Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

371–380 of 524 posts

Re: Web fingerprinting is worse than I thought

#371
post #298

Earlier quoted context omitted.

This is confusing whether it can be blocked and whether it would be effective. Every time you do something unique, you of course become identifiable. But the idea is of course that you are not the only one blocking these scripts which will only make the entire group identifiable. You could for example try to block those scripts with a widely used ad blocker which would make you not stand out any more than any user of…

> This is confusing whether it can be blocked and whether it would be effective. It shouldn't be confusing because its really fairly simple. The gist is this... so long as determinism as a systems property holds true in a system, you can leak information by the absence of something when compared to another expected thing. This is how inference works in many respects, you have properties and you can deduce or infer fr…

I meant you are confusing whether such scripts can be blocked and whether it would be effective to do so. That it can not be blocked would require some fundamental or practical obstruction like having to solve the halting problem or whatnot. You said that it can not be blocked because the act of blocking itself makes you identifiable which defeats the purpose, but that is not true, or only true if only you or a few people are blocking the fingerprinting. When enough people block it, then the act of blocking does not make you identifiable or at least to a much smaller extend than not blocking the scripts.

In principle you could build a browser that - to a good approximation, you will, for example, realistically not be able to prevent timing leaks - does not leak any information about the system it is running on, just isolate it from the host system. With more effort you could let details about the host system leak into the browser but not out into the network. Well, some information has to flow from the host system into the browser and out over the network, for example key strokes and mouse movements, otherwise you could not do much with this browser.

So you could still try to fingerprint users by their choice of words, typing patterns and things like that, maybe made a bit harder by filtering out high frequency timing information. But at least one could no longer simply fingerprint the host system. Which would again be a trade-off, your screen resolution is not only good for a few bits of a fingerprint but can also be legitimately used to serve content at a proper resolution.

Re: Web fingerprinting is worse than I thought

#372
post #317

Earlier quoted context omitted.

> Even benign changes like CSS headline balancing was sent to TAG three weeks ago The "text-wrap: balance" proposal is not new, though? I see it in the 2019-11-13 draft spec: https://www.w3.org/TR/2019/WD-css-text-4-20191113/#valdef-te...

Perhaps, but it was sent for TAG review only three weeks ago, and already with an intent to ship in a month.

Isn’t that the point of the RFC approach to standardization? “Here’s what we think should be done, with the PoC being what we’re already doing ourselves in production; feel free to try our impl out, in order to better notice the design flaws in practice, so that we can talk out what changes could be made before it becomes a de-facto standard we’re all stuck with”? SPDY → HTTP2 was a great example of Google doing exactly this.

The opposite of the RFC approach is the “airy design document written by standards body in reference to nothing, never implemented by anyone” approach; and I know which of the two I prefer.

Re: Web fingerprinting is worse than I thought

#373
post #72

Earlier quoted context omitted.

3 sounds incredibly undesirable to me, assuming we’re dealing with a jpeg. Go through 3 or 4 rounds of that and compression starts to get pretty visible.

I've had to implement this - we have a web app used by engineers in the field where signal is often not great. We got lots of complaints about image uploads as for a typical job there would be potentially 100+ images that needed to be uploaded (multiple assets with 2 before and 2 after photos per asset). iPhone defaults to uploading a large image which can take ages to upload. We implemented a canvas based solution w…

I was under the impression that base64 encoding doesn't reduce file size of an image at all, rather it sometimes increases it. That wasn't the point of using base64 string, right?

Re: Web fingerprinting is worse than I thought

#374

Ha! I followed the instructions and went to fingerprint.com and it all 'crashed' because I had JavaScript turned off—that's my normal default setting. I have five different browsers on my smartphone and three on the PC all sans JS and none of them are Chrome. Also, normal operation is to automatically delete all cookies at session's end. My smartphone and PCs are de-googleized and firewalled and I never see ads in my…

To me this seems extremely elitist. Non-technical people deserve to have their personal data stolen because they don't know about javascript for example?

> Non-technical people deserve to have their personal data stolen

Nobody said that. "My defenses work" != "my defenses should be necessary".

Re: Web fingerprinting is worse than I thought

#375
post #82

Earlier quoted context omitted.

Because some browser-makers (Firefox at least) believe that the identity of those browsing the web should be protected. Legislators do not believe that. (At least, a majority of legislators do not.)

Would you consider the entire European Union a minority of the legislators? Because that's what GDPR is designed to do, make identifying customers well controlled and expensive whatever the method. Granted, the enforcement should be stepped up.

The EU has about 1/18th of the world's population, so certainly that would be a rather small minority.

Re: Web fingerprinting is worse than I thought

#377

I have a sort of love hate relationhip with this stuff. On the one hand, yes tracking me is bad if I am not aware, but on the other hand I work for a company that uses it's expert knowledge to help consumers purchase the right tools for them. Ideally we would like the end product to reward us for putting them in touch with the right customer that we've used our name to help land. Much like a hairdresser would recomme…

> until we drop the whole 'tracking is bad we should just shut it all down', and start to think of a fair and reasonable way for users to say 'I am ok with company B knowing that I have a relationship with company A' then these increasingly nerfarious tracking efforts will happen.

Given how companies have completely and utterly ignored the idea of consent banners, I am deeply disinclined to believe that most companies would ever actually be satisfied with a user controlled choice in the matter. Where we actually are is that companies will relentlessly attempt to stalk everyone all the time no matter what, and in face of that the only sane conclusion is that in practice tracking is bad and we should shut it all down.

Re: Web fingerprinting is worse than I thought

#378

Earlier quoted context omitted.

To me this seems extremely elitist. Non-technical people deserve to have their personal data stolen because they don't know about javascript for example?

> Non-technical people deserve to have their personal data stolen Nobody said that. "My defenses work" != "my defenses should be necessary".

"On the other hand if you insist on using JS, Gmail, Google search, Facebook etc. then you're fair game and you only have yourself to blame if your personal data is stolen."

Re: Web fingerprinting is worse than I thought

#379

Until everyday people realize they’re being stalked, I don’t know what will change. I am seriously thinking about trying to go through the proposition process in my state to forbid selling of data (this should already run afoul of wiretapping laws, imho). I thought having an ad campaign that targeted subgroups very specifically and boldly might be enough drum up public interest. Something like: “Hello $name from $cit…

I will admit that it always made me confused as to why browser has access to detailed hardware information. I can understand OS. I can understand resolution. I can rationalize GPU. I don't understand though why it should be able to access .. well, everything about the machine. edit: It is still impressive. Even with the firefox settings on, the website was able to identify me. I am not entirely certain how I want to…

I got me on iPhone through VPN change, clear cache, private window, and reboot.

I know what to think about this… I fucking hate it.

Re: Web fingerprinting is worse than I thought

#380
Oh, finally I found an element of distinguation for the Iphone:

The zoom settings in the display/brightness section of the iphone seem quite relevant for fingerprint.com algorithm.

Toggling between standard/bigger text toggles the fingerprint value.

This could be because the visible area in the screen size changes, as well as some value of the CSS-fingerprint.

Post reply on HN