Live data from Hacker News

Block Fingerprinting with Firefox

blog.mozilla.org

161–170 of 411 posts

Re: Block Fingerprinting with Firefox

#161
post #34

I find it really interesting that when a company is making moves in a direction that benefits privacy of consumers, everyone takes the opportunity to shit on them for past mistakes or how it isn't good enough or why isn't it on by default or any other thing they can find to shit on. Yes, every single company has made mistakes. FireFox is no exception. Some of them were pretty egregious. Mistakes are - hopefully - an…

I'd be glad to forget Mozilla's past if they'd show that they have learned from them. The problem is that they haven't. In some cases, they've doubled down on them. I say this as someone who uses firefox on every device he can.

> The problem is that they haven't.

How so?

> In some cases, they've doubled down on them.

Which cases?

Re: Block Fingerprinting with Firefox

#162

Earlier quoted context omitted.

I’m sure you’ll be fine, eventually - but that’s not guaranteed to stop them initially, or without a digital search of your entire computer, for example.

Do you have any evidence that any AdNauseam user has ever been arrested for ad fraud?

They said they "might decide to investigate". That suggests it's a real possibility but not something that has previously happened.

Re: Block Fingerprinting with Firefox

#163
post #15

Can someone paste their results (or at least bits of fingerprinting entropy) from https://panopticlick.eff.org with the latest Firefox? With the fancy new anti-fingerprinting Safari on macOS Mojave I get just over 14.5 bits of entropy with the most entropic source being my canvas fingerprint (1 in 600). With Safari on iOS I get 11.71 bits of entropy, with the most entropic value being my screen size and color depth.

17.62 bits on firefox, 11.0 on Tor, 17.63 on chrome. On firefox, the big contributors are HTTP headers (my native language is announced), hash of WebGl fingerprint and time zone. On Tor big contributors are hash of webGL fingerprint, screen size. On chrome, they are system fonts, hash of canvas fingerprint, user agent, and time zone. I am not too concerned about the fingerprinting in firefox since I have strict block…

Panopticlick's numbers are extremely confusing and borderline useless.

On my initial run, I got an overall entropy of 17.63. My two biggest identifiers were screen resolution (1000x595x24 which was approx 1/22000 browsers) and webgl hash (approx 1/3800 browsers). I fixed screen resolution to 1000x600x24 (approx 1/85 browsers) and disabled webgl hashing (approx 1/6 browsers) and the overall entropy did not change one iota, despite also closing browser, flushing cache and cookies, etc. I gave it another run with a deliberately weird resolution (1420x701 which was something like 1/105000 browsers) and once again, the overall entropy was exactly 17.63. So based on my experiment, it seems that screen resolution and webgl hash have no effect whatsoever on [Panopticlick's] overall entropy score.

Re: Block Fingerprinting with Firefox

#165
post #15

Can someone paste their results (or at least bits of fingerprinting entropy) from https://panopticlick.eff.org with the latest Firefox? With the fancy new anti-fingerprinting Safari on macOS Mojave I get just over 14.5 bits of entropy with the most entropic source being my canvas fingerprint (1 in 600). With Safari on iOS I get 11.71 bits of entropy, with the most entropic value being my screen size and color depth.

mine is ~17. language, platform, screen size, time zone, user agent, and plugin info are the most identifying. anyone know of a list of the most used values for these so we could lower our uniqueness by setting our browser values to them?

Likewise. It makes no difference whether I enable or disable the Fingerprinters checkbox.

Maybe due to the "uBlock Origin stops it from working" mentioned elsewhere, or some other glitch. Disabling uBlock Origin on panopticlick.eff.org didn't make a difference.

Re: Block Fingerprinting with Firefox

#166
post #72

Earlier quoted context omitted.

You can draw with different fonts and background colors, then grab the raw pixel values and hash them. The hash will be different depending on the versions of fonts installed, the OS, the GPU, the browser's text rendering algorithms, and the subpixel order/orientation of the display. See https://en.wikipedia.org/wiki/Canvas_fingerprinting for more info.

