Live data from Hacker News

Bypassing Safari 17's advanced audio fingerprinting protection

fingerprint.com

221–230 of 266 posts

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#221
post #201

Earlier quoted context omitted.

> And a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater. A VPN isn't designed to keep your IP address hidden from the operator. iCloud Private Relay doesn't hide your IP address from Apple either. That's not the point, and everyone knows this in advance. The point is to keep your IP address hidden from the request destination servers.

Your logic is that any flaw in an implementation renders it useless. In the case of VPNs, operators can and do share information about clients to destination servers, law enforcement, and more out of band. Just because it involves a spreadsheet and not a WebRTC request does not mean it can be forgiven if you're going around making absolutist claims regarding efficacy.

> Your logic is that any flaw in an implementation renders it useless.

I didn't say that. It's a straw man.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#222
post #203

Earlier quoted context omitted.

I think you missed the point of my comment. When I said my list of CVE and my list of unfixed 0days, I meant that literally: CVE attributed by Apple to me, and unfixed 0days that I personally discovered. I wasn't making a "wild accusation".

No I understood exactly what you meant. The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive. How many CVEs and 0-days have you filed against Audacity? Is it because that software is security bug free?

> No I understood exactly what you meant.

That's a rather bold claim, unless you're a mind-reader.

> The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive.

I didn't give a number. I only said I have a list. It seems that you're still missing my point, which was simply that my knowledge of and experience with these specific technologies means that my original comment was not a "wild accusation". That's it, that's the whole point.

> How many CVEs and 0-days have you filed against Audacity?

I don't use Audacity, and I have no idea how it's relevant here.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#223
post #221

Earlier quoted context omitted.

Your logic is that any flaw in an implementation renders it useless. In the case of VPNs, operators can and do share information about clients to destination servers, law enforcement, and more out of band. Just because it involves a spreadsheet and not a WebRTC request does not mean it can be forgiven if you're going around making absolutist claims regarding efficacy.

> Your logic is that any flaw in an implementation renders it useless. I didn't say that. It's a straw man.

You said that iCPR is privacy theatre because of a resolved security bug from 2 years ago. Please spell out the implication of that claim for me then.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#224
post #222

Earlier quoted context omitted.

No I understood exactly what you meant. The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive. How many CVEs and 0-days have you filed against Audacity? Is it because that software is security bug free?

> No I understood exactly what you meant. That's a rather bold claim, unless you're a mind-reader. > The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive. I didn't give a number. I only said I have a list. It seems that you're still missing my point, which was simply that my knowledge of and experience with these specific technologies…

> That's a rather bold claim, unless you're a mind-reader.

It seems like you have me confused with someone else in the thread who used the phrase "wild accusation" and are responding rudely. I think your original comment was needlessly exaggerated and inflammatory and defending it, instead of clarifying it, is a bad look. Clearly you have an axe to grind with Apple, and my advice to you is you should put a little more effort into hiding it if you want others to take you seriously.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#225
post #110
post #87

Another interesting technique to fingerprint users online is called GPU Fingerprinting [1] (2022). Codenamed 'DrawnApart', the technique relies on WebGL to count the number and speed of the execution units in the GPU, measure the time needed to complete vertex renders, handle stall functions, and more stuff ________________ 1. https://www.bleepingcomputer.com/news/security/researchers-u...

browsers should come with a default software renderer, and behave like the mic and camera where the site will require user permission to release the hardware GPU render path.

What's the point? The capabilities of browsers are so vast they'll just find other ways to fingerprint.

Privacy in browsers is a lost cause. It's a 30+ year old technology that has become ridiculously bloated in scope, with privacy and security only considered as an afterthought.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#226
post #222

Earlier quoted context omitted.

> No I understood exactly what you meant. That's a rather bold claim, unless you're a mind-reader. > The number of reports is not helpful data without a lot of other context, but you offered it as if it would be convincing or definitive. I didn't give a number. I only said I have a list. It seems that you're still missing my point, which was simply that my knowledge of and experience with these specific technologies…

> That's a rather bold claim, unless you're a mind-reader. It seems like you have me confused with someone else in the thread who used the phrase "wild accusation" and are responding rudely. I think your original comment was needlessly exaggerated and inflammatory and defending it, instead of clarifying it, is a bad look. Clearly you have an axe to grind with Apple, and my advice to you is you should put a little mor…

> It seems like you have me confused with someone else in the thread who used the phrase "wild accusation"

No, I'm not confused. But that comment was the context for my mentioning CVE and 0days, which you decided to discuss yourself.

simondotau: "That's an wild accusation to make without citations."

me: "Shall I cite my list of CVE? Or perhaps it would be more interesting to cite my list of unfixed 0days."

you: "The list of vulnerabilities is not very informative for the same reason a trackers blocked statistic is not."

