Maybe firefox should also install ublock origin by default? This isn't just for some power users- it will increase their share among regular people whose pages will load even faster making Firefox popular. Or are they waiting until the user share falls below 5%? Maybe they should listen to Andy grove and prepare now.
They should turn fingerprinting to max and install uBlock origin by default. It might mean millions of FF users would suddenly struggle with captchas, but it might also mean that site creators just stop using reCaptcha and similar.
Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
141–150 of 216 posts
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#142Earlier quoted context omitted.
Yup it's disgusting. Even in private mode sites know it's me with my build version and ip.
To be honest most people are confused about "private mode", I agree there should be privacy options enabled by default with it, but the reality is pretty much "no browser history will be stored (locally) and your session / cookies will be isolated between private mode and "normal mode"
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#143Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#144Earlier quoted context omitted.
What CSS file did the browser fetch? The one for screens less than 500px wide? Or the one for screens that are 504px wide? There are a million ways to exfiltrate UI parameters through JS and CSS. It’s hard to both prevent that and still allow JS and responsive pages.
right... developers suck, overall ( I could not reply to the comment below because nyc would not let me)
If you don't understand how the web works and actively dislike the community I don't understand why you keep commenting here.
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#145Earlier quoted context omitted.
I've been using privacy.resistFingerprinting for a while and also recommend it, but there is one major "side effect": your reCAPTCHA score will drop to 0.1 making many websites really tedious to use. It's a price I'm willing to pay though...
reCAPTCHA is a Google thing so it gets blocked in my browser already anyway (by uMatrix). If I need to load it to see a website, I close the tab immediately and go somewhere else.
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#146Earlier quoted context omitted.
Apps need it to determine where to place elements. If it wasn't you would still be able to reverse engineer it by sticking elements outside the viewport and seeing if they're hidden or not. Turns out anonymity is super freaking hard. :-/
Some would take enhanced privacy over properly-functioning sites. I wonder how broken sites would appear if the browser simply lied about such things.
https://github.com/kkapsner/CanvasBlocker/releases
I have been using it and it makes some websites go nuts and Google CAPTCHA takes forever.
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#147I recommend the privacy.resistFingerpriting about:config mentioned. It's been available for a while and does other things too, like changing your user agent.
In about:config if you search for 'resistFingerprinting' there seem to be sub-settings which you can tweak to disable the timer modifications, but even after tweaking them I wasn't able to get performance to be as smooth as when resistFP was completely disabled.
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#148Earlier quoted context omitted.
I suspect that's the biggest reason Google was so interested in "https everywhere". That removed detailed browsing visibility from a lot of entities, but not Google.
I've seen this tendency on HN - if this person/entity does something, I suspect it must be bad or selfish. On the subject of HTTPS - do you think the interests of ordinary consumers are in any way served by continuing on HTTP? Countless websites, even those accepting login credentials used to think that it was acceptable to not take the trouble to set up HTTPS. The only thing the operators of these websites cared abo…
It could simply mean the interests aligned. I get my credentials encrypted and Google gets more [insert stuff here]. When the interests don't align the result is a bit different. You could be sending tracking/location data every few minutes, adblockers could be crippled, you could be forced to sign in to sync Chrome data, etc. Usually the very same stuff Google relies on for revenue.
So what I'm saying is that it's not that outlandish to assume Google had more reasons than your benefit.
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#149Earlier quoted context omitted.
I'm guessing they would lose their financing from Google by adding UBlock.
I don't know the terms but surely there are enough parties willing to pay them- MS would love to shoot with gun on fx shoulders. The engineering effort required to implement this feature is better spent in doing useful things.
Despite all Microsoft's posing and snuggling up to the Open Source world, they're just as bad as Google and Facebook if given the chance. (And they have been as bad in the past.)
Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing
#150Why can't the ad industry just accept that there are some people out there who don't want to see ads and wouldn't click on one to begin with? Then they can honor Do Not Track and those who choose to work in adtech can start working on things that are more productive to their business.
The ad industry was ready to honour DNT. MS killed it by going default.