Thanks. I'd read the Wikipedia page, I'm just not clear why this process is allowed (or more importantly, why it can't be removed). Is there a legitimate use case for being able to read back pixels?

There are many legitimate uses. Vendors have experimented with making canvas readback opt-in (with a popup) but I don't know if it'll ever ship because it simply breaks too many websites. Sometimes it's used at page load to generate variants of a single image to reduce file sizes, or used by games to prepare image assets before they start up.

Re: Block Fingerprinting with Firefox

#167

Earlier quoted context omitted.

Well if HN users do want to try to lessen that percentage here's the donation page: https://donate.mozilla.org/

It was said earlier today that because of American tax rules donation money cannot go to software development. So donation money goes to outreach and similar. Which is useful but doesn't fund Firefox. Someone please correct me if this is wrong.

There is nothing about how charities work under US Federal tax law that would produce this result.

Tax-exempt charities (which must by definition be non-profit, but not all non-profits are charities, and not all charities are tax exempt!) must spend money in a way that's aligned with their mission, and there are rules on how much they can spend outside that. (The really big no-no has to do with political lobbying and the endorsement of candidates for public office -- a relic of a more civilized age when apparently we thought that should be left up to individuals. But I digress.)

The Mozilla Foundation is a California corporation with tax-exempt status under US Internal Revenue Code 501(c)(3), which covers "public charities, private foundations or private operating foundations". There are slightly different rules for each category.

I'm not sure what category Mozilla Foundation is; my suspicion is they are either a public charity or a private operating foundation. In either case, there's nothing that would prohibit them from funding software development, as long as it doesn't unfairly benefit someone involved in the organization's governance.

Their 2016 financial statements (I couldn't find anything newer) are available:

https://assets.mozilla.net/annualreport/2016/2016_Mozilla_Au...

tl;dr: In 2016 they spent over $250k on software development as a line-item, out of about $500k in revenue total. It's by far their biggest budget item.

Re: Block Fingerprinting with Firefox

#168

Earlier quoted context omitted.

With Google's Chrome I know whom I give my privacy to. With Firefox I am one update away from being part of an experiment without my consent. I take the known evil every time.

I very much doubt that you know all the parties to whom you are constantly being sold by Google. You do realize that Google does not benefit from keeping your info to themselves, right?

[deleted]

Re: Block Fingerprinting with Firefox

#169

Earlier quoted context omitted.

I very much doubt that you know all the parties to whom you are constantly being sold by Google. You do realize that Google does not benefit from keeping your info to themselves, right?

>You do realize that Google does not benefit from keeping your info to themselves, right? Of course they do. That's literally their business model, to use that data to serve more relevant ads. If they gave it to third parties then they would lose their biggest competitive advantage. And really, they couldn't be any more clear about it: https://safety.google/privacy/ads-and-data/ >We do not sell your personal informat…

>We do not sell your personal information to anyone.

That's a technically true and practically meaningless statement. No lying required.

Google's business model relies on giving advertisers a way to target you based on that data and to track you to other activities down the line. Advertisers might never see the data itself, but all that means is Google is selling the product that lets advertisers do the things they were going to do if they actually did have the data, just without being able to see your specific info.

Whether you consider that equivalent to selling your data is a separate question. You'll find a lot of disagreement here about it.

Re: Block Fingerprinting with Firefox

#170

Earlier quoted context omitted.

>You do realize that Google does not benefit from keeping your info to themselves, right? Of course they do. That's literally their business model, to use that data to serve more relevant ads. If they gave it to third parties then they would lose their biggest competitive advantage. And really, they couldn't be any more clear about it: https://safety.google/privacy/ads-and-data/ >We do not sell your personal informat…

>We do not sell your personal information to anyone. That's a technically true and practically meaningless statement. No lying required. Google's business model relies on giving advertisers a way to target you based on that data and to track you to other activities down the line. Advertisers might never see the data itself, but all that means is Google is selling the product that lets advertisers do the things they w…

It's certainly using your data, but I don't think anybody reasonable would argue it's selling your data.
Post reply on HN