Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

361–370 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#361
post #263

Earlier quoted context omitted.

> There was even a proposal to reduce this surface area, but it wasn't adopted: >> Instead of sending a full list of the users' preferred languages from browsers and letting sites figure out which language to use, we propose a language negotiation process in the browser, which means in addition to the Content-Language header, the site also needs to respond with a header indicating all languages it supports Who though…

What language do you put that list in? Would you still want to show it to every visitor when you know most of them speak a particular language? I use to do some work in this area. The first question is difficult and the second is no. We had the best results when we used various methods to detect the preferred language and then put up a language selector with a welcome message in that language. After they made a selec…

You can determine user's language from IP address location. Of course, there are users with VPNs, but they probably are used to seeing foreign content. For example, Youtube shows me advertisement in a language I don't understand despite my language header saying I only understand "en-US" and "en" languages. So this header is unnecessary, even Youtube ignores it.

Also, when using VPN, Google typically uses a language based on IP address, not my language header. I assume the header is only useful for fingerprinting today.

Re: The privacy nightmare of browser fingerprinting

#362
post #124

Earlier quoted context omitted.

> content creators are compensated for their work I have a gut feeling that we've been tricked (by ad companies) into thinking that this is somehow realistic and that casual "content creators" can get meaningful money from us reading their articles. Realistically, while professional content creators can make a living, writing a blog post every once in a while will not provide meaningful income. Instead of trying to "…

You mean I shouldn't make a comfortable living off my valuable HN comments? I was about to consider this comment a good days work. Maybe if I put this comment on my own webpage it would be more valuable?

About as valuable, as many content creators' work. But it all hinges on engagement, so consider this my part in helping you to the next million.

Re: The privacy nightmare of browser fingerprinting

#363
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

Then let's get rid of the business internet. Every single thing I dislike about the internet is from the business internet: tracking, cookies, fingerprinting, SPAs, excessive javascript, optimizing for engagement, data brokers, I could go on.

"But won't you miss XYZ?" Nope, don't care, want it gone. If you can't be bothered to go to the store and get it then it probably didn't matter very much.

Re: The privacy nightmare of browser fingerprinting

#364
post #89

Earlier quoted context omitted.

>The only efficient protection against fingerprinting is what Orion is doing — preventing any fingerprinter from running in the first place. Orion is the only browser on the market that comes with full first-party and third-party ad and tracking script blocking, built-in by default, making sure invasive fingerprinters never run on the page. sounds like they block "known" fingerprinting scripts and call it a day.

This is also covered in the article. I appreciated the analogy they used: You can put on a ski mask when you go to the mall, and it will conceal your identity, but you will also be instantly suspicious to everyone around you, and will likely be asked to leave most of the stores you try to visit.

This is only because there are only 0.001% of people using anonymizers. If you are a minority with specific requirements, you are shown the door almost in any case, not only on the Internet.

Re: The privacy nightmare of browser fingerprinting

#365
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

No. Fingerprinting is a function of the ad network to identify ad-worth aspects of me.

That some aspects may be used to push bots away is a minor effect.

Re: The privacy nightmare of browser fingerprinting

#366

Earlier quoted context omitted.

Firefox does pretty damn well though, especially with privacy.resistFingerprinting set to true

privacy.resistFingerprinting has potentially-unwanted side-effects, like wiping out most of your browser history (instead of the more sensible approach of just disabling purple links). I also recall something about it getting removed or nerfed, though I'm not sure whether that was a mere proposal.

It also does (or at least used to) mess with dates, due to it attempting to hide what time zone you're in.

Re: The privacy nightmare of browser fingerprinting

#367
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

Then let's get rid of the business internet. Every single thing I dislike about the internet is from the business internet: tracking, cookies, fingerprinting, SPAs, excessive javascript, optimizing for engagement, data brokers, I could go on. "But won't you miss XYZ?" Nope, don't care, want it gone. If you can't be bothered to go to the store and get it then it probably didn't matter very much.

To me, it would be enough if there existed a search engine which only lists sites which do nothing of the above. But that would require that sites are honestly answering the question "are you tracking?". They won't. Corps have the same thinking as the criminals they try to keep outside.

There would have to be laws which require site owners to answer that question honestly, so that users have a choice and such a search engine can be built. But states are interested in fingerprinting too, so I guess such will never happen.

Re: The privacy nightmare of browser fingerprinting

#368
post #315

Earlier quoted context omitted.

If I infiltrate someone else’s computer, secretly run code in order to to exfiltrate data I risk prison time because objectively it seems to satisfy criminal laws over where I live. How do prosecutors in any modern country/state not charge this behavior when done by a website owner?

I suppose it depends on what you mean by "modern" In Europe we have the GDPR which does exactly this

The GPDR is not criminal law. But ignoring that, regulators barely pursue GPDR violations.

Consider the swaths of dark patterns surrounding cookie terror banners. The GPDR language is extremely clear that none of them are legal, but virtually nobody is ever punished.

Re: The privacy nightmare of browser fingerprinting

#369

Earlier quoted context omitted.

Definitely a good STEP1, but it’s not like Firefox and Safari are finger printing secure.

what about duck duck go? We need a simple chart: 1. What browsers are good at resisting finger printing 2. tell for each browser, does it work on android ad ios and apple and windows and linux 3. what setting are needed to achieve this for bonus points, is there no way to strip all headers on chrome on control it better?

This is my question also. I tend to not use apps, use DuckDuckGo browser.

I sometimes do use Safari which is a more convenient browser - it would be ironic if DDG browser is less private than Safari.

Re: The privacy nightmare of browser fingerprinting

#370
post #133

Earlier quoted context omitted.

Steam also does this. Most games are significantly cheaper in low-income countries like mine because otherwise they wouldn't make a dime here.

Steam is not the one doing that. Publishers decide regional pricing.

If Steam only had one input field for the price tag, then the publishers would only decide one price.
Post reply on HN