Live data from Hacker News

Bypassing Safari 17's advanced audio fingerprinting protection

fingerprint.com

211–220 of 266 posts

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#211
post #209

Earlier quoted context omitted.

Bad engineering yet state of the art. What are Chromium’s protections against web audio fingerprinting? In the game of tracking, minor hurdles are great at stymying many actors. And finally, your citation in response to someone saying they haven’t seen Apple market web audio fingerprinting protections has no references to said feature. Are you saying all the privacy features in that press release are a smokescreen? I…

> What are Chromium’s protections against web audio fingerprinting? I'm not aware of any. But they aren't advertising fingerprinting resistance either. > In the game of tracking, minor hurdles are great at stymying many actors. That's questionable. > And finally, your citation in response to someone saying they haven’t seen Apple market web audio fingerprinting protections has no references to said feature. There wer…

>> In the game of tracking, minor hurdles are great at stymying many actors.

>

> That's questionable.

It's basically indisputable. Ask any online advertising buyer about the effectiveness of audience targeting for Safari users versus the competition. Or consider the ability of the average website operator to adopt Fingerprint.js instead of whatever half-broken tool their usual audience measurement provider offers them.

https://blog.google/products/chrome/privacy-sandbox-tracking...

> Chrome is testing Tracking Protection, a new feature that limits cross-site tracking.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#212
post #123
post #118

I look forward to the day the EU makes fingerprinting illegal.

Defining fingerprinting in a legal terms is fairly difficult. Most regulators would also likely consider fingerprinting for certain use cases as acceptable. E.g., detecting abuse, fraud, CP, etc.

let's just make fingerprinting for advertising illegal, and then go from there

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#213
post #97
post #83

Earlier quoted context omitted.

I'm the opposite. I think website = sanboxed, native = pownage so whenever I can use a website version I often prefer it over a native app. I use photopea all the time now. it's available on every machine, even machines I don't have permission to install software on

You can sandbox native apps too. Hell, even run them in an airgapped virtual machine. I wouldn't trust a browser sandbox all that much given the high interest in subverting it.

I firejail browsers specifically to stop them from playing audio, it's much easier than playing wack-a-mole with the browser settings.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#214
post #205
post #204

Earlier quoted context omitted.

"Please note that this leak only occurs with iCloud Private Relay on iOS 15" All software has bugs. I think it is more interesting to see how companies respond to reported issues. And how they improve things. Is OpenSSL "theatre" because it had (bad!) bugs in the past?

[flagged]

Well I’ll add to my response that I think it is delusional to think that (security) features ship bug free. It is a bar that _nobody_ can or has met. It is not how the software world works at large.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#215
post #109

Earlier quoted context omitted.

The browser in this adversarial scenario is also in control of the audio context too

Do you, as an end user, know how to change these settings compared to changing your user agent?

From the average user perspective those settings are equally impossible to change, as they neither know nor care that they even exist.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#216
post #126
post #110

Earlier quoted context omitted.

browsers should come with a default software renderer, and behave like the mic and camera where the site will require user permission to release the hardware GPU render path.

Do you have any concept of how many gigawatts per day that would waste?

Just a guess, 1.21 GW?

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#217
post #110
post #87

Another interesting technique to fingerprint users online is called GPU Fingerprinting [1] (2022). Codenamed 'DrawnApart', the technique relies on WebGL to count the number and speed of the execution units in the GPU, measure the time needed to complete vertex renders, handle stall functions, and more stuff ________________ 1. https://www.bleepingcomputer.com/news/security/researchers-u...

browsers should come with a default software renderer, and behave like the mic and camera where the site will require user permission to release the hardware GPU render path.

LibreWolf does this, actually: it initially blocks websites from using WebGPU (and canvas) by default and then gives you a popup to grant them permission.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#218
post #202

Earlier quoted context omitted.

> If Apple only cared about the problem at a superficial level, why wouldn’t they do the same as Chrome and talk a big game about the problem but continuously delay changes? If Safari behaved the same as Chrome, then Apple couldn't market Safari as more private than Chrome.

This is obviously untrue. People accuse Apple of marketing differences where none exist all the time. Thus the trope "X did it first" or "Y on Z is basically the same."

> People accuse Apple of marketing differences where none exist all the time. Thus the trope "X did it first" or "Y on Z is basically the same."

I don't know what you're talking about. What are X, Y, and Z specifically?

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#219
post #185

Earlier quoted context omitted.

there isn't a 'they' and an 'us' in this situation

"They" refers to web developers. "Us" refers to users. We are the owners of the machines where their code will run. They have complete freedom on their servers. On my computer, I make the rules. They are lucky if I allow their code to run at all.

The point is that the "they" who abuse this and the "they" who use it for legitimate reasons usually aren't the same people, and so the "they" who abuse this have no incentive not to out of some concern about their legitimate uses being curtailed.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#220
post #214
post #205

Earlier quoted context omitted.

[flagged]

Well I’ll add to my response that I think it is delusional to think that (security) features ship bug free. It is a bar that _nobody_ can or has met. It is not how the software world works at large.

> Well I’ll add to my response that I think it is delusional to think that (security) features ship bug free.

Have you considered that I'm not delusional, and my point may be more subtle than your straw man?

> It is not how the software world works at large.

Have you considered that I'm a software developer myself?

Post reply on HN