Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

201–210 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#201

Some time ago I noticed that in Chrome, every time you click "Never translate $language", $language quietly gets added to the Accept-Language header that Chrome sends to every website! My header ended up looking like a permuted version of this: en-US,en;q=0.9,zh-CN;q=0.8,de;q=0.7,ja;q=0.6 I never manually configured any of those extra languages in the browser settings. All I had done was tell Chrome not to translate…

Hmmm...YouTube has been getting confused about the language and displaying random languages for the closed captions on videos. This was happening to me across smart TVs but I access YouTube randomly from various devices and browsers...but mostly Chrome when using a browser.

Re: The privacy nightmare of browser fingerprinting

#202

Earlier quoted context omitted.

> writing a blog post every once in a while will not provide meaningful income Nor, generally, should it. Sitting down one or two Saturday afternoons a month to write a blog post shouldn't be generating the income of a FTE.

Allow me a second to play Devil’s Advocate. What if it could? Or should (be able to produce FTE or close income)? In that world, the amount of pointless shite - questing to “go viral” - would be reduced to near zero. That is, if the incentive were more quality, and less quantity, we’d be better off, yes?

That's tempting, but I still don't think it should. There would still be the quest to go viral. "Quality" would still be determined in the aggregate, which means that your income depends on appealing to the widest audience possible, which means high quality niche bloggers still don't get paid much.

Metrics are hard. Just making sure they reward one particular desired outcome doesn't mean you'll escape the unintended consequences.

Also, note that we are past the point of being able to reasonably able to manage any of this. Today, you'd need to come up with a reward function that cannot be maximized by AI. (And lest you think you can fix that by using site visitors to evaluate, most of them will be bots too.)

Re: The privacy nightmare of browser fingerprinting

#203
post #51

I don't mind advertisers knowing more about me. If they can display ads that are relevant to me, this is a better experience on both sides. Unfortunately there is no way to tell advertisers, "No, I'm not interested in your product. I never will be. Don't waste your money." The top offender is Hims. No, I don't have hair loss. I don't want hair loss supplements. I also don't have ED, and I object strongly to ads for t…

That is a loser's proposition. Targeted advertising should be objected to on the grounds that surveillance and manipulation are unethical, it doesn't matter how useful it may or may not be in your personal experience. Them suddenly being more useful wouldn't make them any more ethical.

Re: The privacy nightmare of browser fingerprinting

#204

Some time ago I noticed that in Chrome, every time you click "Never translate $language", $language quietly gets added to the Accept-Language header that Chrome sends to every website! My header ended up looking like a permuted version of this: en-US,en;q=0.9,zh-CN;q=0.8,de;q=0.7,ja;q=0.6 I never manually configured any of those extra languages in the browser settings. All I had done was tell Chrome not to translate…

PSA Don't use chrome.

I only use it when I want to be tracked.

Re: The privacy nightmare of browser fingerprinting

#206
post #47

Earlier quoted context omitted.

Yes seriously - I'm old enough to have enjoy reading magazines that had ads throughout them. They were fine. I'd venture to say contextual advertising would be more effective than whatever we've been trying to squeeze out of fingerprinting etc. All this supposed "data" they are gathering feels like a scam perpetuated by ad companies about how important it is to the people who buy ads. It's not. Even Facebook and Inst…

Same here. By the time I was old enough to have an income, reading comics had already made it possible for me to -not even see any - advertising. That carried over to newspapers, magazines... all those advertisers were wasting their money. Later on in life I got pissed at cable-TV advertisers shoved into my favorite movies every 5-10 minutes ... ruining any ambience or artistic merit in them ... so I got rid of cable…

> Sites demand subscription? blocked.

Odd. In the midst of a (well-deserved) anti-ad rant, you throw in the primary non-ad alternative and discard it.

> How much longer before advertisers realize how much they're getting ripped off?

A while longer, if the same people who reject ads are also the people who reject alternatives to ads. The advertisers can safely ignore those people's opinions.

(I'm not saying subscriptions are the answer. I don't have an answer. I'm just saying that companies wanting subscription money is not part of the problem where companies want to shove ads in our faces 24/7.)

Re: The privacy nightmare of browser fingerprinting

#207

Earlier quoted context omitted.

Sadly, I think you are wrong. Micropayments seem attractive but the idea falls apart quickly - there are just too many intractable non-technical problems. It has been tried more than once and each effort has failed. I wrote a longer post on this[0] but to save you the click I will state the biggest problem from a privacy point of view - if you think privacy is bad now with ads imagine how much worse it would be with…

I think it is a technical problem. If you could integrate payment channels on top of private cryptocurrencies that would be enough. Even without the lightning network and just direct 1-to-1 payment channels, it would work. The article you lists assumes a "conventional" credit card system with chargebacks, massive fees, etc. which makes micropayments ecosystem impractical in the first place. Proposals for micro-paymen…

> If you could integrate payment channels on top of private cryptocurrencies that would be enough.

That “if” is doing a lot of heavy lifting there.

But my point is that even if a magical technical solution existed tomorrow then the same sites that collect data for ads would continue to do so for the much more valuable data on paying users.

Re: The privacy nightmare of browser fingerprinting

#208
post #96

Earlier quoted context omitted.

If I infiltrate someone else’s computer, secretly run code in order to to exfiltrate data I risk prison time because objectively it seems to satisfy criminal laws over where I live. How do prosecutors in any modern country/state not charge this behavior when done by a website owner?

The difference is that there's implied consent to run arbitrary (albeit sandboxed) code when you visit a website. Moreover it's not the website causing the code to be executed, it's your browser. Otherwise if the bar is "code is being run but the user doesn't know about it", it would lead to either any type of web pages with javascript being illegal (or maybe without javascript, given that CSS turing complete), or a…

> any type of web pages with javascript being illegal

Inshallah

Re: The privacy nightmare of browser fingerprinting

#209

Earlier quoted context omitted.

PSA Don't use chrome.

Definitely a good STEP1, but it’s not like Firefox and Safari are finger printing secure.

what about duck duck go? We need a simple chart: 1. What browsers are good at resisting finger printing 2. tell for each browser, does it work on android ad ios and apple and windows and linux 3. what setting are needed to achieve this

for bonus points, is there no way to strip all headers on chrome on control it better?

Re: The privacy nightmare of browser fingerprinting

#210

Earlier quoted context omitted.

> best I guess that really depends on how you classify "best" Tor is pretty good for protection. Then there's always i2P as well… Saying one browser can protect the best is pretty hard to prove.

Best among existing. Anti-fingerprinting field is still in it's early stages. I wouldn't say Tor Browser is the best because it requires custom configuration to be usable conveniently, which will make the connection non-uniform (and the user will stand out). >Tor is pretty good for protection. Then there's always i2P as well… Tor and i2P does nothing for (anti)fingerprinting - the program which render the web pages d…

I'd like a "Firefox + uBlock Origin" column on that page. (But then you'd have to consider filter lists enabled...)
Post reply on HN