Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

291–300 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#291

Earlier quoted context omitted.

Basically the XKCD license plate comic: https://xkcd.com/1105/

Has anyone wrote software that automatically surfaces the relevant XKCD comic for every article this happens under? I’d like a feature in my HN reader that sticks a red button at the bottom anytime XKCD has already made the points I’m reading.

We should go further and make an AI agent that creates counterfeit XKCD comics of dubious quality for literally every scenario.

Re: The privacy nightmare of browser fingerprinting

#292

Some time ago I noticed that in Chrome, every time you click "Never translate $language", $language quietly gets added to the Accept-Language header that Chrome sends to every website! My header ended up looking like a permuted version of this: en-US,en;q=0.9,zh-CN;q=0.8,de;q=0.7,ja;q=0.6 I never manually configured any of those extra languages in the browser settings. All I had done was tell Chrome not to translate…

Hmmm...YouTube has been getting confused about the language and displaying random languages for the closed captions on videos. This was happening to me across smart TVs but I access YouTube randomly from various devices and browsers...but mostly Chrome when using a browser.

[deleted]

Re: The privacy nightmare of browser fingerprinting

#293
post #240

Earlier quoted context omitted.

I had forgotten I was running Ublock origin / Privacy Badger / Ghostry so I was a bit confused with the results from that site. I think it is Ghostry that is faking the responses but I still have a pretty unique fingerprint according to https://coveryourtracks.eff.org/kcarter?aat=1

Isn't ghostry compromised? Having been bought out by an ad company?

Honestly I did not know.

I have had it installed so long I don't even remember when I did it.

Ill look more into it and perhaps re-evaluate

Re: The privacy nightmare of browser fingerprinting

#294
post #263

Earlier quoted context omitted.

What language do you put that list in? Would you still want to show it to every visitor when you know most of them speak a particular language? I use to do some work in this area. The first question is difficult and the second is no. We had the best results when we used various methods to detect the preferred language and then put up a language selector with a welcome message in that language. After they made a selec…

> What language do you put that list in? Would you still want to show it to every visitor when you know most of them speak a particular language? Judging by... a large number of websites, you make the list available in a topbar, and each language is named in itself. You don't apply one language to the entire list. Here's the first page that popped into my head as one that would probably offer multiple languages (and…

You’re looking at it with the perspective of someone who understands the language the site defaults to. Most non-native speakers have a hard time finding the link and they leave.

Re: The privacy nightmare of browser fingerprinting

#295
post #269

Earlier quoted context omitted.

Is this before or after ICE became a $150B secret paramilitary beholden to a corrupt authoritarian with a large cohort of sycophantic tech billionaires?

I’m not an illegal immigrant so I’m not worried about it

Neither are many of the people ICE has beaten and detained, didn't save them, won't save you.

Re: The privacy nightmare of browser fingerprinting

#296
I want a spoofing tool. How would one go about sending all my browser's traffic through a proxy that swapped out fingerprintable aspects with those of selectable presets of the most common browser configurations? It'd help to be able to bypass certain details for a whitelist domains that actually needed granular exceptions. Most websites don't need this data for serving you.

Re: The privacy nightmare of browser fingerprinting

#297
post #107

Earlier quoted context omitted.

Do you think the fact that NO major content websites (NYT, substack, WSJ, ...) have settled on a PPV model is simply because they haven't thought of it? Or is it more likely that the numbers absolutely do not work?

That's a false dichotomy. I can't speak for all web sites, but I reckon a combination of factors could explain why such a solution hasn't been deployed: 1. Advertising is ubiquitous, easy to integrate, and provides a safe revenue stream. 2. There is little to no infrastructure for the PPV model. Whoever builds it would need to maintain their own version of it. 3. People expect the web to be "free". This is even true…

And people prefer unlimited subscriptions.

Re: The privacy nightmare of browser fingerprinting

#298

Earlier quoted context omitted.

Basically the XKCD license plate comic: https://xkcd.com/1105/

Has anyone wrote software that automatically surfaces the relevant XKCD comic for every article this happens under? I’d like a feature in my HN reader that sticks a red button at the bottom anytime XKCD has already made the points I’m reading.

Randal had a long career of good takes, until around 2016 when they stopped being objectively good.

I’m not kidding at all, that my guess is he was doing drugs and stopped.

Re: The privacy nightmare of browser fingerprinting

#299
post #290

Earlier quoted context omitted.

PSA Don't use chrome.

Translating pages is literally the only thing I use Chrome for. The built-in translation works way better than other browsers, even though they also use Google Translate.

I don’t think safari uses google translate

Re: The privacy nightmare of browser fingerprinting

#300

Earlier quoted context omitted.

Definitely a good STEP1, but it’s not like Firefox and Safari are finger printing secure.

Modern Safari is pretty damned good at randomizing fingerprints with Intelligent Tracking Prevention. With IOS 26 and MacOS 26, it's enabled in both private and non private browser windows (used to be only in private mode). All "fingerprint" tests I've run have returned good results.

Unfortunately, it's closed source and only available on Apple devices.
Post reply on HN