Live data from Hacker News

Web fingerprinting is worse than I thought (2023)

bitestring.com

191–200 of 219 posts

Re: Web fingerprinting is worse than I thought (2023)

#191
post #172

Earlier quoted context omitted.

>Random User-Agent Switcher Don't bother. User agent spoofing is easily detectable and it's trivial to figure out your real user-agent based on js implementation differences or TLS fingerprinting. All this does is get you banned/flagged by security vendors, on top of sticking out like a sore thumb. >Canvas Blocker >Font Fingerprint Defender Also easy to easy to detect because randomized values will put you in the buc…

Maybe. >>Random User-Agent Switcher >Don't bother. User agent spoofing is easily detectable and it's trivial to figure out your real user-agent based on js implementation differences or TLS fingerprinting. JS is blocked by default on my browser. >Canvas Blocker >Font Fingerprint Defender > Also easy to easy to detect because randomized values will put you in the bucket of "uses privacy extension" Hm. How are they goi…

>JS is blocked by default on my browser.

The major browsers can still be differentiated via default headers and TLS fingerprints, none of which requires js. Moreover if they're inconsistent you'd get flagged with "spoofs user agent", which makes you more identifiable than something like "firefox on mac".

>Hm. How are they going to detect it is randomized? They would have to identify me first again as the same user and then conclude I randomize these values.

Because a given canvas/font metrics value should return the same result given the same graphics hardware/font set. If you randomize the results it basically guarantees that your fingerprint has never been seen before. This might seem like a good thing (because you're randomized every time), but any competent fingerprinting implementation is just going to flag you as "spoofs canvas/font information". The point isn't necessarily to identify you as any particular user, it's to use the fact you're spoofing canvas/font/user-agent to fingerprint you further.

Re: Web fingerprinting is worse than I thought (2023)

#192

Earlier quoted context omitted.

Making it a technical problem means it’s an arms race forever. Making it a regulation problem, if done right, can simply end the arms race. Not to mention the big players on the users’ team in the technical arms race (google, ms, apple) are also advertising companies. By all means let’s solve it from the technical side - but also lets regulate privacy so everyone gets it not just people paranoid/technical enough to u…

> Making it a technical problem means it’s an arms race forever. Making it a regulation problem, if done right, can simply end the arms race. “If done right” is doing a lot of work in that sentence. The way hypothetical regulation is spoken of in abstract terms where it’s perfect, solves everything, and everyone complies perfectly is at odds with how regulation works in the real world.

I agree entirely, but I think that’s a problem because gov is captured by corporate interests / neoliberal ideas.

They try to balance keeping corporate donors happy with keeping people happy, and create regulations that are toothless empty gestures that only serve as employment opportunities for lawyers and consultants.

So yes, “if done right” is doing a lot of work. But i refuse to cede gov to the corps and retreat to anarcho-capitalist ideas like “this is a technical problem”. We attack on all fronts - regulation and technological solutions.

Re: Web fingerprinting is worse than I thought (2023)

#193
post #173
post #95

Earlier quoted context omitted.

other downsides, cloudflare, PayPal and all kinds of finance related sites will assign high threat level for you and you will make your life miserable for causes ranging from captcha through rejecting your purchases to even blocking you access. and the worst part is that this didn't changed the fingerprint generated by mentioned here site just increases suspect level to 9

>and the worst part is that this didn't changed the fingerprint generated by mentioned here site ??? It definitely does. Are you talking about how it doesn't change between subsequent visits?

In my case it stayed the same, but I tested it on android Firefox, maybe it works better on desktop, but I do not have access to it right now to verify

Re: Web fingerprinting is worse than I thought (2023)

#194
post #137

Earlier quoted context omitted.

I can see this as an argument for avoiding unusual properties, but how can they identify you using random properties? Even if it is just one user doing this how can they match the fingerprints? Also, its unusual enough that its unlikely they will bother trying.

The fact that the properties are randomized (and which properties are randomized) identifies the extension that you’re using, and if that extension has like 10 users, that uniquely identifies you across sites. All of this is overkill anyway unless you actually think you’re up against a determined actor targeting you personally. If you are, they will bother trying.

> The fact that the properties are randomized (and which properties are randomized) identifies the extension that you’re using, and if that extension has like 10 users, that uniquely identifies you across sites.

How do they know they are randomised rather than actual properties?

Re: Web fingerprinting is worse than I thought (2023)

#195

Earlier quoted context omitted.

https://fingerprint.com/demo/ Yes, fingerprint.com realizes that I am the same visitor. But ONLY IF I access it from the same IP address. This is impressive, but in the end not so much. They claim VPN does not matter for them. It does. Probably one of the last things that makes my browser identifiable.

Haha, that failed spectacularly. On stock Mac OS Safari (no plugins, no hardened config), I did what they asked and visited their site in incognito mode via a VPN. It gave me a different id, with a message gleefully announcing that "your ID is the same when you're in incognito mode!" It even showed me some supposed visit from a minute ago. Jesus what a scam.

Hi, I work at Fingerprint. Our demo accuracy is actually much lower than in production. You're welcome to try it yourself for free: https://dashboard.fingerprint.com/signup

Re: Web fingerprinting is worse than I thought (2023)

#196
post #173

Earlier quoted context omitted.

>and the worst part is that this didn't changed the fingerprint generated by mentioned here site ??? It definitely does. Are you talking about how it doesn't change between subsequent visits?

In my case it stayed the same, but I tested it on android Firefox, maybe it works better on desktop, but I do not have access to it right now to verify

You probably need to quit/force close and reopen. At the very least it randomizes your canvas results and timezone, which should mess with most fingerprinting sites.

Re: Web fingerprinting is worse than I thought (2023)

#198

Earlier quoted context omitted.

It always freaked me out that WhatsApp found the SMS code sent to verify the phone number without requiring any action from me. Also, WhatsApp refuses to be usable without giving it Contacts access. I had to use the app, login to the web client, and then I was finally able to type a phone number to start a new chat. I ended up uninstalling it, but there's plenty of people AND business that nowadays mainly or even onl…

I share your woes regarding WhatsApp; my family overseas uses it, so I have to use it when visiting them, and I also had to do the weird workaround of creating a Whatsapp URL with the destination phone number, and then opening it in the browser, and then having it redirect me to the app.

Oh, I forgot about this, yeah, you can use the links that webpages post to workaround it. Quite annoying though, I think I only used it once.

Here's an example link,

https://api.whatsapp.com/send?phone=5551112233

Re: Web fingerprinting is worse than I thought (2023)

#199

Earlier quoted context omitted.

Yes. Apple is a huge corporation and I feel confident that such an entity would happily harm any person or group of persons in the pursuit of profit.

Are there any examples?

The host the data for Chinese customers in a mainland datacenter. Chinese iPhones can not use eSims. Foxconn has nets…

Re: Web fingerprinting is worse than I thought (2023)

#200

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=44169115 They found sneaky ways on Android. There is no way they aren't trying to do so on iOS. One must always assume malice with anything Meta.

It always freaked me out that WhatsApp found the SMS code sent to verify the phone number without requiring any action from me. Also, WhatsApp refuses to be usable without giving it Contacts access. I had to use the app, login to the web client, and then I was finally able to type a phone number to start a new chat. I ended up uninstalling it, but there's plenty of people AND business that nowadays mainly or even onl…

> It always freaked me out that WhatsApp found the SMS code sent to verify the phone number without requiring any action from me.

I don't fault you for not trusting Meta - I feel the same.

That said, what you're talking about here is an OS feature nowadays.

Post reply on HN