Live data from Hacker News

Bypassing Safari 17's advanced audio fingerprinting protection

fingerprint.com

251–260 of 266 posts

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#251
post #83

Earlier quoted context omitted.

I'm the opposite. I think website = sanboxed, native = pownage so whenever I can use a website version I often prefer it over a native app. I use photopea all the time now. it's available on every machine, even machines I don't have permission to install software on

A "sandbox" that can freely send anything it wants to any computer connected to the internet

confused why you'd think a native app has any less restrictions on sending anything it wants to any computer connected to the internet.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#252
post #219

Earlier quoted context omitted.

The point is that the "they" who abuse this and the "they" who use it for legitimate reasons usually aren't the same people, and so the "they" who abuse this have no incentive not to out of some concern about their legitimate uses being curtailed.

If "they" run ads which unfortunately most websites do then "they" are part of those who abuse the browser capabilities.

most websites don't, but google doesn't send you to those, but instead to the big ones that do

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#253
post #119

Earlier quoted context omitted.

What’s an easy way to sandbox apps on Windows? Sorry, I’d prefer to stick with my operating system, not install QubesOS.

sandboxie was neat last time i tried it.

Windows has a native sandboxing tech now: https://learn.microsoft.com/en-us/windows/security/applicati...

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#254

Earlier quoted context omitted.

I would have thought it might have yielded a machine and OS identifier - but more user specific than that?

That’s what it does, users on the same browser and same hardware should have identical fingerprints. It’s just one way of multiple to narrow down your fingerprint.

Thanks for the clarification - much appreciated

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#255
post #123

Earlier quoted context omitted.

Defining fingerprinting in a legal terms is fairly difficult. Most regulators would also likely consider fingerprinting for certain use cases as acceptable. E.g., detecting abuse, fraud, CP, etc.

How is that difficult? Anything that is stored to recognise a user on two different devices/sites is fingerprinting.

Oh no my session cookie!

Remember Me On This Device: Not today Satan!

Use code LINUS for immediate jail-time.

Find My iPhone — You mean find my digital privacy regulator.

I think the only way you're gonna swing it legally is by intention.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#256

Earlier quoted context omitted.

I think fewer people would be in favor of this if apple just let you download native apps and run them on your iPhone like any other computing device.

Apple lets you run native apps on the iPhone. You get them through the App store.

I mean, at this point do I need to add the asterisk? *: From any source, not just the app store

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#257
post #183

Earlier quoted context omitted.

I haven't seen marketing related to audio fingerprinting protection. Maybe Hanlon's applies here. As for your point about the pattern of vulnerabilities: I'd attribute this to being closed source. They keep shipping security features with limited auditing, and only discover flaws in production.

> I haven't seen marketing related to audio fingerprinting protection. Apple announces powerful new privacy and security features: https://www.apple.com/newsroom/2023/06/apple-announces-power... WebKit Features in Safari 17.0: https://webkit.org/blog/14445/webkit-features-in-safari-17-0... In general, Apple is trying to market itself as the privacy company. "What happens on iPhone stays on iPhone", yadda yadda. > May…

> In general, Apple is trying to market itself as[...]

And I haven't heard any argument suggesting that the marketing is deceptive. Apple implemented numerous fingerprinting protections and nobody has demonstrated any of them to be "theatre" or mere "marketing", only that a security researcher was able to defeat one protection among many (and then published their work so Apple can solve for it in the next release). In reality, ALL such work is an ongoing battle between developers and security researchers.

In each subsequent reply you are shifting your stance in order to deflect away from this original claim, essentially by holding Apple to an impossible standard where anything less than perfection on the first try is equivalent to scamming the public with lies. Do you want to defend your original claim that "a lot of Apple's privacy features nowadays are marketing" and "privacy theater"?

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#258
post #226

Earlier quoted context omitted.

> That's a rather bold claim, unless you're a mind-reader. It seems like you have me confused with someone else in the thread who used the phrase "wild accusation" and are responding rudely. I think your original comment was needlessly exaggerated and inflammatory and defending it, instead of clarifying it, is a bad look. Clearly you have an axe to grind with Apple, and my advice to you is you should put a little mor…

> It seems like you have me confused with someone else in the thread who used the phrase "wild accusation" No, I'm not confused. But that comment was the context for my mentioning CVE and 0days, which you decided to discuss yourself. simondotau: "That's an wild accusation to make without citations." me: "Shall I cite my list of CVE? Or perhaps it would be more interesting to cite my list of unfixed 0days." you: "The…

> Where exactly was I rude?

You're throwing around your ego and responding with alleged claims of personal expertise when this discussion has nothing to do with that. You're deflecting with puffery; which is irrelevant with respect to your original claim which I questioned. I don't care that you have a list and I don't care how long it is. You accused Apple of engaging in privacy theatre, and that "many" privacy features where mere "marketing". Defend that claim or move on.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#259
post #248

Earlier quoted context omitted.

You have noscript to block all that but it breaks the most simple sites these days. Part of it is legitimate like responsive design (though most can be done with css these days). But most of it is bullshit tracking, anti-scraping and similar stuff.

Responsive sites could’ve been done with css a decade ago too. IIRC Even IE6 has some support for flexbox and media queries. but people would rather pick up react and have a pile of js do it for them.

IE6 was EOL before flexbox was a thing, according to Wikipedia.

Re: Bypassing Safari 17's advanced audio fingerprinting protection

#260
post #91
post #64

Earlier quoted context omitted.

I always assume that any difficult/annoying anti-fingerprint techniques make you more identifiable instead of less, since very few people do them.

This is why the Tor Browser attempts its best to only have one fingerprint. The more people use it, the more this argument looses its edge. Or so they say.

Mullvad browser tries to be the same, but for normal internet users. Perhaps it's time to switch over to it full-time.
Post reply on HN