Live data from Hacker News

Google starts tracking all your devices in 8 weeks

forbes.com

151–156 of 156 posts

Re: Google starts tracking all your devices in 8 weeks

#151

Earlier quoted context omitted.

What if they use IPs instead of domain names?

Then you write router-level firewall rules for the IPs you know are safe to fully block. You can do that selectively so you don’t break other devices. I already do this for local DNS circumvention, which is probably a lot more common than hardcoded IPs.

Right, but Pi-Hole can't help with this.

Re: Google starts tracking all your devices in 8 weeks

#152

Earlier quoted context omitted.

How would they know? The point of returning “standard” values, is that you are indistinguishable from any number of legitimate users.

They start blocking any fingerprint that looks like you're hiding it. Similar to sites blocking known Tor exit nodes and proxies.

The point is that the fingerprint looks like “the generic fingerprint”, blocking that would be pointless, because it’d block a massive number of completely valid users.

Re: Google starts tracking all your devices in 8 weeks

#153

Every browser information leak that can contribute to fingerprinting needs to be plainly considered a security vulnerability in need of fixing/mitigation, period. This class of vulnerabilities has continued to get a huge pass, only being taken seriously by projects like TOR browser and then still only the convenient fixes getting backported. I do realize this is a tall ask, as many of these vulnerabilities arise from…

The Accept-Language header predates Google by many years, see https://www.rfc-editor.org/rfc/rfc1945#appendix-D.2.4

I certainly did not mean to imply that every browser fingerprinting vulnerability is due to Google née Doubleclick. What did I say to make you think so?

And from a technical perspective, Accept-language doesn't seem terribly hard to mitigate - exactly one language at a time, and UI that allows a user to easily change to another, as if it's part of the logical URL. It's all the javascript APIs, especially the graphics ones with their loads of weakly-defined behavior, that are especially pernicious.

Re: Google starts tracking all your devices in 8 weeks

#154

Earlier quoted context omitted.

The Accept-Language header predates Google by many years, see https://www.rfc-editor.org/rfc/rfc1945#appendix-D.2.4

I certainly did not mean to imply that every browser fingerprinting vulnerability is due to Google née Doubleclick. What did I say to make you think so? And from a technical perspective, Accept-language doesn't seem terribly hard to mitigate - exactly one language at a time, and UI that allows a user to easily change to another, as if it's part of the logical URL. It's all the javascript APIs, especially the graphics…

Sorry, mis-click threading issue on mobile. I meant the reply to this thread: https://news.ycombinator.com/item?id=42480099

Do any of the mobile-friendly alternative HN front-ends support commenting without giving up your creds?

Re: Google starts tracking all your devices in 8 weeks

#155

Earlier quoted context omitted.

I certainly did not mean to imply that every browser fingerprinting vulnerability is due to Google née Doubleclick. What did I say to make you think so? And from a technical perspective, Accept-language doesn't seem terribly hard to mitigate - exactly one language at a time, and UI that allows a user to easily change to another, as if it's part of the logical URL. It's all the javascript APIs, especially the graphics…

Sorry, mis-click threading issue on mobile. I meant the reply to this thread: https://news.ycombinator.com/item?id=42480099 Do any of the mobile-friendly alternative HN front-ends support commenting without giving up your creds?

On mobile, the one I use has a share button that lets you open the comment in a browser.

Re: Google starts tracking all your devices in 8 weeks

#156

Earlier quoted context omitted.

I certainly did not mean to imply that every browser fingerprinting vulnerability is due to Google née Doubleclick. What did I say to make you think so? And from a technical perspective, Accept-language doesn't seem terribly hard to mitigate - exactly one language at a time, and UI that allows a user to easily change to another, as if it's part of the logical URL. It's all the javascript APIs, especially the graphics…

Sorry, mis-click threading issue on mobile. I meant the reply to this thread: https://news.ycombinator.com/item?id=42480099 Do any of the mobile-friendly alternative HN front-ends support commenting without giving up your creds?

On mobile, the one I use has a share button that lets you open the comment in a browser and not have to login to the apo, though you miss some customizations like notification on comment replies.
Post reply on HN