Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

391–400 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#391
post #315

Earlier quoted context omitted.

I suppose it depends on what you mean by "modern" In Europe we have the GDPR which does exactly this

The GPDR is not criminal law. But ignoring that, regulators barely pursue GPDR violations. Consider the swaths of dark patterns surrounding cookie terror banners. The GPDR language is extremely clear that none of them are legal, but virtually nobody is ever punished.

> The GPDR is not criminal law

While the GDPR does not directly prescribe prison sentences, it absolutely enables countries to establish criminal offences for severe data protection violations, and they will clearly extradite!

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs...

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs...

> But ignoring that,

No don't ignore that. When you're so completely wrong about the first thing you say, everything that follows is going to be even more wrong.

> Consider ... cookie ... banners. The GPDR language is extremely clear that none of them are legal

You are confusing the ePrivacy directive (2002/58/EC) with the GDPR (2016/679).

Re: The privacy nightmare of browser fingerprinting

#392

Earlier quoted context omitted.

privacy.resistFingerprinting has potentially-unwanted side-effects, like wiping out most of your browser history (instead of the more sensible approach of just disabling purple links). I also recall something about it getting removed or nerfed, though I'm not sure whether that was a mere proposal.

It also does (or at least used to) mess with dates, due to it attempting to hide what time zone you're in.

The browser should reasonably know what time zone you're in and what time zone you're reporting to the website and translate between them automatically.

Re: The privacy nightmare of browser fingerprinting

#393

Earlier quoted context omitted.

More and more international audiences websites literally do this themselves, putting a language (sometimes even currency) select box option on top when they detect your settings don’t match best at first the page you are on. Why not have this negotiation implemented at the browser level?

Because that prevents all of your users from selecting the language they want. It's a terrible idea with no upside and not-high-but-still-not-no downside.

It doesn't, because that's an optional negotiation. Try Apple.com in a different country/locale than yours, you'll see how it behaves.

Re: The privacy nightmare of browser fingerprinting

#394

Some time ago I noticed that in Chrome, every time you click "Never translate $language", $language quietly gets added to the Accept-Language header that Chrome sends to every website! My header ended up looking like a permuted version of this: en-US,en;q=0.9,zh-CN;q=0.8,de;q=0.7,ja;q=0.6 I never manually configured any of those extra languages in the browser settings. All I had done was tell Chrome not to translate…

Is Chrome trying to assume that, since you don’t want it to translate those pages/languages, that you can read them/want them in your header? Interesting

I'd read it more generously than that. I think Chrome trying to stop the server choosing the language for you. By sending an accepts-language header (which your browser does regardless of what you use; it's not a Chrome thing) the server should return the page in a language you've said you'll accept. By adding the language to what you've told Chrome not to translate, it's attempting to show you pages in languages you want.

I imagine Chrome is really adding the language to your browser preferences when you choose not to translate a page, and the HTTP client in the browser is generating request headers based on your preferred languages. A small (and largely unimportant) semantic point, but it's possible that the Google translate team weren't aware of how adding a preferred language might impact user privacy. That isn't to excuse the behaviour; they should have checked.

Re: The privacy nightmare of browser fingerprinting

#395
post #52

Firefox w/ the Arkenfox user.js is probably as good as it gets in terms of privacy. By default, this config burns cookies on exit, standardizes the time zone to UTC, spoofs the canvas fingerprint, and does other helpful things. Basically, it makes Firefox expose the same information as the Tor browser. In addition, I block most known advertizing/tracking domains at the DNS level (I run my own server, and use Hagezi's…

There's no point unless a critical mass of people use these tools. You will be the only one on your IP address using this configuration of masked fingerprinting, which is itself a fingerprint. That's also why it's indeed useful when using Tor, because you're not identified by your base IP. Unless we make this part of the culture, you have basically 0 recourse to browser fingerprinting except using Tor. Which can itse…

I have packed ff with arkenfox js into container and maybe a handful other people use it https://github.com/grzegorzk/ff_in_podman. Still, most likely the IP address alone is probably the strongest part of fingerprint vector Maybe instead it would be better to have very different vector each time?

