Live data from Hacker News

The privacy nightmare of browser fingerprinting

kevinboone.me

441–450 of 456 posts

Re: The privacy nightmare of browser fingerprinting

#441
post #290

Earlier quoted context omitted.

Translating pages is literally the only thing I use Chrome for. The built-in translation works way better than other browsers, even though they also use Google Translate.

Firefox does not use Google Translate and performs the translation locally, which works great for the most common languages out there. For the less common ones you still have to go to Google Translate, but IME it's definitely not worth changing the browser to Chrome over.

> works great for the most common languages out there

Most of the time when I tried it the Firefox translations were obviously wrong or nonsense.

Re: The privacy nightmare of browser fingerprinting

#442
post #289

It is not really fingerprinting but I realized that ipinfo can place my IP on my house. I guess some stupid phone sent the GPS location. Isn't that supposedly under GDPR in Europe? Can I delete it somehow?

I work for IPinfo. If you're on a residential connection, the geolocation of that IP address is likely to be accurate up to the ZIP code area. We have generalized hints of location information from over 70 different sources. Then we aggregate them and we map this information based on population density in the geographic region. Sure, our data is becoming more granular, but it's not granular enough to detect individua…

I have my own IP range and the data is accurate to the meter, which is what worries me.

Re: The privacy nightmare of browser fingerprinting

#443
post #442

Earlier quoted context omitted.

I work for IPinfo. If you're on a residential connection, the geolocation of that IP address is likely to be accurate up to the ZIP code area. We have generalized hints of location information from over 70 different sources. Then we aggregate them and we map this information based on population density in the geographic region. Sure, our data is becoming more granular, but it's not granular enough to detect individua…

I have my own IP range and the data is accurate to the meter, which is what worries me.

That is surprising. I am not sure what is going on. This type of accuracy can only work if you are operating like a literal data center. Even in that case, I think meter level accuracy will involve hosting one of our ProbeNet PoPs.

For example, we know where our ProbeNet PoPs are located. If hops to your ranges are through private IPs or sub 1 MS RTT, we can pretty much confidently tell the name of the data center. However, considering that there are data centers that span thousands of square meters, we can point to the data center building, rather than the rack or the room.

To me, it is likely a coincidence.

Re: The privacy nightmare of browser fingerprinting

#444
post #290

Earlier quoted context omitted.

PSA Don't use chrome.

Translating pages is literally the only thing I use Chrome for. The built-in translation works way better than other browsers, even though they also use Google Translate.

Safari does not use Google Translate and it works well. It even translates text on images BTW!

Re: The privacy nightmare of browser fingerprinting

#445
post #354
post #348

The OP argues that fingerprinting is a "privacy nightmare," but we need to look at why it exists. From a pragmatic perspective, we are forcing two very different networks to run on the same protocols: The Business Internet: Banking, SaaS, and VC-funded content (Meta/Google). The Fun Internet: Hobby blogs, Lego fan sites, and the "GeoCities" spirit. You cannot have a functioning "Business Internet" without identity ve…

I find it a bit hard to relate to the "privacy nightmare". I've not worried about such things in ~27 years of using the web and are yet to notice ill effects from the stuff he worries about. I don't know if my ads are targeted because I have an ad blocker and don't see any. Maybe the answer to the nightmares in general is not to worry about stuff that doesn't affect you? Re insurers knowing you've been browsing heart…

It’s less about targeted ads and more about how little right you have to your own information. Politically, you really should care that you have a right to your own data! Everyone generates so much data through their online activity, and privacy policies everyone agrees to allow your data to be collated, sold, and analyzed really without your knowledge or true consent. While it might not have a negative impact to you today, there are more and more compelling business incentives for companies to turn your data against you.

For example, did you know your car manufacturer sold information about their customers to data brokers? Which then combined that data with anything else they can buy and get their hands on to calculate a “risk score?” Which then gets sold to car insurance companies, which increases your insurance rate? https://youtu.be/X6UW4CFz71s

This kind of BS is why we all need to care and assert our right to privacy. Companies don’t have a right to your data, but aren’t forced to do informed consent, and somehow data brokers are legal. Why is my data being sold without my informed consent?

Re: The privacy nightmare of browser fingerprinting

#446
post #92

Earlier quoted context omitted.

How to scream I'm behaving badly online...

