Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

151–160 of 524 posts

Re: Web fingerprinting is worse than I thought

#151

Look, forget about threat models. It's relatively trivial these days to avoid fingerprinting attacks if you want to (as a private, web browsing individual). I use fingerprinting actively in enterprise apps as a form of silent 3FA. It's a useful backstop. If I have a user who forgot their password but retrieves it via email, I'll usually let them pass if their fingerprint matches one of their priors; otherwise my soft…

I'm afraid your view is how the journey to the *"world where submitting to such fingerprinting actively was mandatory" starts. Something with frogs in very warm water.

Re: Web fingerprinting is worse than I thought

#152
post #126

Earlier quoted context omitted.

right. but using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts. My point was that fingerprinting is much more practical and useful as a positive form of identity verification than it is as a tracking devi…

And you count that as "trivial" for regular user? 90% of users don't know difference between a tab and browser, and you think they would know to setup vpn, vm, and what else to avoid getting tracked.

That's sort of their problem, isn't it? It's not as if those people are reading this and concerned about their privacy.

If they don't care about privacy, they don't deserve it.

Re: Web fingerprinting is worse than I thought

#153

Earlier quoted context omitted.

right. but using a VPN plus a fresh VM running Ubuntu can mostly do the trick. In a pinch, just keep a few different versions of various browsers around when you plan to surf a site that you don't want associated with you. Or change your screen resolution or turn off your fonts. My point was that fingerprinting is much more practical and useful as a positive form of identity verification than it is as a tracking devi…

"Oh look it's that one dude with that weird Ubuntu device coming from an AWS IP again."

wellllll.... using your own AWS IP would definitely be dumb

Re: Web fingerprinting is worse than I thought

#154
post #92

Earlier quoted context omitted.

How does the fingerprinting know the payment method you used to pay for the computer, is that stored somewhere in the operating system? How would they know it was a dead drop also? Genuinely curious.

It was a joke lmao

Someone not getting a joke is funnier to you than the joke itself.

Re: Web fingerprinting is worse than I thought

#155

Earlier quoted context omitted.

> the page unnecessarily copies the image into a and then tries to upload the data from the instead of the original image. Surely there could be valid reasons for doing so? I imagine for example that: 1. It ensures the selected file is a valid image before uploading it 2. It strips meta data like GPS position from the image before uploading it 3. It could reduce the size of the image, by either scaling it down, or co…

These are valid use-cases I agree. However I don't see why should be leaky to support those use-cases. Browsers should ensure all operations produce identical results across platforms and hardware, and anything in the spec that prevents this should be removed from the spec. Now, I recognize some of that functionality is handy for certain apps. In that case do like Android and put it behind an opt-in API, so the user…

> Browsers should ensure all operations produce identical results across platforms and hardware, and anything in the spec that prevents this should be removed from the spec.

You would basically have to kill all hardware accelerated features and run everything in an interpreter. Also make sure that turbo button is set to slow, to get consistent behavior across all CPUs.

The only real way to prevent finger printing is to lock these features away by default and force websites to beg for every single one of them, not a "accept all" screen, make the process so painful that 90% of users would rather avoid those abusive sites entirely, basically the same dark pattern shit every site pulled with the cookie and GDPR accept popups, just in reverse.

Re: Web fingerprinting is worse than I thought

#156
post #124

Earlier quoted context omitted.

I tried live boot of ubuntu. Every time it can detect accurately. Looks like the whole privacy thing is OVER. Unless lawmakers do something - (i.e) not going to happen! Atleast they can use this to prevent reCaptcha - and make passwords disappear!

Ubuntu has a lot of unique information that is readily accessible. Machine-ID in /etc being one, but there's various other items that can be used in the same way from d-bus activation, and something like 20 different other places, another large number in snap.

Websites can access machine-id?

Re: Web fingerprinting is worse than I thought

#157

Using the IP address & user agent alone already gives you nearly 100 % accuracy, so the fact that they can re-identify you when these things stay identical isn't surprising at all. I tested that website as well and if you take care to rotate your IP address their re-identification rate becomes abysmal, especially if you're using a privacy-focused browser and extensions like Privacy Badger / uBlock.

