Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

231–240 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#231
So there seems to be some confusion around fingerprinting related to identifying characteristics and tracking. These are two different things. Setting your timezone to UTC, masks that one characteristic of your "identity". But there are better signals for location than timezone, like GeoIP. Same with hiding capabilities. All this does is make the web harder for you but it doesn't make your untrackable. Trackability comes from a combination of factors both within and out of your browser's control. If you share your IP with a family of 4, and you go changing your request headers you are only making yourself MORE trackable. The fact that one request comes across with UTC as a timezone and others come back with EST or other timezones, means I now can track a single user on this single IP. This is made worse if you and your family are using different browsers or different devices.

So what do we care about? If you care about being untrackable, then you have a couple of options, rotate VPNs, or cycle your public facing IP often. Additionally, every request you make MUST change up the request headers. You could cycle between 50 different sets of headers. Combine these two and you will likely be very hard to fingerprint.

If you only care about being identified, use Tor + the Tor browser which makes A LOT of traffic look identical.

Re: The privacy nightmare of browser fingerprinting

#232

When an individual stalks a person without their consent, it is considered unlawful. Why is it ok for websites to do this? Perhaps what is missing is a criminal law that forbids deliberate non-consensual tracking of a person's activity. Even in public. Recording someone as you happen to be recording something in public (including CCTV) is not deliberate or targeted towards an individual. But even in public, if someon…

A counter argument is that stalking in itself, in the US at least, is not unlawful. It becomes unlawful once someone starts threatening another person. So the digital analog would be to allow tracking as long as the site doing the tracking doesn't threaten the people that are being tracked.

Re: The privacy nightmare of browser fingerprinting

#233
post #52

Firefox w/ the Arkenfox user.js is probably as good as it gets in terms of privacy. By default, this config burns cookies on exit, standardizes the time zone to UTC, spoofs the canvas fingerprint, and does other helpful things. Basically, it makes Firefox expose the same information as the Tor browser. In addition, I block most known advertizing/tracking domains at the DNS level (I run my own server, and use Hagezi's…

There's no point unless a critical mass of people use these tools. You will be the only one on your IP address using this configuration of masked fingerprinting, which is itself a fingerprint. That's also why it's indeed useful when using Tor, because you're not identified by your base IP. Unless we make this part of the culture, you have basically 0 recourse to browser fingerprinting except using Tor. Which can itse…

Basically the XKCD license plate comic: https://xkcd.com/1105/

Re: The privacy nightmare of browser fingerprinting

#234

The core of the problem is that we've made this behavior of "run javascript that pulls more javascript and then run that too" the default. Stallman was right, as always.

The older I get the more I see that RMS was right about so many things. When I was young I used to think of him as that eccentric pedantic mit guy but now I see him as a true warrior for freedom.

Oh yeah. He's been telling us for decades how technology will be used to oppress people. I guess he had the experience of how things turned out with UNIX, and knew first hand how hard he had to work to even have a chance at undermining them. What he did at a time was build something from scratch which was compatible with the UNIX interface. These days I would call that a lost battle.

Imagine if you said: I'm going to undermine facebook by building another social network which will be Free software, and will be compatible with facebook. I'll federate facebook whether they like it or not, and I'll do that by reverse engineering how facebook servers talk to each other. That wouldn't work because it takes you huge effort to pull off, and it takes facebook zero effort to change the interface in a tiny way that breaks everythign for you. (Ok the analogy isn't perfect, but hopefully you get the idea of diminishing something's value by forcefully opening it up)

But he hugely contributed to win a battle like this in the late 80s, then Linus Torvalds came in and finished the job in 1991 or so. RMS doesn't get the credit or even appreciation he deserves. I think he's one of the most tragic figures in the history of computers.

Re: The privacy nightmare of browser fingerprinting

#235
post #226

Earlier quoted context omitted.

> How does tracking me and invading my privacy make ads perform better? If you don’t want to be tracked, you shouldn’t be, but how could it not? At a very simple level, an ad targeted towards a 50 year old woman isn’t going to be the same ad to show a 14 year old boy. Different people like different things and ads targeting you as an advertising profile are going to be better than ones that aren’t. You may not like t…

A 14-year-old is unlikely to read/look at the same content as a 50-year old woman. That's how contextual advertisement works.

contextual advertising isn't targeted advertising, yes.

