Earlier quoted context omitted.
I think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built…
WGET can be pretty trivially told to send custom headers.
Web fingerprinting is worse than I thought
141–150 of 524 posts
Re: Web fingerprinting is worse than I thought
#142Re: Web fingerprinting is worse than I thought
#143You can try https://www.amiunique.org/fp to get a view of all params can used to track you
It's interesting that they can narrow me down to less than 0.1% with just my language list (en-US,en,fr,ro). My user agent is practically unique as well, since I'm running an unusual configuration. I've never thought of that as a disadvantage when it comes to tracking, hah.
Re: Web fingerprinting is worse than I thought
#144Re: Web fingerprinting is worse than I thought
#145Earlier quoted context omitted.
GDPR doesn't really apply outside of Europe, despite what the EU might claim.
also, one could just roll it up into a wall of fine print or something, no? who reads these things anyway?
Re: Web fingerprinting is worse than I thought
#146For anyone who this is news to: This is why I always call the "I don't care about cookies" extension an adtech submarine, because it deceives you into thinking it’s all about cookies, when the permission you give automatically in many cases are about tracking, so using that extension will often have you consent that fingerprinting you and creating a profile based on that is perfectly fine.
Implying they actually stop tracking when you press "Reject"
Re: Web fingerprinting is worse than I thought
#147Earlier quoted context omitted.
right. but using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts. My point was that fingerprinting is much more practical and useful as a positive form of identity verification than it is as a tracking devi…
one point is that I may not have any specific sites I care about disassociating myself with. I just don’t want an aggregate picture to be built and sold freely. Cliche example/ I want to be able to buy a pregnancy test online but don’t want that information shared and re marketed to me. There is plenty of stuff like this. The impact of privacy violation is small and often boring but on aggregate corrosive to public d…
Fingerprinting is by definition a lot more imprecise and vague. It's always going to be an issue if surveillance networks use it to pick out individual users. Whining about that is useless. It's also a valuable security tool and part of the landscape. Do with it what you can.
Re: Web fingerprinting is worse than I thought
#148Earlier quoted context omitted.
A law needs a justification and needs to apply equally to everyone. Writing that about fingerprinting would not be trivial. Some site operators can make a believable argument that they use it in ways that are good for society.
"Some site operators can make a believable argument that they use it in ways that are good for society." Example please
Re: Web fingerprinting is worse than I thought
#149For anyone who this is news to: This is why I always call the "I don't care about cookies" extension an adtech submarine, because it deceives you into thinking it’s all about cookies, when the permission you give automatically in many cases are about tracking, so using that extension will often have you consent that fingerprinting you and creating a profile based on that is perfectly fine.
For me, the cookie consent modals are the submarines. Why would I outsource the responsibility not to track me to the people with the incentive to track me? IDCAC, Cookie Autodelete, and strict tracking protection feels like the better alternative for me.
(From today onwards, I'll add resistFingerprinting=true to that list as well.)
Re: Web fingerprinting is worse than I thought
#150Earlier quoted context omitted.
The real snag comes from putting text into a canvas. Nobody can agree on what fonts they have installed, and of course there are all kinds of subtle variations from one version of the “same” font to the next, and then everyone has different ideas about hinting, kerning, stem widths, etc, etc, etc. You can fingerprint basically everyone just from that information alone.
Sure fonts and text is hard. But none of that is needed for basic surfing of the web.