It's a little unclear to me - does Brave prevent it or not? Edit: some interesting background on what they do here: https://github.com/brave/brave-browser/wiki/Fingerprinting-P...
https://privacytests.org Maintained by a Brave employee, though the site is fully open in all senses of the word, as far as I'm aware.
Web fingerprinting is worse than I thought (2023)
201–210 of 219 posts
Re: Web fingerprinting is worse than I thought (2023)
#202Earlier quoted context omitted.
https://news.ycombinator.com/item?id=44169115 They found sneaky ways on Android. There is no way they aren't trying to do so on iOS. One must always assume malice with anything Meta.
It always freaked me out that WhatsApp found the SMS code sent to verify the phone number without requiring any action from me. Also, WhatsApp refuses to be usable without giving it Contacts access. I had to use the app, login to the web client, and then I was finally able to type a phone number to start a new chat. I ended up uninstalling it, but there's plenty of people AND business that nowadays mainly or even onl…
For example,
1. Export contacts from the Contact app to a file if it is not a new phone
2. Disable Contacts app
3. Install a different contact database such as OpenContacts from F-Droid or Github
4. Import contacts from the file into OpenContacts
WhatsApp will not import the contacts in the OpenContacts database
Further, no other app will import these contacts either
This solves the "access to contacts" issue
Re: Web fingerprinting is worse than I thought (2023)
#203Re: Web fingerprinting is worse than I thought (2023)
#204Edit: Have also set all other `fingerprinting` bools to False. uBlock, uMatrix, Privacy Badger installed.
Under Settings → Privacy and security: Enhanced Tracking Protection = strict. Tell websites not to sell or share my data. Delete cookies and site data when Firefox is closed. Enable HTTPS-Only Mode in all windows. Enable DNS over HTTPS using: Max Protection – I still can be detected.
Edit 2: Just tried with Brave, strictest settings. No effect, I am detected.
Edit 3: Tor works.
Re: Web fingerprinting is worse than I thought (2023)
#205Earlier quoted context omitted.
Haha, that failed spectacularly. On stock Mac OS Safari (no plugins, no hardened config), I did what they asked and visited their site in incognito mode via a VPN. It gave me a different id, with a message gleefully announcing that "your ID is the same when you're in incognito mode!" It even showed me some supposed visit from a minute ago. Jesus what a scam.
Hi, I work at Fingerprint. Our demo accuracy is actually much lower than in production. You're welcome to try it yourself for free: https://dashboard.fingerprint.com/signup
Re: Web fingerprinting is worse than I thought (2023)
#206Browser fingerprinting is one of those things that should be outright illegal - it is far more of a threat than tracking cookies ever were. But it hasn't permeated the public consciousness like cookies have, so regulators seem to ignore it.
This is a technical problem, not a legal one. The solution is for browsers to provide users with the ability to limit the information being sent. There's no need for the vast majority of websites to know my OS, number of CPUs, screen or window size, or most of the other fingerprinting metrics.
It isn't trivial to craft legislation to separate these use cases, but it also is far from impossible if there would be political will to do it.
I think the latter is far more interested in surveillance of users where tracking is one building block.
And of course legislation is needed to criminalize tracking without user consent. It would just be an internet stalking law being applied.
Re: Web fingerprinting is worse than I thought (2023)
#207Earlier quoted context omitted.
> What is the downside Just of the top of my head: - Timezone is set to UTC which means any web calendar input becomes confusing at best - Canvases turn into random stripes, which leaves artefacts all over many websites - Some websites outright block you as bots (twitch does this) - Some web APIs break, which can be a pain if you're web apps that rely on them You can add websites to a whitelist to avoid the downsides…
other downsides, cloudflare, PayPal and all kinds of finance related sites will assign high threat level for you and you will make your life miserable for causes ranging from captcha through rejecting your purchases to even blocking you access. and the worst part is that this didn't changed the fingerprint generated by mentioned here site just increases suspect level to 9
resistFingerprinting does seem to work against fingerprint.com in my experiments after clearing its website data and a browser restart.
Re: Web fingerprinting is worse than I thought (2023)
#208Earlier quoted context omitted.
It always freaked me out that WhatsApp found the SMS code sent to verify the phone number without requiring any action from me. Also, WhatsApp refuses to be usable without giving it Contacts access. I had to use the app, login to the web client, and then I was finally able to type a phone number to start a new chat. I ended up uninstalling it, but there's plenty of people AND business that nowadays mainly or even onl…
In testing I did, it is possible to run WhatsApp on Android without access to "Contacts" For example, 1. Export contacts from the Contact app to a file if it is not a new phone 2. Disable Contacts app 3. Install a different contact database such as OpenContacts from F-Droid or Github 4. Import contacts from the file into OpenContacts WhatsApp will not import the contacts in the OpenContacts database Further, no other…
Re: Web fingerprinting is worse than I thought (2023)
#209Would be curious how Brave handles fingerprinting, I’ll have to look into that.
Brave has built in fingerprinting protection ( https://github.com/brave/brave-browser/wiki/Fingerprinting-P... ), that's enabled by default. It seems like it's less aggressive than firefox's though (since firefox's fingerprint protection is disabled by default because it breaks things), and it doesn't seem to be able to block this companies fingerprinting tech. I got the same ID in a regular window and private browsi…
Re: Web fingerprinting is worse than I thought (2023)
#210Earlier quoted context omitted.
It always freaked me out that WhatsApp found the SMS code sent to verify the phone number without requiring any action from me. Also, WhatsApp refuses to be usable without giving it Contacts access. I had to use the app, login to the web client, and then I was finally able to type a phone number to start a new chat. I ended up uninstalling it, but there's plenty of people AND business that nowadays mainly or even onl…
In testing I did, it is possible to run WhatsApp on Android without access to "Contacts" For example, 1. Export contacts from the Contact app to a file if it is not a new phone 2. Disable Contacts app 3. Install a different contact database such as OpenContacts from F-Droid or Github 4. Import contacts from the file into OpenContacts WhatsApp will not import the contacts in the OpenContacts database Further, no other…