Earlier quoted context omitted.
> If your product or service is accessible to EU citizens, in the EU market, then you need to abide by the laws of the EU It's not that simple though. If I offer a website in the US, I can collect the info of anyone that visit it as long as I am not breaking US law. If the EU doesn't like that, then they can block my site. They claim though that I am subject to their law if I harness the data of Europeans.
Yes, this is what they claim. As long as your company has no physical offices in the EU you probably don't have to worry about it. If your company grows bigger, you probably should.
Web fingerprinting is worse than I thought
441–450 of 524 posts
Re: Web fingerprinting is worse than I thought
#442Look, forget about threat models. It's relatively trivial these days to avoid fingerprinting attacks if you want to (as a private, web browsing individual). I use fingerprinting actively in enterprise apps as a form of silent 3FA. It's a useful backstop. If I have a user who forgot their password but retrieves it via email, I'll usually let them pass if their fingerprint matches one of their priors; otherwise my soft…
You seem to have a conflict of interest here. How can you accept this for employee/employer but at the same time say it's not ok for a person to submit fingerprinting? Employees are also persons.
Re: Web fingerprinting is worse than I thought
#443Earlier quoted context omitted.
Stallman shot himself in the foot by having a text only blog that was easily searchable when it came time for the wolves to cancel him. A crappy proprietary blog or thousands of hours of ranting via Youtube videos ironically would have slowed down the haters and maybe even cause them to miss things with which to cancel him with. Its hilarious in an ironic way. Bonus points if the cancelers were running GNU software.…
You make it sound like he said something mildly insensentive. He was "cancelled" for making pro-cp comments, and for literal decades of being a creep. https://twitter.com/_sagesharp_/status/1173637138413318144
More importantly, was he charged and convicted with anything?
I am getting really tired of this public opinion tribunal, where mere accusation is enough to get a person out of their position. This is not how this is supposed to work at all.
Re: Web fingerprinting is worse than I thought
#444Until everyday people realize they’re being stalked, I don’t know what will change. I am seriously thinking about trying to go through the proposition process in my state to forbid selling of data (this should already run afoul of wiretapping laws, imho). I thought having an ad campaign that targeted subgroups very specifically and boldly might be enough drum up public interest. Something like: “Hello $name from $cit…
Re: Web fingerprinting is worse than I thought
#445Earlier quoted context omitted.
No ISPs don't need to do NAT but you can if you like. You also don't have to do NAT with IPv4 if you only have one device or get a subnet from your ISP. It's just done because we don't have enough v4 addresses. They can do subnet to customer correlation. The IPv6 is randomly generated by your device if you use SLAAC. But if your ISP is an adversary you have pretty much lost anyway. If they provide you with a router t…
I'm sorry, you've misconstrued the question. The context is the privacy extension to IPv6 under RFC 4941. So, my question was would ISPs need to do NAT in order to provide that extension -- I only skimmed the RFC but there was no other obvious way to me for it to be provided that wouldn't fall to an adversarial ISP because it appears they must do NAT to make that work? AIUI ISPs provide a fixed prefix to customers. S…
Yes they get a /32 by default (at least in RIPE) larger allocations need justification. But there are 2^32 /64 subnets in a /32 so every ISP gets a complete IPv4 internet of /64 they can assign to their customers at will. Your devices assigns itself a random IP address from that /64 network your ISP gave you via prefix delegation.
Re: Web fingerprinting is worse than I thought
#446Until everyday people realize they’re being stalked, I don’t know what will change. I am seriously thinking about trying to go through the proposition process in my state to forbid selling of data (this should already run afoul of wiretapping laws, imho). I thought having an ad campaign that targeted subgroups very specifically and boldly might be enough drum up public interest. Something like: “Hello $name from $cit…
FTFY: People already know; nothing will change.
Many of the things that are happening (at least in the US) are deeply, deeply unpopular, but are not changing, and show no signs that they are even susceptible to change. Fortune-sized companies, the 1%, and the deep state are calling the shots, despite how much can be seen in real time, through things like Twitter and TikTok. I've actually had to pull back from Twitter because of all the things that are obviously beyond the pale, yet will never change. (Snowden, Assange, et. al.)
Re: Web fingerprinting is worse than I thought
#447Fingerprinting is doing terrible things for big-tech data collection, and at the same time it's excruciatingly hard to protect against bots, spammers, fraudaters etc without it. Few people seem to try to reconcile this, since neither side cares about the other. I personally think that discussion about fingerprinting as raw tech, without mentioning the size of the company collecting the date or the purpose is meaningl…
Totally agree that this is perfectly within the government's purview, and they should be doing something about it. But, as with anything else in the US, until a Fortune 100, some few 1%-ers, or the deep state MIC wants it, we're not going to be getting it.
Re: Web fingerprinting is worse than I thought
#448Earlier quoted context omitted.
I think it absolutely does work. We need better regulation to temper capitalism.
That's very naive, and you need to educate yourself about what capitalism actually is because it certainly isn't what you are saying. You've misused that term.
We need limits to prevent capitalism from doing its worst.
It's only fair that we all live and work with the same limits.
This is the type of regulation that is necessary.
Re: Web fingerprinting is worse than I thought
#449Fingerprinting services tries to figure out browsing settings. Since very few people have this feature enabled. You might be easier to fingerprint by enabling it. A metric that historically been used for fingerprinting is the "do not track" feature which is a bit of irony.
Re: Web fingerprinting is worse than I thought
#450As the years pass, I keep thinking back and realize that Richard Stallman was right all along: > For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time.
"Mail for you, sir!"