Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

341–350 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#341

Earlier quoted context omitted.

Has anyone wrote software that automatically surfaces the relevant XKCD comic for every article this happens under? I’d like a feature in my HN reader that sticks a red button at the bottom anytime XKCD has already made the points I’m reading.

Randal had a long career of good takes, until around 2016 when they stopped being objectively good. I’m not kidding at all, that my guess is he was doing drugs and stopped.

As far as "obligatory xkcd" is concerned: 3154, 3155, 3159, 3160, 3162, 3165 and 3167 are all relevant. (I've found myself citing 3155 a lot, in attempts to deradicalise cranks: it sometimes works, if I can convince them to quit ChatGPT cold-turkey.)

It's fine to like the comics before around 2016, and dislike the ones afterwards, but there's nothing objective about that. Various people have put forward various thresholds for when xkcd "stopped being good", but ultimately it boils down to a combination of what TV Tropes would call "Tone Shift" and "They Changed It, Now It Sucks!".

Re: The privacy nightmare of browser fingerprinting

#342
post #290

Earlier quoted context omitted.

PSA Don't use chrome.

Translating pages is literally the only thing I use Chrome for. The built-in translation works way better than other browsers, even though they also use Google Translate.

Sorry but you're using a Google browser and Google translation service, when excellent alternatives to both exist. What did you expect regarding privacy?

A clueless person might not know any better, but you clearly do, and also you seemingly care. So why do you use Google all the same?

Re: The privacy nightmare of browser fingerprinting

#343
post #52

Firefox w/ the Arkenfox user.js is probably as good as it gets in terms of privacy. By default, this config burns cookies on exit, standardizes the time zone to UTC, spoofs the canvas fingerprint, and does other helpful things. Basically, it makes Firefox expose the same information as the Tor browser. In addition, I block most known advertizing/tracking domains at the DNS level (I run my own server, and use Hagezi's…

Firefox already provides this feature in about:config using resist fingerprint - https://support.mozilla.org/en-US/kb/resist-fingerprinting

Re: The privacy nightmare of browser fingerprinting

#344
post #226

Earlier quoted context omitted.

A 14-year-old is unlikely to read/look at the same content as a 50-year old woman. That's how contextual advertisement works.

contextual advertising isn't targeted advertising, yes.

Indeed. So no idea what your argument is about.

BTW, targeted ads need to be 100% to 700% more efficient than regular ads to be as profitable: https://www.sciencedirect.com/science/article/pii/S016781162...

Re: The privacy nightmare of browser fingerprinting

#345
post #70

Earlier quoted context omitted.

Brave Inc. gets a lot of flack, some warranted, but their Basic Attention Token allows for exactly this. Users can add credit to their wallet by either consuming privacy-friendly ads or topping it up manually, which then gets distributed to the sites they visit in the proportion they choose, transparently in the background while they browse. It is a shame that this feature gets lumped together with claims of crypto s…

Brave strips out the ads that the creators put on their site, puts their own ads there, then gives the creators some of that money if and only if the creator realizes they have to sign up for Brave's cryptoshit. It's straightforwardly the kind of racket that would get your knees broken if you tried to do it to somebody in real life, but "it's ok because it's on computers". All the flak is deserved.

Nope, they don't "put ads on the site". That's not how it works.

Re: The privacy nightmare of browser fingerprinting

#346
post #52

Firefox w/ the Arkenfox user.js is probably as good as it gets in terms of privacy. By default, this config burns cookies on exit, standardizes the time zone to UTC, spoofs the canvas fingerprint, and does other helpful things. Basically, it makes Firefox expose the same information as the Tor browser. In addition, I block most known advertizing/tracking domains at the DNS level (I run my own server, and use Hagezi's…

There's no point unless a critical mass of people use these tools. You will be the only one on your IP address using this configuration of masked fingerprinting, which is itself a fingerprint. That's also why it's indeed useful when using Tor, because you're not identified by your base IP. Unless we make this part of the culture, you have basically 0 recourse to browser fingerprinting except using Tor. Which can itse…

You can and should be using a good VPN to make the masked fingerprint and IP address non-unique.

Re: The privacy nightmare of browser fingerprinting

#347

I still haven't found a method that can fingerprint simple Firefox containers. I use automatic temporary containers as a rule, and rules for specific sites where I want to keep persistent sessions. I don't understand how temporary containers are still not a built-in Firefox feature, it seems like such a no-brainer solution for privacy.

Do you have a repo for this?

Re: The privacy nightmare of browser fingerprinting

#348
The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists.

From a pragmatic perspective, we are forcing two very different networks to run on the same protocols:

The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google).

The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit.

You cannot have a functioning "Business Internet" without identity verification. If you try to perform a transaction (or even just use a subsidized "free" tool like Gmail) while hiding behind a generic, non-unique fingerprint, you look indistinguishable from a bot or a fraudster.

Fingerprinting is often just the immune system of the commercial web trying to verify you are human.

The friction arises because we expect the "Fun Internet" to play by different rules. A Lego fan site shouldn't need to know who I am. But because we access both the Lego site and our Bank using the same browser, the same IP, and the same free tools (Chrome/Search), the "Fun Internet" becomes collateral damage of the "Business Internet's" need for security and monetization.

We can't have it both ways. We accepted the SLA for the "Business Internet" in exchange for free, billion-dollar tools. If you want 100% anonymity, you are effectively asking to use the commercial web's infrastructure without providing the identity signal it runs on.

As the OP notes, mitigation is hard. But that’s not just because advertisers are "evil"—it's because on the modern web, anonymity looks exactly like a security threat.

Re: The privacy nightmare of browser fingerprinting

#349
yeahh. For me technically it does not make sense for "privacy friendly" web analytics to rely on fingerprinting techniques because the common sentiment seems to be that cookies are bad. At least cookies are easily controllable.

Now shameless adverting: of course I present the solution: https://counter.dev

Re: The privacy nightmare of browser fingerprinting

#350
post #280

Earlier quoted context omitted.

https://medium.com/@colin.fraser/target-didnt-figure-out-a-t... https://www.predictiveanalyticsworld.com/machinelearningtime...

Even if that one particular instance is false, I seem to remember Target saying their model was too accurate and they were changing how they did things. i.e. Target admitted to predicting pregnancies very well. Why would they do that, if they didn't think their system was that good?

Maybe to convince other companies to buy Target ads. Advertising companies uptalk how effective their advertisements are to persuade other companies to buy adspace.

Target isn’t going to do something that scares away consumers, like say “our ad tracking is TOO good”, unless there’s another benefit that makes it net positive for them.

Post reply on HN