Live data from Hacker News

Bypassing Safari 17's advanced audio fingerprinting protection

fingerprint.com

201–210 of 266 posts

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#201
post #182

Earlier quoted context omitted.

[flagged]

And a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater. Do you see why you’re coming across as having inconsistent standards and thereby perhaps an axe to grind? iCloud Private Relay is used for all network activity from Safari which does not seem like a “limited amount of activity.”

> And a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater.

A VPN isn't designed to keep your IP address hidden from the operator. iCloud Private Relay doesn't hide your IP address from Apple either. That's not the point, and everyone knows this in advance. The point is to keep your IP address hidden from the request destination servers.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#202
post #177

Earlier quoted context omitted.

> Is iCloud Private Relay theatre? https://fingerprint.com/blog/ios15-icloud-private-relay-vuln... > 3rd party cookie blocking? It's very funny that you should ask this question in response to an article about fingerprinting without cookies. But yes, there are various workaround to use 1st party cookies or other storage to take the place of 3rd party cookies. Perhaps the worst is the Safari "Privacy Report", which ha…

Built in tracker blocking and the various ways Safari makes it hard to share user sessions with 3rd parties absolutely has real effect. It also has real costs: part of Safari’s poor compatibility reputation comes from websites that are broken by its tracking prevention features. This is why Google claims they haven’t rolled out the same. If Apple only cared about the problem at a superficial level, why wouldn’t they…

> If Apple only cared about the problem at a superficial level, why wouldn’t they do the same as Chrome and talk a big game about the problem but continuously delay changes?

If Safari behaved the same as Chrome, then Apple couldn't market Safari as more private than Chrome.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#203
post #176

Earlier quoted context omitted.

> That's an wild accusation to make without citations. Shall I cite my list of CVE? Or perhaps it would be more interesting to cite my list of unfixed 0days. > It doesn't even apply in this instance, since Apple's work on fingerprint resistance still results in real privacy improvements even when later shown to be imperfect. It means Apple has to improve what they've already done, not that what they've done so far is…

“Apple’s quantity and resolution rate of security bugs undermine its privacy marketing” and “Apple’s privacy marketing is a lie” are two very different claims, and it seems like you meant to make the first. Even that claim though is unsupported since Safari users are definitely harder to track across the web in practice than Chrome users. > Shall I cite my list of CVE? Or perhaps it would be more interesting to cite…

I think you missed the point of my comment. When I said my list of CVE and my list of unfixed 0days, I meant that literally: CVE attributed by Apple to me, and unfixed 0days that I personally discovered. I wasn't making a "wild accusation".

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#204
post #177

Earlier quoted context omitted.

Is iCloud Private Relay theatre? 3rd party cookie blocking? What specific features do you allege exist just to mislead the general public?

> Is iCloud Private Relay theatre? https://fingerprint.com/blog/ios15-icloud-private-relay-vuln... > 3rd party cookie blocking? It's very funny that you should ask this question in response to an article about fingerprinting without cookies. But yes, there are various workaround to use 1st party cookies or other storage to take the place of 3rd party cookies. Perhaps the worst is the Safari "Privacy Report", which ha…

"Please note that this leak only occurs with iCloud Private Relay on iOS 15"

All software has bugs. I think it is more interesting to see how companies respond to reported issues. And how they improve things.

Is OpenSSL "theatre" because it had (bad!) bugs in the past?

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#205
post #204
post #177

Earlier quoted context omitted.

> Is iCloud Private Relay theatre? https://fingerprint.com/blog/ios15-icloud-private-relay-vuln... > 3rd party cookie blocking? It's very funny that you should ask this question in response to an article about fingerprinting without cookies. But yes, there are various workaround to use 1st party cookies or other storage to take the place of 3rd party cookies. Perhaps the worst is the Safari "Privacy Report", which ha…

"Please note that this leak only occurs with iCloud Private Relay on iOS 15" All software has bugs. I think it is more interesting to see how companies respond to reported issues. And how they improve things. Is OpenSSL "theatre" because it had (bad!) bugs in the past?