Re: The privacy nightmare of browser fingerprinting

#396

When an individual stalks a person without their consent, it is considered unlawful. Why is it ok for websites to do this? Perhaps what is missing is a criminal law that forbids deliberate non-consensual tracking of a person's activity. Even in public. Recording someone as you happen to be recording something in public (including CCTV) is not deliberate or targeted towards an individual. But even in public, if someon…

A counter argument is that stalking in itself, in the US at least, is not unlawful. It becomes unlawful once someone starts threatening another person. So the digital analog would be to allow tracking as long as the site doing the tracking doesn't threaten the people that are being tracked.

You're talking about the law today, and I concede. Why don't we change it so it becomes lawful. No one wants to be stalked, and notwithstanding the exceptions I mentioned, no one should have to endure the harassment. There is no scenario where one person would legitimately have a right or a need to stalk another person (unless financial gain is a legitimate reason).

Re: The privacy nightmare of browser fingerprinting

#397
post #52

Firefox w/ the Arkenfox user.js is probably as good as it gets in terms of privacy. By default, this config burns cookies on exit, standardizes the time zone to UTC, spoofs the canvas fingerprint, and does other helpful things. Basically, it makes Firefox expose the same information as the Tor browser. In addition, I block most known advertizing/tracking domains at the DNS level (I run my own server, and use Hagezi's…

There's no point unless a critical mass of people use these tools. You will be the only one on your IP address using this configuration of masked fingerprinting, which is itself a fingerprint. That's also why it's indeed useful when using Tor, because you're not identified by your base IP. Unless we make this part of the culture, you have basically 0 recourse to browser fingerprinting except using Tor. Which can itse…

> "There's no point unless a critical mass of people use these tools"

That's what Mullvad Browser attempts to solve i guess:

https://mullvad.net/en/browser

Re: The privacy nightmare of browser fingerprinting

#398
post #290

Earlier quoted context omitted.

Translating pages is literally the only thing I use Chrome for. The built-in translation works way better than other browsers, even though they also use Google Translate.

Firefox does not use Google Translate and performs the translation locally, which works great for the most common languages out there. For the less common ones you still have to go to Google Translate, but IME it's definitely not worth changing the browser to Chrome over.

I don't really like firefox translate, despite having made the switch many years ago. For a long time it didnt have the (european) language of the country I live in. Now it does have it. Every time I want it to translate I have to manually find both languages in the insanely long dropdowns. It will not save it the way I want it, but impressively seems to manage to always save it in the other direction...

Re: The privacy nightmare of browser fingerprinting

#399

Earlier quoted context omitted.

Ditching Chrome is something we need to teach everyone. The DOJ is totally spineless and refuses to squash Google's absurd monopoly on the internet. We are literally the last line of defense, even though we really don't amount to much. Perhaps we could start a grassroots movement.

You don’t need a grassroots movement when other movements doing this exact thing already exist. In fact it is likely counterproductive. Mozilla Foundation is the organization you want to support, or EFF.

> Mozilla Foundation is the organization you want to support

Mozilla Foundation is rudderless. I'm convinced the leadership are all Google plants who are keeping the "antitrust litigation sponge" from doing anything damaging to Chrome.

Re: The privacy nightmare of browser fingerprinting

#400
I have a bit of a different take on browser fingerprinting: I don't want to uniquely identify you as a person so I can serve you ads, or whatever. I want to identify your traffic when you're scraping my content from 2,000 different IP's and 1,000 different user accounts, I can block you or rate limit you without hurting anyone else.

Given the scale of scrapers these days (AI companies with VC money have no problem spinning up thousands of VMs running Chrome), fingerprinting at the browser level is the only realistic option.

(obligatory: my personal opinion, not necessarily my employer's)

Post reply on HN