Live data from Hacker News

Chrome is entrenching third-party cookies that will mislead users

brave.com

141–150 of 329 posts

Re: Chrome is entrenching third-party cookies that will mislead users

#141
post #65

Earlier quoted context omitted.

> or your favorite websites won't work If my favorite websites stop working with Firefox, they won't be my favorite websites anymore. I'll just stop using them instead.

I'll just stop using them instead. Easily said, until it's your bank, or a government entity, or the electric company, or any of the thousands of other entities that have started blocking Firefox. Firefox should really camouflage its user agent, or make it trivial to do so.

>Firefox should really camouflage its user agent, or make it trivial to do so.

Mozilla employee made an easy user agent switcher called Chrome Mask

https://old.reddit.com/r/firefox/comments/1eic7bj/chroe_mask...

Re: Chrome is entrenching third-party cookies that will mislead users

#142

Earlier quoted context omitted.

> I've heard that fake data, like from AdNausium, just becomes noise as the advertisers know the patterns to filter them out. It's actually much worse. That fake data is dangerous because data brokers don't really care how accurate their data is. Even the fake data AdNausium stuffs into your dossier will be used against you eventually, just like the real data will be. If you get turned down for a job, or your health…

> If you get turned down for a job, or your health insurance rates go up, or you have to pay more for something than you would have otherwise It must suck to live in a capitalist dystopia. Dunno why Americans put up with it.

It's the democracy. The big capital one.

/s

Re: Chrome is entrenching third-party cookies that will mislead users

#143
post #122

Earlier quoted context omitted.

Fine enough, if the ranges for each value are wide enough. Compare: - $120-140k, hetero, white, 190-220 lb, broadly Christian. - $137,500/y, prefers tall redhead females, Irishman originally from Cork, 197 lb, observant Catholic. The first one is too unspecific, while the second could suffice to identify a particular person in a neighborhood. What makes a butter knife safe is not that it's completely devoid of an edg…

Now substitute the first one for "gay", and you might get a death sentence in several parts of the world. Why does almost nobody on this site thinks about the wider world bedsides their own extremely privileged position? I would very much prefer for advertisers to not even be able to determine my city, for personal safety. Throwaway account for obvious reasons.

This is very true. Usually the discussion goes about tracking by commercial entities in rich Westernized countries, which, by no coincidence, are the principal market of the ad industry. (Yes, China exists and is a huge market, but commercial tracking is a minor problem here, compared to other forms of surveillance.)

If you belong to such a category that the mere belonging to it is a death sentence, if revealed, the situation is vastly different. You have to act more like a secret agent or a spy. This means constant, pervasive, fastidious opsec. Any death-sentence-invoking activities should be strictly separated from the normal civil life. Only use the normal browser to visit commerce, official news, and government web sites. Everything that is not openly pious and loyal should belong to ephemeral VMs with a fresh browser install every time (preferably several different), VPNs that are indistinguishable from legitimate web traffic, like XRay, truecrypt-protected media with some plausible deniability data, etc. It all takes quite some technical chops, but is not sufficient. Many other small details, related to technology or not, have to be carefully, well, sanitized, and any small slip can out you.

Such undercover life, while possible, is very tiring, takes a lot of extra time and energy, and noticing this also may mark you as suspicious.

Another browser API that may slightly help track you is a minor problem on this background, unless it pierces any of your layers of protection.

Re: Chrome is entrenching third-party cookies that will mislead users

#144
post #61

Earlier quoted context omitted.

That's what I used for a year or so before switching back to Firefox. It's OK, but doesn't come as close to meeting my needs as Firefox does.

Curious about what needs you had that Brave didn't fill?

Lack of sufficient customization and lack of extensions I want. The customization is a big deal because I dislike the Chromium UI and want to be able to fix the worst of it. My dislike of the UI is also a source of grumbling from me about modern Firefox, which has picked up a lot of Chromium and which is also less customizable than it used to be, but I can still fix a lot.

I also want to be able to use the same browser at work as at home, and my workplace banned the use of Brave when it started including a VPN.

Re: Chrome is entrenching third-party cookies that will mislead users

#145
post #111
post #81

Earlier quoted context omitted.

> Brave has received negative press for diverting ad revenue from websites to itself,[30] collecting unsolicited donations for content creators without their consent,[43] suggesting affiliate links in the address bar[49] and installing a paid VPN service without the user's consent.[58] These are the primary issues I hear about regarding Brave on this forum. It's also founded by Brendan Eich who was forced out of Mozi…

Also, BAT being a cryptocurrency already turns off people who aren't fan of crypto.

