Live data from Hacker News

Chrome is entrenching third-party cookies that will mislead users

brave.com

161–170 of 329 posts

Re: Chrome is entrenching third-party cookies that will mislead users

#161
post #154
post #128

Earlier quoted context omitted.

Mozilla is a Google vassal and nothing more. Google analytics? Check. Firefox Safebrowsing sending your private tab traffic to google? Of course! https://spyware.neocities.org/articles/firefox Mozilla only has their Google billion$ in mind, not you. https://digdeeper.neocities.org/articles/mozilla

> Google analytics? Check. Add this to /etc/hosts 0.0.0.0 www.google-analytics.com 0.0.0.0 google-analytics.com 0.0.0.0 ssl.google-analytics.com

Is it as simple as this?

Re: Chrome is entrenching third-party cookies that will mislead users

#162
post #154

Earlier quoted context omitted.

> Google analytics? Check. Add this to /etc/hosts 0.0.0.0 www.google-analytics.com 0.0.0.0 google-analytics.com 0.0.0.0 ssl.google-analytics.com

Is it as simple as this?

Unfortunately no. The entire point of DoH is to bypass the ability of the users to prevent browsers from providing browsing habits to their owners.

Re: Chrome is entrenching third-party cookies that will mislead users

#164

Earlier quoted context omitted.

Is it as simple as this?

Unfortunately no. The entire point of DoH is to bypass the ability of the users to prevent browsers from providing browsing habits to their owners.

No, that is not the entire point of DoH. That’s like saying the entire point of TLS is to prevent users from looking at the traffic being sent to a website.

DNS without DoH, DoT, or DoQ, is wide open to anyone snooping traffic in the raw, that’s not necessarily information you want to share with the world.

Re: Chrome is entrenching third-party cookies that will mislead users

#165

Earlier quoted context omitted.

Is it as simple as this?

Unfortunately no. The entire point of DoH is to bypass the ability of the users to prevent browsers from providing browsing habits to their owners.

DoH and similar technologies don't override /etc/hosts. They're just a different way of making DNS queries. The entire point of these technologies is to prevent your ISP and everyone else along the way from knowing which websites you visit.

Re: Chrome is entrenching third-party cookies that will mislead users

#166
post #98
post #74

Earlier quoted context omitted.

Firefox is usually great for me, but with Chromium-based browsers having such a massive market share monopoly I do occasionally find a website that doesn't work properly on Firefox. But, I will stick with Firefox as long as possible.

Do you have any recent examples? It's more often I see websites that claim they don't work with firefox but actually do if you change your user agent.

I cannot open message in LinkedIn with Firefox linux. Haven't pinpoint the error cause though

Re: Chrome is entrenching third-party cookies that will mislead users

#167

Earlier quoted context omitted.

We do. > Insurers contend that they use the information to spot health issues in their clients — and flag them so they get services they need. And companies like LexisNexis say the data shouldn't be used to set prices. But as a research scientist from one company told me: "I can't say it hasn't happened." source: https://www.propublica.org/article/health-insurers-are-vacuu... See also: > Is it legal? As explained by…

> which is a total joke since it's often trivial to re-identify anonymized data HIPAA doesn't say ROT13 or anything else in particular counts as "anonymized". It's an after-the-fact assessment. If your "encrypted" data is accidentally released, and there's any reasonable suspicion inside or outside the company that it's crack-able, then it's a YOU problem and you need to notify a bajillion people by mail and per-stat…

> HIPAA doesn't say ROT13 or anything else in particular counts as "anonymized".

ROT13 was only an example of a step that makes data look "protected" in some way when it really isn't, just like the ineffective means used to anonymize data makes it look safe to sell that data when it really isn't.

There is a lot of research showing how easy it can be to identify an individual using data that has been anonymized. (https://www.technologyreview.com/2019/07/23/134090/youre-ver...)

HIPAA does provide a standard and guidelines for what they call the "de-identification of protected health information" (https://www.hhs.gov/hipaa/for-professionals/special-topics/d...) and it includes, for example, a list of specific identifying information that must be removed from the records before they can be sold or otherwise passed around in order to get safe harbor protections. It also includes an option where an "expert" ("There is no specific professional degree or certification program for designating who is an expert") can just say "Trust me bro, it's anonymized".

If somebody was able to buy their re-identified data from a broker and they could prove that was sold by a health provider bound by HIPAA, they would still have to prove that the provider who sold the data had "actual knowledge" that the broker would be able to re-identify the individual, where:

> actual knowledge means clear and direct knowledge that the remaining information could be used, either alone or in combination with other information, to identify an individual who is a subject of the information.