How to scream, “I’m living a life of unalloyed privilege.”

> "I’m living a life of unalloyed privilege"

How to scream I'm the worst of online discorse

Re: The privacy nightmare of browser fingerprinting

#447
post #106

Don’t confuse privacy with anonymity. One is a right in the US, the other is not.

The only way to have privacy in a semi public location, like the Internet, is anonymity. Ask any celebrity how much privacy they have. They can’t even buy Starbucks without people commenting on how fat their comfy clothes make them look. Because they have no anonymity.

But privacy in public in general isn’t a thing, right?

Re: The privacy nightmare of browser fingerprinting

#448

Earlier quoted context omitted.

Every time I manually touched the "fingerprinting" about:config settings, my entropy went up. I used the EFF site to test: https://coveryourtracks.eff.org/ AFAIK some of these options are there to be used by the Tor browser, which comes with strict configuration assumptions, and it doesn't translate well to normal Firefox usage. Especially if you change the window size on a non-standardized device. Mind you, the goal…

I've had good success with tracking tool tests and resistFingerprinting. Granted, I usually use it with uMatrix/NoScript most of the time which cuts down on the available data a lot and maybe makes it an unfair test. One issue, I expect, is simply not enough people using resist fingerprinting to add variation to the mix. Since it's off by default, and only a small % of users use Firefox and an even tinier percentage…

Oh, and a bit of followup. I tried the EFF cover your tracks on a Firefox profile with resist fingerprinting, and almost all the bits of identifying information came from the window size (which EFF considers "brittle") and the UA (I was testing in Firefox Nightly).

Apparently you need to add the hidden pref: firefox.resistFingerprinting.letterboxing

Enabling letterboxing knocked off 5 bits of identifying information. Apparently my 1800px wide letterbox was still pretty identifiable, but, an improvement.

Setting a chrome user agent string using a user agent string manager dropped that one from 12ish bits to <4 bits. 'course, that has disadvantage of reducing firefox visibility online further, and probably being more recognisable with the other values (like mozilla in the webgl info). Using firefox stable for windows was <5bits, so probably best to use that if on linux. Although, it might conflict with the font list unless a windows font list was pulled in.

Re: The privacy nightmare of browser fingerprinting

#449

Earlier quoted context omitted.

It also does (or at least used to) mess with dates, due to it attempting to hide what time zone you're in.

The browser should reasonably know what time zone you're in and what time zone you're reporting to the website and translate between them automatically.

Yeah, "should". Too bad it's unfeasible. As soon as you e.g. print the current date as part of a paragraph somewhere, the browser loses track of it, and the website can just read the element's content and parse it back.

Re: The privacy nightmare of browser fingerprinting

#450
post #263

Earlier quoted context omitted.

What language do you put that list in? Would you still want to show it to every visitor when you know most of them speak a particular language? I use to do some work in this area. The first question is difficult and the second is no. We had the best results when we used various methods to detect the preferred language and then put up a language selector with a welcome message in that language. After they made a selec…

You can determine user's language from IP address location. Of course, there are users with VPNs, but they probably are used to seeing foreign content. For example, Youtube shows me advertisement in a language I don't understand despite my language header saying I only understand "en-US" and "en" languages. So this header is unnecessary, even Youtube ignores it. Also, when using VPN, Google typically uses a language…

> You can determine user's language from IP address location.

There are reasons why it might not work (VPN is only one of them; there are others such as places with multiple languages, people traveling to foreign countries, and others), although it is also a bad idea for other reasons as well.

If the user specifies the language then you should use that one. I think it would probably be better to use the following order of figuring out which language you should want:

1. If the URL specifies the language to use, then use the language specified by the URL.

2. If the language is not specified by the URL, use the language specified by any cookies that are set for the purpose of selecting the language.

3. If the language is not specified by URL or cookies, but the user is logged in and the user account has a language setting, use the language specified by the user account. (If TLS client authentication is being used, then you might consider adding an extension into the client's X.509 certificate to select the language.)

4. If the language is not specified by URL or cookies or the user's account, or the user is not logged in, use the Accept-Language header.

5. If the language is not specified by URL or cookies or the user's account, or the user is not logged in, or the Accept-Language header is not present or cannot be parsed or does not specify any language that the request file is available in, then use the default, such as the language that it was originally written in.

Post reply on HN