Exactly. IP address identification is the elephant in the room that the article just briefly mentions. Nearly all websites that want to target adds to you use that. It's just so simple to use, you can't switch it off like you can with cookies, except of course by using a VPN but almost nobody does that.

Re: Web fingerprinting is worse than I thought

#158
post #96

Earlier quoted context omitted.

A law needs a justification and needs to apply equally to everyone. Writing that about fingerprinting would not be trivial. Some site operators can make a believable argument that they use it in ways that are good for society.

"Some site operators can make a believable argument that they use it in ways that are good for society." Example please

[deleted]

Re: Web fingerprinting is worse than I thought

#159
post #116
post #113

Earlier quoted context omitted.

The short answer which should be obvious... regulatory doesn't work, legal doesn't currently work. The burden of proof is on the claimant, and with proper information control you can't ever meet that burden of proof. It becomes an ant versus a gorilla instead of David vs. Goliath. Tell me, how do you differentiate a simple random alpha-numeric string from another random string that may have been generated as a finger…

Can you provide any proof that "regulatory doesn't work"? Might be my European outlook, but consumer law has been stupidly effective at curbing abuses from companies here and was much more effective than playing the technology race USA is trying to fight. There's always a next side-step, the next abuse a company can invent - and you keep trying to push the responsibility of avoiding it to users (by adding more and mo…

You don't need proof you just need some sound reasoning about the trends. If it were as effective as you claim, progression in this area would have halted full stop.

Ask yourself how long have those consumer laws been in effect. Has this technology problem progressed during that time (increased or decreased). Have the fines against the large tech companies actually been collected and were they sufficient to curb that behavior or are they still being administrated or adjudicated (decades later)? Have the large tech companies provided all of the information they collect for review (including the intermediates they generate from processing for derivation internally, in a way that discloses all the ways they use it), or did they only provide a plausible alternative, or just the base information collected without explanation. Do you have a way to prove its the former and not the latter?

I'm sure consumer law has been effective at eliminating the provable abuses domestically. If they were effective internationally, why would the problem be progressing to ever more complicated ways of ubiquitous tracking (which are against that law), or even domestically for those multinationals.

Its business as usual and these people know centralized power structures suffer structurally from corruption and malign influence, and as a market force they exploit that.

There's enough money in people's futures that no fine will actually solve the issue because fraud gets baked into the process. Privacy, communication, and agency are what largely compose people's future.

Due process from corporate sovereignty guarantees they can draw it out as long as they need to while continuing to make money off their actions, both increasing costs to regulatory (as a resource drain), and increasing revenue.

The real cost is borne on either the individual or on the public, and corporations have incentive to lie in ways that are difficult or impossible to prove. A lie of omission, is a lie.

In my opinion, for certain critical societal protections, its necessary to have a guilty by default, for 'people' whose only possible motive is profit incentive. The corporations or the firm are considered people in most locales, but they only adjust behavior based on profit or future profit (through monopoly).

Placing the burden of proof on the company to prove they are complying, instead of compliant with good faith protections by default, would eliminate most benefits they might receive from deceit, or lying through omission.

Re: Web fingerprinting is worse than I thought

#160
post #95

Earlier quoted context omitted.

really? it takes a minute to set up a VPN and do your web browsing through a virtual machine. I guess it's not "trivial" for the average American, but it definitely is for the average terrorist or child pornographer, so it's easy compared to surmounting most other threat models faced by people intending to evade detection. Therefore, "trivial". [edit] also, the less trivial it is, the better for corporate security.

I think you should read more about what fingerprinting actually is.

yeah? I use about 24 different parameters and/or their lack of ability to i.d. a machine. Pretty sure I understand how to turn that into a set of tolerances that can be compared with another machine to provide a reasonable projection of whether those match with the people using them. I think I get the concept.
Post reply on HN