Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

271–280 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#271
post #124

I agree with the points in the article. Fingerprinting of any kind is a major risk for personal freedom. At the same time I want to make sure that content creators are compensated for their work. Ad firms that employ fingerprinting stand between me and the content creator. That said, I'm not going to pay $5/month for every blog that I occasionally read. The ad based model provides a more streamlined approach to compe…

> content creators are compensated for their work I have a gut feeling that we've been tricked (by ad companies) into thinking that this is somehow realistic and that casual "content creators" can get meaningful money from us reading their articles. Realistically, while professional content creators can make a living, writing a blog post every once in a while will not provide meaningful income. Instead of trying to "…

[deleted]

Re: The privacy nightmare of browser fingerprinting

#272

I agree with the points in the article. Fingerprinting of any kind is a major risk for personal freedom. At the same time I want to make sure that content creators are compensated for their work. Ad firms that employ fingerprinting stand between me and the content creator. That said, I'm not going to pay $5/month for every blog that I occasionally read. The ad based model provides a more streamlined approach to compe…

Give each of them $0.25/mo, and you’ll probably 10x-100x what they’re currently getting from you watching ads.

Re: The privacy nightmare of browser fingerprinting

#273
post #126

when PayPal tells you that they already know you and don't require you to log in: that's fingerprint.com behind the scenes. There are pros/cons. It should be obvious by now that using any free service of scale is being paid for by your interactions which are made more valuable through fingerprinting. Trying to circumvent that just makes it more expensive for the rest of us.

>when PayPal tells you that they already know you and don't require you to log in: that's fingerprint.com behind the scenes.

Why use a third party service when cookies can do exactly that? They load their .js from the same domain they set up a cookie and there's no limitation to read that cookie, correct?

Re: The privacy nightmare of browser fingerprinting

#274
post #52

Firefox w/ the Arkenfox user.js is probably as good as it gets in terms of privacy. By default, this config burns cookies on exit, standardizes the time zone to UTC, spoofs the canvas fingerprint, and does other helpful things. Basically, it makes Firefox expose the same information as the Tor browser. In addition, I block most known advertizing/tracking domains at the DNS level (I run my own server, and use Hagezi's…

There is also server side fingerprinting like JA4+ and others. Also, if you somehow evade fingeprinting, you have to prepare yourself to solve some very slow Google and Cloudflare captchas.

Privacy tax, sigh

Re: The privacy nightmare of browser fingerprinting

#275

You could test with this: https://github.com/abrahamjuliot/creepjs Does it store the data? Unknown. The best browser for protection is https://mullvad.net/en/browser because it makes the connection uniform, to better blend in.

> best I guess that really depends on how you classify "best" Tor is pretty good for protection. Then there's always i2P as well… Saying one browser can protect the best is pretty hard to prove.

Mullvad Browser is just Tor Browser without tor.

Among all the available browsers, mullvad/tor browser is the best we have in terms of fingerprinting resistance.

Re: The privacy nightmare of browser fingerprinting

#276
post #101

For a fingerprint to be useful it must not only be unique but also persistent. If I have a process that randomly installs and deletes wacky fonts, I'm unique at any given time, but the me of today can't be linked to the me of tomorrow, right?

>If I have a process that randomly installs and deletes wacky fonts, I'm unique at any given time, but the me of today can't be linked to the me of tomorrow, right? See: https://xkcd.com/1105/ Services with a large enough fingerprinting database can filter out implausible values and flag you as faking your fingerprint, which is itself fingerprintable.

The problem we’re falling into under this (ostensibly accurate) point is when we start making this a game, where fingerprinting is either “100% effective and insidious”, or “can’t be 100% certain 100% of the time, so it’s ineffective and nobody will use it against me”.

The point is that a sufficiently motivated actor could use a very broad array of tactics, some automated and some manual, to identify, observe, track, and/or locate a target. Maybe they can’t pin you down with your browser fingerprints because you’ve been smart enough to use tools that obfuscate it, but that’s not happening in a vacuum. Correlating one otherwise useless datapoint that happens to persist long enough to tie things together at even low-ish confidence is still a hugely worthwhile sieve with which to filter people out of the possibility pool.

The problem isn’t that it doesn’t affect most average people, or that it it’s terribly imprecise. The problem is that it’s even a little effective, while being nearly impossible to completely avoid. It’s also a problem if that’s used by a malicious state actor against a journalist, to pick a rather obvious example. Because even in isolation, this kind of violation of civil liberties necessarily impacts all of society.

The public should be given more information and control, broadly speaking, for when they are asked to trade their rights for convenience, security, and/or commerce. In particular, I think the United States has allowed bad faith arguments against regulatory actions and basic consumer rights so corporate lobbyists can steamroll any chance of even baseline protections. It would behoove all of us to be more distrustful of companies and moneyed interests, while being more engaged with, and demanding of, our governments.

Re: The privacy nightmare of browser fingerprinting

#277
post #229

What I don't get, all this data is reported by your machine - why isn't there a tool/browser fork that allows spoofing a (fairly) complete realistic profile, with some sane presets like Edge/W11/Thinkpad or Safari/macOS/M4? Is it too complex, would it break too much, or am I just unaware?

Most privacy-thumping browsers do this, to some degree, but it’s not a panacea. The article gets into it.

Re: The privacy nightmare of browser fingerprinting

#278

I still haven't found a method that can fingerprint simple Firefox containers. I use automatic temporary containers as a rule, and rules for specific sites where I want to keep persistent sessions. I don't understand how temporary containers are still not a built-in Firefox feature, it seems like such a no-brainer solution for privacy.

[deleted]

Re: The privacy nightmare of browser fingerprinting

#279
post #92

I still haven't found a method that can fingerprint simple Firefox containers. I use automatic temporary containers as a rule, and rules for specific sites where I want to keep persistent sessions. I don't understand how temporary containers are still not a built-in Firefox feature, it seems like such a no-brainer solution for privacy.

How to scream I'm behaving badly online...

How to scream, “I’m living a life of unalloyed privilege.”

Re: The privacy nightmare of browser fingerprinting

#280
post #58

Earlier quoted context omitted.

Yes, but you can make assumptions based on what you know about humans generally. Like their example that if you ask if you have long hair. If you answer yes the likelihood is you are probably female. You can think of all sorts of questions and answers like this, and when you combine with the assumptions and answers from previous answers you can make even more assumptions. They won't always be correct, but you don't h…

https://medium.com/@colin.fraser/target-didnt-figure-out-a-t... https://www.predictiveanalyticsworld.com/machinelearningtime...

Even if that one particular instance is false, I seem to remember Target saying their model was too accurate and they were changing how they did things. i.e. Target admitted to predicting pregnancies very well.

Why would they do that, if they didn't think their system was that good?

Post reply on HN