[flagged]

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#206

This is gross.

I assumed a level of irony here, from fingerprint.com. It’s like if a website popped up popularising loopholes to get around tax burdens as an attempt to disgust the world into closing those loopholes. Even if that’s wishful thinking, there’s still immense virtue in publishing this research and getting it out in the open. If an article gets published explaining how a particular brand of green backpack helps with shop…

Unfortunately in this case, the website does content marketing with known, easy to fix vulnerabilities presumably to put competition out of business while keeping unknown, harder to fix vulnerabilities as part of their "pro" products.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#207
post #203

Earlier quoted context omitted.

“Apple’s quantity and resolution rate of security bugs undermine its privacy marketing” and “Apple’s privacy marketing is a lie” are two very different claims, and it seems like you meant to make the first. Even that claim though is unsupported since Safari users are definitely harder to track across the web in practice than Chrome users. > Shall I cite my list of CVE? Or perhaps it would be more interesting to cite…

I think you missed the point of my comment. When I said my list of CVE and my list of unfixed 0days, I meant that literally: CVE attributed by Apple to me, and unfixed 0days that I personally discovered. I wasn't making a "wild accusation".

No I understood exactly what you meant. The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive. How many CVEs and 0-days have you filed against Audacity? Is it because that software is security bug free?

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#208
post #202

Earlier quoted context omitted.

Built in tracker blocking and the various ways Safari makes it hard to share user sessions with 3rd parties absolutely has real effect. It also has real costs: part of Safari’s poor compatibility reputation comes from websites that are broken by its tracking prevention features. This is why Google claims they haven’t rolled out the same. If Apple only cared about the problem at a superficial level, why wouldn’t they…

> If Apple only cared about the problem at a superficial level, why wouldn’t they do the same as Chrome and talk a big game about the problem but continuously delay changes? If Safari behaved the same as Chrome, then Apple couldn't market Safari as more private than Chrome.

This is obviously untrue. People accuse Apple of marketing differences where none exist all the time. Thus the trope "X did it first" or "Y on Z is basically the same."

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#209
post #183

Earlier quoted context omitted.

> I haven't seen marketing related to audio fingerprinting protection. Apple announces powerful new privacy and security features: https://www.apple.com/newsroom/2023/06/apple-announces-power... WebKit Features in Safari 17.0: https://webkit.org/blog/14445/webkit-features-in-safari-17-0... In general, Apple is trying to market itself as the privacy company. "What happens on iPhone stays on iPhone", yadda yadda. > May…

Bad engineering yet state of the art. What are Chromium’s protections against web audio fingerprinting? In the game of tracking, minor hurdles are great at stymying many actors. And finally, your citation in response to someone saying they haven’t seen Apple market web audio fingerprinting protections has no references to said feature. Are you saying all the privacy features in that press release are a smokescreen? I…

> What are Chromium’s protections against web audio fingerprinting?

I'm not aware of any. But they aren't advertising fingerprinting resistance either.

> In the game of tracking, minor hurdles are great at stymying many actors.

That's questionable.

> And finally, your citation in response to someone saying they haven’t seen Apple market web audio fingerprinting protections has no references to said feature.

There were multiple antifingerprinting methods in Safari 17. The linked articles referred to them collectively.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#210
post #201

Earlier quoted context omitted.

And a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater. Do you see why you’re coming across as having inconsistent standards and thereby perhaps an axe to grind? iCloud Private Relay is used for all network activity from Safari which does not seem like a “limited amount of activity.”

> And a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater. A VPN isn't designed to keep your IP address hidden from the operator. iCloud Private Relay doesn't hide your IP address from Apple either. That's not the point, and everyone knows this in advance. The point is to keep your IP address hidden from the request destination servers.

Your logic is that any flaw in an implementation renders it useless. In the case of VPNs, operators can and do share information about clients to destination servers, law enforcement, and more out of band. Just because it involves a spreadsheet and not a WebRTC request does not mean it can be forgiven if you're going around making absolutist claims regarding efficacy.
Post reply on HN