BAT was what kept me from trying Brave for a very long time, but I eventually tried it nonetheless (I'm back on Firefox now). In fairness to Brave, you can disable the BAT stuff and never have to see it.

Re: Chrome is entrenching third-party cookies that will mislead users

#146

Earlier quoted context omitted.

> I've heard that fake data, like from AdNausium, just becomes noise as the advertisers know the patterns to filter them out. It's actually much worse. That fake data is dangerous because data brokers don't really care how accurate their data is. Even the fake data AdNausium stuffs into your dossier will be used against you eventually, just like the real data will be. If you get turned down for a job, or your health…

> If you get turned down for a job, or your health insurance rates go up, or you have to pay more for something than you would have otherwise It must suck to live in a capitalist dystopia. Dunno why Americans put up with it.

We don’t. Individualized health insurance rates like that are illegal.

Re: Chrome is entrenching third-party cookies that will mislead users

#147
post #110

Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, encrypted DNS without fallbacks, supports SOCKS and Encrypted Client Hello (although almost no website support it). However, it is better to just buy more memory (unless you are lucky to use Apple products). Regarding analytics, I believe browsers should take use…

BTW I don't understand the anti-tracking absolutism. I don't care about being profiled as long as the profile lands me in a group of thousands of people like me. Yes, I live in ${CITY}, identify as ${GEDNER}, am approximately ${AGE_RANGE} years old, run ${BROWSER} under set to ${LOCALE}. This does not allow to easily harm me. If it allows ad networks to target their ads, so be it, uBlock Origin still works well. But…

That's a reasonable stance to take, certainly. I also think it's reasonable for others to be even more sensitive about it. I'm an anti-tracking absolutist because I am angered by the strong-arming, the deception, and the hacking around defenses against it.

The tracking is a constant assault, and I'm no longer willing to put up any of it, even if the data being tracked is relatively minor. Screw the bastards, they've burned one too many bridges.

Re: Chrome is entrenching third-party cookies that will mislead users

#148
post #42

That seems the obvious result of this sort of thing. > Related Website Sets (RWS) is a way for a company to declare relationships among sites, so that browsers allow limited third-party cookie access for specific purposes. So the website itself gets to declare other "blessed" domains that can bypass third party cookie blocks? Big websites are constantly looking for ways to abuse users by bypassing their attempts at p…

No, the website itself does not get to declare this. There’s a master list that they have to submit their site to and go through an approval process. But as the article details, the contents of that preliminary list is already disconcerting. The whole “Google as the arbiter of all things ads” concept is a bust. But the alternative isn’t great either - today’s system of third party cookies allows for far worse. We nee…

> There’s a master list that they have to submit their site to and go through an approval process.

How is that not the website declaring it? Approval processes are meaningless.

> today’s system of third party cookies allows for far worse.

That's why I want zero third party cookies.

Re: Chrome is entrenching third-party cookies that will mislead users

#149
post #58
post #25

Earlier quoted context omitted.

the only two browsers, Chrome and Brave

That doesn't make a bit of sense. There's plenty of browsers, there's chrome, brave, firefox, opera, edge and safari, those are the big ones. There's also a ton of spinoffs like ice weasel or that browser Kagi is developing that I can't remember the name of. Way more than just two chromium browsers in existence.

[dead]

Re: Chrome is entrenching third-party cookies that will mislead users

#150

Earlier quoted context omitted.

> If you get turned down for a job, or your health insurance rates go up, or you have to pay more for something than you would have otherwise It must suck to live in a capitalist dystopia. Dunno why Americans put up with it.

We don’t. Individualized health insurance rates like that are illegal.

We do.

> Insurers contend that they use the information to spot health issues in their clients — and flag them so they get services they need. And companies like LexisNexis say the data shouldn't be used to set prices. But as a research scientist from one company told me: "I can't say it hasn't happened." source: https://www.propublica.org/article/health-insurers-are-vacuu...

See also:

> Is it legal? As explained by William McGeveran, University of Minnesota professor of law, and Craig Konnoth, University of Colorado associate professor of law, it is — largely because federal law hasn’t kept pace with the modern, technological world in which we live. source: https://www.chicagotribune.com/2018/08/29/help-squad-health-...

Another important takeaway from that second article is that none of your "protected" HIPAA data is prevented from being sold as long as it's "anonymized" which is a total joke since it's often trivial to re-identify anonymized data. It's about as secure as requiring companies to ROT13 your data before they sell it. It will be used to identify and target you individually.

Post reply on HN