If you don't want to discuss my previous quoted comment, that's fine, but you have in fact mentioned it and continue to mention it. Thus, the context is very relevant.

> and are responding rudely.

Where exactly was I rude?

> I think your original comment was needlessly exaggerated and inflammatory and defending it, instead of clarifying it, is a bad look.

I would be happy to clarify it, but the first time you asked for clarification was here: https://news.ycombinator.com/item?id=39661492

I'll respond to that comment, though it may take some time.

> Clearly you have an axe to grind with Apple

I've been a Mac user for more than 20 years, a professional Mac developer for more than 15, and I currently sell apps in the Mac App Store and iOS App Store. Do I have critiques of Apple? Yes, of course. However, they are the critiques of an insider who has no intention to leave the ecosystem.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#227
post #177

Earlier quoted context omitted.

Is iCloud Private Relay theatre? 3rd party cookie blocking? What specific features do you allege exist just to mislead the general public?

> Is iCloud Private Relay theatre? https://fingerprint.com/blog/ios15-icloud-private-relay-vuln... > 3rd party cookie blocking? It's very funny that you should ask this question in response to an article about fingerprinting without cookies. But yes, there are various workaround to use 1st party cookies or other storage to take the place of 3rd party cookies. Perhaps the worst is the Safari "Privacy Report", which ha…

The term “security theater” has a specific meaning which is not a bug or less than perfect protection: per its creator, “Security theater refers to security measures that make people feel more secure without doing anything to actually improve their security.”

https://www.schneier.com/blog/archives/2009/11/beyond_securi...

Public Relay is obviously not accurately described by that term and any rule which classifies it as such would be useless because it would classify all browser security as theater because everyone has had bugs, and everyone has had to adopt more sophisticated defenses to counter more sophisticated attackers.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#228
post #227
post #177

Earlier quoted context omitted.

> Is iCloud Private Relay theatre? https://fingerprint.com/blog/ios15-icloud-private-relay-vuln... > 3rd party cookie blocking? It's very funny that you should ask this question in response to an article about fingerprinting without cookies. But yes, there are various workaround to use 1st party cookies or other storage to take the place of 3rd party cookies. Perhaps the worst is the Safari "Privacy Report", which ha…

The term “security theater” has a specific meaning which is not a bug or less than perfect protection: per its creator, “Security theater refers to security measures that make people feel more secure without doing anything to actually improve their security.” https://www.schneier.com/blog/archives/2009/11/beyond_securi... Public Relay is obviously not accurately described by that term and any rule which classifies it…

[flagged]

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#229
post #113

Earlier quoted context omitted.

> Why did Safari add this? A lot of Apple's "privacy" features nowadays are marketing. It's privacy theater. What matters is whether they can tell a plausible story to the public, not whether is technically effective.

Is iCloud Private Relay theatre? 3rd party cookie blocking? What specific features do you allege exist just to mislead the general public?

https://sneak.berlin/20231005/apple-operating-system-surveil...

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#230
post #228
post #227

Earlier quoted context omitted.

The term “security theater” has a specific meaning which is not a bug or less than perfect protection: per its creator, “Security theater refers to security measures that make people feel more secure without doing anything to actually improve their security.” https://www.schneier.com/blog/archives/2009/11/beyond_securi... Public Relay is obviously not accurately described by that term and any rule which classifies it…

[flagged]

Yes, and privacy theater is clearly an attempt to apply the same concept to a closely related topic. I edited my comment to focus on the problem here: you started with this absurdly sweeping claim which you’ve been unable to meaningfully substantiate throughout the thread. Trying to dismiss something as theater based on a bug fixed in the beta period is not only self-contradictory (you’re tacitly admitting that it’s not theater now) but also almost useless as a heuristic because very few products never have bugs.

Now if we want to talk about guidelines, consider that the broad claim you originally made would have to be widely accepted in the industry not to need supporting evidence, at which point it wouldn’t be contributing anything; since the opposite is true, the guidelines about flame bait cover it. It could have gone in a potentially useful direction if you’d been willing to define your terms and support them with evidence, and that would have helped suggest less hyperbolic terms. For example, if you said that Apple could do better at vetting and implementing their features I doubt many people would disagree with you.

Post reply on HN