Live data from Hacker News

Open-source tests of web browser privacy

privacytests.org

31–34 of 34 posts

Re: Open-source tests of web browser privacy

#31

Earlier quoted context omitted.

Thank you for the feedback -- I agree more context and explanation is needed for each of these tests. In the Blob case: the test code is storing a unique string in a Blob URL under one website (first party), and then attempting to read back that string under a second, different website. (See "result, different first party".) If the string is accessible under a different first party, then it is possible to use a Blob…

Oh ok. That does make sense. Hopefully you read my comment as feedback and not super negative. Just some verbiage on each test would be wonderful. You have clearly worked on it. It is a really good resource.

> Oh ok. That does make sense. Hopefully you read my comment as feedback and not super negative.

It was helpful feedback. I value all critiques because they help me make the site better.

> Just some verbiage on each test would be wonderful.

There is some explanation for each test, if you click on the test name. But it's clear I need to expand those explanations and also make them easier to find.

Re: Open-source tests of web browser privacy

#32

Wow. Glad that I switched to Brave. I've also looked at ungoogled-chromium and other similar forks, but also concerned about tracking the upstream for fixes fast enough; some of the smaller forks take too long. Brave works really well and is a great experience overall (once crypto ads are disabled).

How is the stability of Brave on Linux? When I was using it 2 years ago on macOS it had frequent crashes and was forced to use nightly builds with lesser crashes.

It would be tough to change from Firefox to Brave on Linux, FF feels native to Linux after all those years of being default browser on several distros.

Also I wonder what would be the test results if FF was run with uBlock Origin; As FF is the best browser to use uBlock with due to lesser API level restrictions.

Re: Open-source tests of web browser privacy

#33
post #26

The entire last two sections are completely arbitrary and cherry-picked, and simply amount to "does the browser ship uBlock and ClearURLs by default with these specific filters", which isn't very informative nor useful a privacy feature, as easy as it is to circumvent by simply using different URL tokens or telemetry providers.

Thank you for the feedback! Granted, blocklists (lists of tracking domains or URL query parameters) can be circumvented by a determined attacker. Indeed, I agree that blocklists aren't sufficient on their own for a browser to provide solid privacy protection. In my view it's critical, primarily, to have policies that enforce privacy, including such protections as state partitioning and fingerprinting resistance. That…

The tests are neat, Thank you.

Can you update the steps to run the tests locally to test against browser with uBlock Origin vs default browser?

Re: Open-source tests of web browser privacy

#34

Very useful table. But it would be very helpful if the table of test results were furnished with a glossary that: (a) explains the function and workings of each item under test, and, (b) also explain how said item is a threat to one's privacy, etc. (how it leaks one's info). This ought to be important, for many users wouldn't have a clue what some or even many of those functions do and it wouldn't be expected as such…

Hi -- thanks for the comments! > it would be very helpful if the table of test results were furnished with a glossary that: There is some explanation for each test -- to see these explanations, you need to click on category titles, test titles, or test results themselves. But I take your point that these annotations need to be expanded and easier to find. > I tried to send feedback to this effect but could not as I'm…

Thank you for your reply on all points.

On the matter of testing browser exploits etc. it seems to me there's no decent comprehensive list of exploitable browser functions that's easily comprehensible to normal users as well as being easily accessible.

I reckon that a link on your homepage to a well organized table etc. that lists browser function names, their description or explanation thereof together with their various exploits (description, modus operandi, notes, links to more info etc.) in an easily readable format would be very worthwhile as would also draw users to your site for that reason alone. When there, they'd also find the browser tests.

(There's any amount of stuff on the web about browsers, exploits etc. but I've not seen one that's comprehensive in that it brings all three aspects into one place.)

About Tor, I would certainly agreed with you. Bootstrapping with fallback security makes sense. If there's any argument then make it optional at the click of a button, etc. In a way, your test results have acted as a review and I reckon that's a good thing.

Frankly, I'm horribly disenchanted with most browsers and we need a site that reviews most of them in an objective and comprehensive way. Perhaps in the future you might consider doing this by reviewing browsers in the light of your tests.

Post reply on HN