Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

351–360 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#351
As someone who used to work on Chrome, I can confirm that browser fingerprinting is indeed a nightmare.

Back in the early days of Privacy Sandbox, before that crashed and burned against the UK CMA not even letting Google remove third-party cookie support [0], there was a lot of optimism about how we were going to completely solve cross-site tracking, even in the face of determined adversaries. This had several ingredients; the biggest ones I can remember are:

1. Remove third-party cookie support 2. Remove unpartitioned storage support 3. IP protection at scale 4. Solving fingerprinting

In the end, well... at least we got 2, which has some security benefits, even if Chrome gave up on 1, 3, and 4, and thus on privacy. Anyway, everyone could tell that 4 was going to be the hardest.

The closest I saw to an overarching plan was the "privacy budget" proposal [1], which would catalogue all the APIs that could be used for fingerprinting, and start breaking them (or hiding them behind a permission prompt, maybe?) if a site used too many of them in a row. I think most people were pretty skeptical of this, and the main person driving it moved off of Chrome in 2022. Mozilla has an analysis suggesting it's impractical at [2]. Some code seems to still exist! [3]

A key prerequisite of the privacy budget proposal was trying to remove passive fingerprinting surfaces in favor of active ones. That involved removing data that is sent to the server automatically, or freezing APIs like `navigator.userAgent` which are assumed infallible, and then trying to replace them with flows like client hints where the server needed to request data, or promise-based APIs which could more clearly fail or even generate a permissions prompt. This was quite an uphill battle, as web developers (both in ad tech and outside) would fight us every step of the way, because it made various APIs less convenient. Elsewhere people have cited one example, of reducing Accept-Language [4]. The other big one was the user agent client hints headers/API [5], which generated whole new genres of trolls on the W3C forums.

As Privacy Sandbox slumped more and more towards its current defeated state, people backed off from the original vision of a brilliant technical solution that worked even in the face of determined adversaries. Instead they retreated to stances like "if we just make it hard enough to fingerprint, it'll be obvious that fingerprinting scripts are doing something wrong, and we can block those scripts"; see e.g. [6]. Maybe that would have worked, I don't know, but it becomes much more of a cat-and-mouse game, e.g. needing to detect bundled or obfuscated scripts.

And now of course it's all over; the ad tech industry, backed by the UK CMA, has won and forced Google to keep third-party cookies forever, and with those in place, there's not really any point in funding the anti-fingerprinting work, so it's getting wound down [7]. The individual engineers and teams are probably still passionate about launching opt-in or Incognito-only privacy protections, but I doubt that align with product plans. I'm sure Google doesn't mind the end result all that much either, as having to migrate the world to privacy-preserving ad tech was going to be a big lift. Now all that eng power can instead focus on AI instead of privacy.

[0]: https://privacysandbox.com/news/privacy-sandbox-next-steps/

[1]: https://github.com/mikewest/privacy-budget

[2]: https://mozilla.github.io/ppa-docs/privacy-budget.pdf

[3]: https://chromium.googlesource.com/chromium/src/+/36dc3642bee...

[4]: https://github.com/explainers-by-googlers/reduce-accept-lang...

[5]: https://developer.mozilla.org/en-US/docs/Web/API/User-Agent_...

[6]: https://privacysandbox.google.com/protections/script-blockin...

[7]: https://privacysandbox.com/news/update-on-plans-for-privacy-...

Re: The privacy nightmare of browser fingerprinting

#352
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

This is an excellent insight.

I think there is still some hope that technical solutions could be developed so that only the "Business Internet" gets access to verified identity, with the user somehow understanding this, while the "Fun Internet" doesn't have such capabilities. This is what stood behind, e.g., Google's proposed WEI [1] that got such huge backlash, or Apple's Private Access Tokens [2] which are essentially the same thing but quietly slipped under the community radar.

Other proposals are Google's in-limbo Private State Tokens [3], or the various digital-wallet/age verification proposals (I think Apple and Google both have stuff in that space).

But even basic stuff, like IP protection, can really throw off the anti-fraud and anti-botnet mechanisms. Your Lego fan site wants to be behind a CDN for speed and protection from DDOS? Well, people using VPNs or in Incognito mode might end up inconvenienced, because the CDN thinks it's dealing with bots. Rough stuff.

[1]: https://en.wikipedia.org/wiki/Web_Environment_Integrity

[2]: https://developer.apple.com/news/?id=huqjyh7k

[3]: https://privacysandbox.google.com/protections/private-state-...

Re: The privacy nightmare of browser fingerprinting

#353

Earlier quoted context omitted.

> writing a blog post every once in a while will not provide meaningful income Nor, generally, should it. Sitting down one or two Saturday afternoons a month to write a blog post shouldn't be generating the income of a FTE.

