Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

411–420 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#411

Earlier quoted context omitted.

Because that prevents all of your users from selecting the language they want. It's a terrible idea with no upside and not-high-but-still-not-no downside.

It doesn't, because that's an optional negotiation. Try Apple.com in a different country/locale than yours, you'll see how it behaves.

It has a remarkably inconspicuous language selector, also using the names of countries rather than languages, located in the page footer. Compared to Dyson, Apple's list of country names is much more willing to use English in preference to whatever someone from that country would call it. This isn't consistent; many countries are rendered in their own language (日本 / Ελλάδα) and many aren't (Georgia / Kazakhstan).

The page defaults to the locale that you request in the URL. https://www.apple.com/ shows up in English, regardless of your country;† https://www.apple.com/bg/ shows up in Bulgarian. Switching your preferred location simply takes you to the page for that location. (Dyson does the same thing.) Some locations support more than one language; there's https://www.apple.com/lae/ for Latin America (English) and https://www.apple.com/la/ for Latin America (Spanish). If you're on the page for a location like this, a language selector (with language names) displays next to the location selector. In the case of Latin America, only two languages are supported, and the language selector automatically displays "Español" if you're on the English site and "English" if you're on the Spanish site, which makes sense but won't generalize.

Apple's selector is inconspicuous because it refuses to display flags, which I would guess is due to much higher political exposure than Dyson. So it's lower-quality in two ways, but fundamentally the same approach. The user asks for a language, and the site honors that.

Given that I presented Dyson as an example of doing language selection correctly, I'm confused about what you wanted me to see on apple.com. They're trying to do the right thing, but less effectively.

† I tested this by accessing the site(s) from Mongolia, Vietnam, and Morocco using ExpressVPN.

Re: The privacy nightmare of browser fingerprinting

#412
post #303

Earlier quoted context omitted.

Randal had a long career of good takes, until around 2016 when they stopped being objectively good. I’m not kidding at all, that my guess is he was doing drugs and stopped.

> Randal had a long career of good takes, until around 2016 when they stopped being objectively good. Specifically it was at this point in 2016: https://xkcd.com/1756/ > I’m not kidding at all, that my guess is he was doing drugs and stopped. I don’t know if he stopped or started, but something changed.

Coming our against a candidate that literally said the words "grab them by the pussy" is a bad thing?

Re: The privacy nightmare of browser fingerprinting

#413
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

> You cannot have a functioning "Business Internet" without identity verification.

Yes, you can. Just like you can have a functioning grocery store without checking the identity of each shopper that walks through the door.

What you cannot have is a free and democratic society or an efficient free market without robust protections for individual privacy. Privacy is the best shield the less powerful have from being abused and exploited by the more powerful.

> We accepted the SLA for the "Business Internet" in exchange for free, billion-dollar tools.

No, we did not accept. There was no informed consent. The full consequences of our use of these services was and is still is kept hidden from us. Tracking happens invisibly, without our knowledge or consent. This deprives us of the opportunity to express our true preference and opt out and choose an alternative. It's employing deception in order to subvert the consumer's ability to make a rational choice that represents their best interests.

> on the modern web, anonymity looks exactly like a security threat

An anonymous user who just uses the service normally and does not attempt to access sensitive information without authorization does not look like a security threat.

Re: The privacy nightmare of browser fingerprinting

#414
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

Note that one very simple mitigation for browser fingerprinting is to simply run different browsers for "the business Internet" and "the fun Internet". You may need to do this anyway, because so many business sites only work on Chrome, with Javascript enabled, no VPN, no adblocker, and pop-ups enabled. But then you might use Chrome (which tracks everything you do anyway) for all your banking, SaaS, government tasks,…

I don't think separate browsers is a very effective mitigation. If both browsers are running on the same machine, from the same ip address, using the same email address for logins, the same phone number for 2FA, it will be pretty clear that both browsers represent the same person. Even cross-device identity tracking is a real thing.

Re: The privacy nightmare of browser fingerprinting

#415

I agree with the points in the article. Fingerprinting of any kind is a major risk for personal freedom. At the same time I want to make sure that content creators are compensated for their work. Ad firms that employ fingerprinting stand between me and the content creator. That said, I'm not going to pay $5/month for every blog that I occasionally read. The ad based model provides a more streamlined approach to compe…

> I'm not going to pay $5/month for every blog that I occasionally read

Why would you assume ads are worth $5 a month? Its more like paying 10cents to read the blog.

