely because of the canvasblocker (or something else you have), because just separate containers doesn't cut it?

Re: Web fingerprinting is worse than I thought

#130

For anyone who this is news to: This is why I always call the "I don't care about cookies" extension an adtech submarine, because it deceives you into thinking it’s all about cookies, when the permission you give automatically in many cases are about tracking, so using that extension will often have you consent that fingerprinting you and creating a profile based on that is perfectly fine.

Implying they actually stop tracking when you press "Reject"
Post reply on HN