Which all seems like it would be almost impossible to prove unless the provider left obvious identifying information in the data, or if a whistleblower came forward with records of direct communication between the seller and buyer where the buyer was reassured that the data being sold to them would later be able to be re-identified.

Awareness of the fact that we have mountains of research showing that individuals are easy to re-identify from anonymized data doesn't count as "actual knowledge":

> Much has been written about the capabilities of researchers with certain analytic and quantitative capacities to combine information in particular ways to identify health information.32,33,34,35 A covered entity may be aware of studies about methods to identify remaining information or using de-identified information alone or in combination with other information to identify an individual. However, a covered entity’s mere knowledge of these studies and methods, by itself, does not mean it has “actual knowledge”

Which leaves us with healthcare providers who can use methods to "anonymize" data that have been proven to be vulnerable to re-identification, then freely sell that "anonymized" data to third parties with a nudge and a wink.

I'll admit to being pessimistic. We know that the strength of the regulations we have in the US has done little to slow down the buying and selling of our healthcare data.

We've also already seen a lot of very shady behavior by health care providers and companies such as tricking or coercing people into giving up their rights so that they don't even have to pretend to protect their data with anonymization before selling it. (see https://www.washingtonpost.com/technology/2022/06/13/health-... and https://www.washingtonpost.com/technology/2023/05/01/amazon-... and https://news.ycombinator.com/item?id=22177812 and https://www.12onyourside.com/story/23852025/on-your-side-ale...)

Re: Chrome is entrenching third-party cookies that will mislead users

#168

Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, encrypted DNS without fallbacks, supports SOCKS and Encrypted Client Hello (although almost no website support it). However, it is better to just buy more memory (unless you are lucky to use Apple products). Regarding analytics, I believe browsers should take use…

> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies Browsers were supposed to act as agents working for the user. User-agents. These days it's getting harder and harder to find a browser that doesn't work for an ad company at the expense of the user. Chrome's entire reason for existing is data collection. Firefox can, for now at least, be hardened to work fo…

I just switched to Libre Wolf, seems like a pretty good Firefox replacement but without the malware.

Re: Chrome is entrenching third-party cookies that will mislead users

#169

Earlier quoted context omitted.

Unfortunately no. The entire point of DoH is to bypass the ability of the users to prevent browsers from providing browsing habits to their owners.

DoH and similar technologies don't override /etc/hosts. They're just a different way of making DNS queries. The entire point of these technologies is to prevent your ISP and everyone else along the way from knowing which websites you visit.

> DoH and similar technologies don't override /etc/hosts.

It seems that it does:

https://bugzilla.mozilla.org/show_bug.cgi?id=1544233

https://github.com/StevenBlack/hosts/issues/968

https://old.reddit.com/r/firefox/comments/e64073/dns_over_ht...

https://www.liquidweb.com/help-docs/Fixing-Firefox-Bypassing...

https://superuser.com/questions/437649/firefox-not-taking-no...

https://stackoverflow.com/questions/37452361/why-is-my-hosts...

Re: Chrome is entrenching third-party cookies that will mislead users

#170

Earlier quoted context omitted.

Unfortunately no. The entire point of DoH is to bypass the ability of the users to prevent browsers from providing browsing habits to their owners.

No, that is not the entire point of DoH. That’s like saying the entire point of TLS is to prevent users from looking at the traffic being sent to a website. DNS without DoH, DoT, or DoQ, is wide open to anyone snooping traffic in the raw, that’s not necessarily information you want to share with the world.

Which (for people not handing all of their DNS traffic over to google anyway) usually just means that their ISP can see their DNS traffic which is kind of a moot point because your ISP can see the domains you go to even with DoH.

If somebody is on your local network capturing packets or they've cracked your wifi you've got bigger problems than your DNS leaking a list of domains. They'll also see the IP of every server you visit online anyway

The way DoH is implemented usually means that all of your DNS traffic is collected by some third party for-profit corporation like cloudflare anyway (who admittedly will already know most of the domains you visit anyway because of how often cloudflare's IP space is where DNS will point you).

There really aren't any good options for DNS and privacy, just a lot of compromises. Host your own. Or, if your ISP is trustworthy, you might be better off using what they provide. The DNS traffic between you and your ISP's servers should never leave their network.

Post reply on HN