Re: The privacy nightmare of browser fingerprinting

#416

Earlier quoted context omitted.

It doesn't, because that's an optional negotiation. Try Apple.com in a different country/locale than yours, you'll see how it behaves.

It has a remarkably inconspicuous language selector, also using the names of countries rather than languages, located in the page footer. Compared to Dyson, Apple's list of country names is much more willing to use English in preference to whatever someone from that country would call it. This isn't consistent; many countries are rendered in their own language (日本 / Ελλάδα) and many aren't (Georgia / Kazakhstan). The…

That was my point. Not comparing Apple/Dyson/whatever, but showing that website do have this need.

If this was designed and implemented as a standard at the browser level, we would get something better in the end, rather than re-implementations on each and every website.

Re: The privacy nightmare of browser fingerprinting

#417

Earlier quoted context omitted.

The PPV model has been tried a bunch of times, and it always turns out that the rate people are willing to pay per view is not a rate that is high enough to be a viable revenue source for the content owners. it takes a lot of $0.10-$0.25 views to make up for the loss of a $5/month recurring revenue stream that might last for years.

I wrote about this exact problem last year. To anyone who disagrees, would you pay me 5 cents to click on the following link? https://sheep.horse/2024/11/on_micropayments.html

yeah 5cents is nothing and knowing it goes straight to the person who put the effort into writing is better than it going to an advertiser.

Re: The privacy nightmare of browser fingerprinting

#418

Earlier quoted context omitted.

Based on your comment it sounds like you rarely travel (booking hotel / flights online), don’t have mobility issues (ordering groceries / household essentials online), don’t participate in online banking (do you write checks? carry cash with you all the time? go to an ATM weekly?), you don’t stream movies or tv shows, and you enjoy looking for apartments to rent in your local newspaper listing, and you enjoy using pa…

>you rarely travel (booking hotel / flights online) Yes, and I really dislike traveling when I have to. I personally wish that air travel would become unaffordable for most people, including myself. >don’t have mobility issues (ordering groceries / household essentials online) No, but mobility issues existed before the modern internet. >don’t participate in online banking (do you write checks? carry cash with you all…

Your opinions are totally reasonable IMO, i just hope you realize how outside the norm they are. :)

Re: The privacy nightmare of browser fingerprinting

#419

Earlier quoted context omitted.

Randal had a long career of good takes, until around 2016 when they stopped being objectively good. I’m not kidding at all, that my guess is he was doing drugs and stopped.

1357 (2014-04-18) is pretty bad. (Bonus points for the alt-text argument being isomorphic to nothing-to-hide.)

He was effectively years early to the “if you don’t like how twitter is run, build your own ” interesting how that argument isn’t used anymore.

Re: The privacy nightmare of browser fingerprinting

#420
post #263

Earlier quoted context omitted.

What language do you put that list in? Would you still want to show it to every visitor when you know most of them speak a particular language? I use to do some work in this area. The first question is difficult and the second is no. We had the best results when we used various methods to detect the preferred language and then put up a language selector with a welcome message in that language. After they made a selec…

You can determine user's language from IP address location. Of course, there are users with VPNs, but they probably are used to seeing foreign content. For example, Youtube shows me advertisement in a language I don't understand despite my language header saying I only understand "en-US" and "en" languages. So this header is unnecessary, even Youtube ignores it. Also, when using VPN, Google typically uses a language…

> You can determine user's language from IP address location.

I live in Hyderabad, Telangana, India. I do not yet speak enough Telugu or Hindi or Urdu to be useful, and cannot read Hindi or Urdu at all; but I’m a foreigner who grew up on English only, rather rare around here, so let’s consider native Indians instead. Many can speak these languages but not read them in their native scripts, only romanised (in which case they can probably speak English tolerably). And many (many) come from other parts of India (or even Nepal) and can’t speak Telugu. Or are Muslim and at least prefer to deal in Hindi, often not having very good Telugu. And so on. It’s messy.

Some IP geolocation doesn’t even get the city right—I’ve seen Noida suggested, which is up north in Hindi territory.

Post reply on HN