Re: The privacy nightmare of browser fingerprinting

#236

Sandboxing in containers and manually exempting specific security tokens is arguably one of the better steps we can take in the immediate term, as are random agent strings and returning fake data for common prompts. Of course that only works in the immediate, because this, like advertising in general, is an arms race at the moment. This feels like a regulatory question, not a technical one. We've repeatedly proven th…

> ...severe consequences for data breaches...

Often had the same thought, if not shared same opinion. On the other hand, stiffer penalties have the trade off of incentivizing cover-ups, i.e. disincentivize honest disclosure.

Re: The privacy nightmare of browser fingerprinting

#237
post #121
post #106

Don’t confuse privacy with anonymity. One is a right in the US, the other is not.

Not trying to be sarcastic; I may be unaware of some relevant legal framework for the US, could you please elaborate which one is a right and how is it enshrined and enforced?

Arguments for both are derived from, but not explicit in, the Bill of Rights. Privacy has broad points of support while anonymity is primarily attributed to the First Amendment, but only in narrow circumstances.

Re: The privacy nightmare of browser fingerprinting

#238
The real problem here is not technical, it's political. None of this should be legal, let alone the basis of companies worth hundreds of billions. This is surveillance capitalism, and is incredibly harmful to society in a multitude of ways. And as long as the owning class is able to dictate what's legal, this injustice will continue.

Re: The privacy nightmare of browser fingerprinting

#239
post #159

Earlier quoted context omitted.

My preferences are based on my understanding of myself. I do not have those problem addictions. Of course I am going to comparison shop for any large purchases. I am good enough about controlling spending that excess junk isn't one of my problems. But what I do have a problem with is coming up with creative ideas for people in my life. So, for example, I would have never thought to look for https://www.zazzle.com/cup…

There are always situations where an advert is useful and we remember those. However, when an advert causes you to spend more than you would, you have no idea it has happened. Maybe you truly are above the influence of advertising. However, almost no one believes that they are affected by advertising yet clearly almost all of those people are wrong. I find it safer to assume I am part of the vast majority of people w…

You do you. If you believe that you are helpless in the face of the temptation of advertising, you should avoid advertising.

But it would be nice if you worked on your listening skills as well.

You gave a list of major evils that consuming advertising leads to. I don't suffer from those evils. Or at least if I do, then I must also in serious denial to be unaware of it.

You also seem to think that I said that I am unaffected by advertising, and it doesn't lead to me spending money. This is a bizarre conclusion given that I said that I am affected by advertising, and I gave an example of where it did lead to me spending money.

But the critical difference is this. You treat advertising as an assault on your mind. Whose job is to enable evil corporations to steal your money. I view advertising as a discovery method. The world is full of innovators coming up with things that they think others may want. They then use advertising as a way to let people know that there is a thing that they may want. I rarely want it. But I'm willing to waste a bit of time on the pitch.

And on the rare occasions that I do get something, I actually enjoy it regularly. That cup I mentioned? I just made tea for my wife, and served it to her in that cup.

We are different people. I have a very different relationship to advertising than you do. The fact that it is different, doesn't mean that I'm wrong to be me.

Re: The privacy nightmare of browser fingerprinting

#240
post #66

Earlier quoted context omitted.

> Does it hide GPU name that is exposed via WebGL/WebGPU? Does it hide internal IP address, available via WebRTC? My GPU is reported as simply "Mozilla" by https://abrahamjuliot.github.io/creepjs/ . The number of cores is also set to 4 for everyone using this config and/or Tor. > It's not going to work, because the fingerprinting script can be (and is often served) from first-party domain. This may be true, but allow…

I had forgotten I was running Ublock origin / Privacy Badger / Ghostry so I was a bit confused with the results from that site. I think it is Ghostry that is faking the responses but I still have a pretty unique fingerprint according to https://coveryourtracks.eff.org/kcarter?aat=1

Isn't ghostry compromised? Having been bought out by an ad company?
Post reply on HN