Live data from Hacker News

Block Fingerprinting with Firefox

blog.mozilla.org

301–310 of 411 posts

Re: Block Fingerprinting with Firefox

#301
I wonder is there is the possibility (or if someone came across) of saving (and loading) all the data of a fingerprint state, or to be able to craft one, modify it, or share it. That is, all the metadata (cookies, history, etc.) that supposedly identifies a user-type.

It could be interesting to have a drop-down in the browser to select a "who I want to be today" profile and be able to see the world from that perspective.

Re: Block Fingerprinting with Firefox

#302
post #299
post #291

Earlier quoted context omitted.

they're there for denying access to automated scripts.

This is the reason they exist in the first place, but doesn't answer the question why they're implemented this particular way.

They're implemented this particular way to provide training data for image segmentation systems, they move the image around inside the frame which allows them to use a few people doing the challenge to create a boundary representation that can be used to train things like YOLO style ML systems

Re: Block Fingerprinting with Firefox

#303
post #296
post #282

Firefox is playing its trump, the privacy, very well lately. This is very smart as the competition has no good answer. Equalizing on privacy level would go against their business model so they won't ever do it wholeheartedly. Trying out Firefox now...

> Equalizing on privacy level would go against their business model... More importantly it would go against the mission statement. Mozilla isn't around to make money, it's around to make progress toward a mission. (Search revenue helps fund that, but revenue is not the end goal for Mozilla).

He was talking about the competition, not Mozilla.

Re: Block Fingerprinting with Firefox

#305

It seems that almost weekly, I am reminded why I love Firefox because of some new thing Mozilla is doing. A lot of good decisions have been coming from them lately.

FF is my primary browser, yet people I know that work in security laugh at me as they claim FF is always the first browser to fail in the hacker games. I don't know enough about why, but I'd love for that to not be a thing. Taking into account my threat profile (types of sites I visit, JS blocking, etc), I feel the hacking risk is still a worth while trade off for the lack of tracking.

I've heard that too.. I know it's been attacked successfully at pwn2own a few times, and in the past the sandbox on e.g. Linux wasn't as restricted.

I think things have improved though.

Re: Block Fingerprinting with Firefox

#306
post #148

Earlier quoted context omitted.

17.62 bits on firefox, 11.0 on Tor, 17.63 on chrome. On firefox, the big contributors are HTTP headers (my native language is announced), hash of WebGl fingerprint and time zone. On Tor big contributors are hash of webGL fingerprint, screen size. On chrome, they are system fonts, hash of canvas fingerprint, user agent, and time zone. I am not too concerned about the fingerprinting in firefox since I have strict block…

> On Tor big contributors are hash of webGL fingerprint, screen size. Doesn't tor randomise the window size on startup? Though I guess it chooses some sensible size for your screen which is then leaking info about your screen size (in a pretty indirect way).

Not quite correct. It automatically picks the browser window size based on the monitor its being displayed on, in some multiple of 200x100. There is no randomization on every run.

https://tor.stackexchange.com/questions/15705/why-does-tor-b...

Re: Block Fingerprinting with Firefox

#307
post #54

I've been really impressed with Firefox Quantum for the steps they've taken towards privacy and transparency. This definitely seems like the edge that Mozilla will have when trying to stand out against Chromium-based browsers going forward (especially now that everyone else seems to base their browser off of Chromium).

I'm a big user of Firefox since I switched from Chrome 1 year ago for these reasons, but I wonder why don't they base their underlying engine on Chromium then build all their safety, privacy and other niceness on top of that?

I know Mozilla has been working hard on the engine (rewrite with Rust?) and new versions like Firefox Focus on mobile is blazing fast, but keeping a separate renderer (and developer tools!), with its own issues and discrepancies, seems like a lot of sweat and pain when the Chromium project seems decently sound OSS. I know being able to put in practice your own interpretation of standards is a great exercise in freedom and web diversity, which seems to reinforce their mission, but still... the end result is probably millions in economic impact worldwide to keep website codebases aligned with browser standards, even if the differences are apparently minimal and 99% of the time it just works.

Is being a fully independent browser Mozilla's main raison d'être?

Re: Block Fingerprinting with Firefox

#308
post #293

Earlier quoted context omitted.

Google's reCAPTCHA is cancer upon the web. Everyone should enable fingerprint block to shut this invasive and abusive garbage. If everyone would block it the website owners would have no choice other than to move to a different captcha system.

Do you know of any good alternatives? I would love to get rid off recaptcha but it is a very convenient and quick to set up way to stop most spam bots.

There is an ongoing thread that may help you: https://news.ycombinator.com/item?id=20058697

Re: Block Fingerprinting with Firefox

#309
post #283

Earlier quoted context omitted.

Cloudflare must be mentioned when talking about recaptcha and cancer. They are the ones locking people out from whole websites and forcing you to fill out these recaptchas. They are also the ones who have almost destroyed browsing the internet using TOR due to these recaptchas.

While I agree with you -- I'd also like to point out that >90% of malicious traffic to the websites I administer comes through the Tor network. It shouldn't be the case, and I don't want to block people who have a legitimate reason to use Tor. Unfortunately there isn't a "block Tor traffic from assholes" option, so all I can really do to reduce the malicious traffic is block exit nodes.

This has nothing to do with Tor. Cloudflare frequently blacklists entire countries/counties worth of people (and rarely reverts those blacklists). There is a good chance, that you have missed a lot Indian/Vietnamese/Russian/Chinese visitors, because Cloudflare concluded, that forwarding their traffic to your site isn't financially viable for them.

> Unfortunately there isn't a "block Tor traffic from assholes" option

What exactly is "Tor traffic from assholes"? Bulk DDoS attacks? E-mail spam? SSH login attempts? Please share your valuable experience with everyone here, so that all of us could stay safe by learning from your example.

Re: Block Fingerprinting with Firefox

#310
post #3

As always when it comes to Firefox and privacy, the question is why isn't it on by default?

We can only wonder.

Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional.[1]

[1]https://www.mozilla.org/en-US/about/manifesto/details/

Post reply on HN