Allow me a second to play Devil’s Advocate. What if it could? Or should (be able to produce FTE or close income)? In that world, the amount of pointless shite - questing to “go viral” - would be reduced to near zero. That is, if the incentive were more quality, and less quantity, we’d be better off, yes?

Anything that can provide income inevitably leads to a flood of garbage from people trying to game the system. The current ad-driven web resulted in SEO garbage and near-uselessness of search engines.

Re: The privacy nightmare of browser fingerprinting

#354
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

I find it a bit hard to relate to the "privacy nightmare". I've not worried about such things in ~27 years of using the web and are yet to notice ill effects from the stuff he worries about. I don't know if my ads are targeted because I have an ad blocker and don't see any. Maybe the answer to the nightmares in general is not to worry about stuff that doesn't affect you?

Re insurers knowing you've been browsing heart disease etc, I have sometimes had issues like that, more you get a cheap initial price from an insurer/airline/car hire and then they jack it up when you visit again. You can sometimes do better by having a go from a different browser. I regard that more as me trying a hack to get a discounted price than a privacy nightmare but whatever I guess.

Re: The privacy nightmare of browser fingerprinting

#355
post #303

Earlier quoted context omitted.

> Randal had a long career of good takes, until around 2016 when they stopped being objectively good. Specifically it was at this point in 2016: https://xkcd.com/1756/ > I’m not kidding at all, that my guess is he was doing drugs and stopped. I don’t know if he stopped or started, but something changed.

A person used their relatively large platform to tell people that they don't support a crazy lunatic millionaire running the world's most powerful country? How scandalous! In the USA, 2016 and onwards wasn't "just an election". It was something between a mildly harmful establishment candidate or a useless new face on one side, and "holy fucking shit are we actually letting this deranged wannabe monarch run for office…

Couldn’t have said it better. But hey, they made their bed…

Re: The privacy nightmare of browser fingerprinting

#356

Earlier quoted context omitted.

Has anyone wrote software that automatically surfaces the relevant XKCD comic for every article this happens under? I’d like a feature in my HN reader that sticks a red button at the bottom anytime XKCD has already made the points I’m reading.

Randal had a long career of good takes, until around 2016 when they stopped being objectively good. I’m not kidding at all, that my guess is he was doing drugs and stopped.

Wow. Not liking their political views equals doing drugs.

Must be an interesting place, that originates these "arguments".

Re: The privacy nightmare of browser fingerprinting

#357
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

I don't see why banks need browser fingerprinting at all. Every credit card I've had in the past 10 years required two-factor authentication. If your theory was correct, trying to do a purchase in a new browser wouldn't work.

Re: The privacy nightmare of browser fingerprinting

#358
post #139

Earlier quoted context omitted.

As someone who utilizes these tools for anti-fraud purposes, Firefox is just as trackable if not more trackable than Chrome (especially because you stand out by using a niche browser in the first place). Firefox exposes a massive amount of identifiable information via canvas, audio device and feature detection methods. There's also active methods to detect private windows, use of the developer console and more.

Of course. There's data where there isn't data. -make client load something -client doesn't load it -add.fingerprint.point(client,'doesnltloadthings',1) -detect if client does something only a certain browser does -client does it -add.fingerprint.point(client,'doesthisbrowsderthing',1) -window was resized/moved, send a websocket snitch to the backend - keep a consistent web socket open, or fetch a backend-api call fo…

In the end all this shit we have to deal with is probably 99% used for deciding which ads to show you, which we are gonna block anyway, and it's all a complete and utter waste of computing power and electricity. This is how big tech "makes the world a better place" apparently.

Re: The privacy nightmare of browser fingerprinting

#359

Earlier quoted context omitted.

That will just make you stand out more.

You can change the reported UA header independently of the UA you use.

You can change the header, but browser developers are not that dumb and they added properties like "navigator.platform" which do not change and immediately give you away. Consider also writing a browser extension to patch these properties. Also, I think that DRM module (widewine), that is bundled with browsers, also can report the actual software version. Sadly it is undocumented so I don't know what information it can provide, but I notice warnings from Firefox about attempts to use DRM on various sites like Yandex Market.

Re: The privacy nightmare of browser fingerprinting

#360
Visiting a store does not give it the right for someone to stalk you. I don't see any reasons why (apart from the obvious $) this sort of business is not considered illegal. It wouldn't solve all the problems but would drastically reduce the incentives.

I know one particular online car store that shares user data with insurance companies and they use that in their models to compute a "willingness" to pay more for insurance as well as of establishing the user profile. Let's say you look a sports car but you end up buying a family van, they charge you more for that.

The very interesting part is that they create a "customer profile score" they is just a number and sell that number to other companies. So, by pipping your habits they aggregate data and technically do not violate some local laws.8

Post reply on HN