Earlier quoted context omitted.
99% of websites we visit do not need canvas or sound. And the few websites that do can explain why you should click "Allow" when they prompt you for access. What's a charitable reason that stops even a supposedly privacy-concerned niche browser like Brave from implementing opt-ins for these things? I suppose one reason is that you would immediately unleash opt-in spam on your users that don't know what these pop-ups…
Ok, how to fix fingerprinting: - for web, stop using chrome, install firefox (or firefox mobile) and in about:config set privacy.resistFingerprinting on true then add following addons: https://addons.mozilla.org/en-US/android/addon/canvas-finger... https://addons.mozilla.org/en-US/android/addon/audioctx-fing... https://addons.mozilla.org/en-US/android/addon/webgl-fingerp... https://addons.mozilla.org/en-US/android/ad…
Privacy analysis of Tiktok’s app and website
181–190 of 207 posts
Re: Privacy analysis of Tiktok’s app and website
#182Earlier quoted context omitted.
And I wonder whether comments like yours are spread by the Chinese Government to undermine trust in our media/democracy.
If I could prove I'm not associated with China in any way, and in fact don't like what they do, could it be proved that the wave of Tiktok-related posts has nothing to do with Facebook/Google?
Re: Privacy analysis of Tiktok’s app and website
#183"They draw an image in the background using vector graphic commands. Afterwards they save the image to a rasterized PNG. This data is quite unique among different devices depending on settings and hardware." Why the fuck does this still work? People are complaining about all those websites that use it, but ignore the fact that it can be mostly fixed by changing 2 applications (Chrome and Firefox).
Re: Privacy analysis of Tiktok’s app and website
#184Earlier quoted context omitted.
It was my understanding that these methods profile performance of the API which will execute at different speeds on different devices. The samples themselves shouldn't be different if they're using AudioBuffer and typed arrays.
Time to add random delay and noise then.
Re: Privacy analysis of Tiktok’s app and website
#185We are growing a community of people who don't trust our fragile governments to figure this out, and instead want to democratize these tools and level the playing field rather than attempting prohibition yet again..
Re: Privacy analysis of Tiktok’s app and website
#186> Canvas Fingerprinting. They draw an image in the background using vector graphic commands. Afterwards they save the image to a rasterized PNG. This data is quite unique among different devices depending on settings and hardware. > They also use audio fingerprinting to identify visitors. This doesn’t mean they actually use your microphone or speaker. Instead they generate a sound internally and record the bitstream,…
This kind of fingerprinting is used across the industry for anti-fraud purposes. The problem is that it used to be good enough to block "known-bad" IPs but now with AWS and cloud services it's very easy for cybercriminals to get around IP blocks. For normal users, tracking can be done with cookies, so fingerprinting isn't really needed for normal users anyways (not entirely true if you're a totally bad actor, which i…
Re: Privacy analysis of Tiktok’s app and website
#187> Canvas Fingerprinting. They draw an image in the background using vector graphic commands. Afterwards they save the image to a rasterized PNG. This data is quite unique among different devices depending on settings and hardware. > They also use audio fingerprinting to identify visitors. This doesn’t mean they actually use your microphone or speaker. Instead they generate a sound internally and record the bitstream,…
99% of websites we visit do not need canvas or sound. And the few websites that do can explain why you should click "Allow" when they prompt you for access. What's a charitable reason that stops even a supposedly privacy-concerned niche browser like Brave from implementing opt-ins for these things? I suppose one reason is that you would immediately unleash opt-in spam on your users that don't know what these pop-ups…
Re: Privacy analysis of Tiktok’s app and website
#188> Canvas Fingerprinting. They draw an image in the background using vector graphic commands. Afterwards they save the image to a rasterized PNG. This data is quite unique among different devices depending on settings and hardware. > They also use audio fingerprinting to identify visitors. This doesn’t mean they actually use your microphone or speaker. Instead they generate a sound internally and record the bitstream,…
I still remember the news articles refering a patent Facebook filed about audio fingerprinting as the evidence of Facebook eavesdropping on the people.
Also technologically with some encryption argorithms, a company can claim that they are not capable to identify user with the fingerprint. But in theory given enough data they still can.
Re: Privacy analysis of Tiktok’s app and website
#189Earlier quoted context omitted.
Thank you, but I'm a bit confused. You lost me here: > And yes, most website are violating it, but in the sense of Eprivacy, not the GDPR. From what I understand of your post, GDPR has basically superseded the old Eprivacy law, because it requires the same things and then more on top.
Sorry about that. They are violating Eprivacy, not the GDPR, because they are dropping tracers without proper consent. But they are violating it because the consent they are collecting is not valid in the definition given in the GDPR. The previous understanding of Eprivacy (before the GPDR) admitted a "soft consent", ie "keep reading and you consent". That is not longer the case because of GDPR. What they do with the…
Re: Privacy analysis of Tiktok’s app and website
#190Earlier quoted context omitted.
99% of websites we visit do not need canvas or sound. And the few websites that do can explain why you should click "Allow" when they prompt you for access. What's a charitable reason that stops even a supposedly privacy-concerned niche browser like Brave from implementing opt-ins for these things? I suppose one reason is that you would immediately unleash opt-in spam on your users that don't know what these pop-ups…
> What's a charitable reason that stops even a supposedly privacy-concerned niche browser like Brave from implementing opt-ins for these things? In my experience, blocking these everywhere globally as a default will result in being banned from websites, trigger bullshit "fraud" invasive analytics, and all sorts of obnoxious fail-closed problems by invasive trackers. You will also be banned from most Distil-hosted sit…