Live data from Hacker News

Web fingerprinting is worse than I thought

bitestring.com

461–470 of 524 posts

Re: Web fingerprinting is worse than I thought

#461
This author doesn’t seem to know what they’re talking about. Just because the service generated the same ID for their Chromium sessions doesn’t mean that applies to all users’ Chromium sessions. Chromium just exposes more of their machine. My guess is that they, writing a computer-technical blog post, have a particularly unique machine. Even having 16Gb of RAM separates you from the masses and might make you unique depending on graphics card etc..

The fingerprinting discussion is relatively new. The first research paper’s author is only 35 or so. (Its title is Cookie Monster.) The discussion is also a little amusing on a site like Hacker News. A perfect example of someone who’s easy to fingerprint is someone who built their own computer (likely to be found on HN). On the opposite end of the spectrum, Safari iPhone users with the same model are impossible to distinguish.

There’s a paper out there where the researchers worked with a public entity’s website to get more accurate fingerprinting data. There are very few unique fingerprints in reality and therefore no reason for any company to track them. This tech probably won’t ever identify users uniquely.

There are actually some positive aspects of fingerprinting. Tor leaves a very obvious fingerprint, and it’s easy for banks to detect its use by criminals.

Re: Web fingerprinting is worse than I thought

#462
post #92

Earlier quoted context omitted.

... on a new computer, each time ordered from a different brand and reseller, paid with a unique type of cryptocurrency and delivered each time to a new dead drop in a different country.

How does the fingerprinting know the payment method you used to pay for the computer, is that stored somewhere in the operating system? How would they know it was a dead drop also? Genuinely curious.

It's just a precaution for when they eventually breach your OS and dig out the machine's serial number from the BIOS. This will allow them to trace you to the reseller you used. But if you ordered to a dead drop in a random country and paid with a different cryptocurrency network each time THEY gain exactly zero information to profile you.

That, or the game against pervasive web tracking is lost.

Re: Web fingerprinting is worse than I thought

#463

Earlier quoted context omitted.

And how does that invalidate his technical expertise? More importantly, was he charged and convicted with anything? I am getting really tired of this public opinion tribunal, where mere accusation is enough to get a person out of their position. This is not how this is supposed to work at all.

No you don't get it. He was a "creep" aka should be cancelled wholesale on everything /s The only questionable thing he did was try to rationalise pedophilia, which he has since changed his mind about. Given that he's clearly _not all there in the head_ (i.e neurodiverse) and assuming he hasn't tried to access child pornography or similar I couldn't care less. All of the other accusations against him are nonsense[0]…

> Given that he's clearly _not all there in the head_ (i.e neurodiverse)

Neurodiverse people are "not all there in the head"?

gtfo.

Re: Web fingerprinting is worse than I thought

#465
Fingerprint.com gives me different IDs across different tabs, and also in private mode. I guess the privacy setup still works somewhat. The stack I use:

- Firefox, Enhanced Tracking Protection ON

- Multi-Account Containers + Temporary Containers addon

- Privacy Settings addon, most settings private, but referrers enabled

- uBO with lots enabled, Decentraleyes addon

Re: Web fingerprinting is worse than I thought

#466
post #107

Earlier quoted context omitted.

> I think browsers need a "web app" mode and a "surf mode" Agree. It will be hard to define a standard for "surf mode", but in addition to privacy benefits there would be security benefits for the browser container as well.

I don't think it would be that hard, start with "no javascript". Add a better compataiblity method. Ideally add ways to get the browser to do common stuff like resize images, although even saving that for "app mode" would be a big improvement on the current situation. Making the standard is easy, it is getting anyone to follow it that is difficult. Sites could already work great without javascript if they wanted to b…

"No javascript" is a non starter in my opinion. That's a very simple on/off switch that is already available but has very little buy in. As you noted, "JS off" mode requires a shift in what HTML/CSS are capable of on their own.

> Making the standard is easy, it is getting anyone to follow it that is difficult

That's my point, those two parts aren't disconnected. The standard isn't useful (or a standard really) until people follow it, and in this case that's most of the internet connected world. Both people building for the a new default subset, and users accepting a default subset with opt in "web app" bells and whistles.

Without removing JS, in my head it's along the lines of starting with a freeze of a current ECMA version, define the API's that are stripped out, force low fidelity timers, remove JIT, limit some cross origin options. Stop adding shiny new feature's every 8 weeks. Keep it there for 3-4 years. Or maybe a similar concept with a WASM container when it gains some browser usefulness. Then there's the html and css subset too. So, defining that stock subset navigator at the right level is what I see as the "hard" part.

Re: Web fingerprinting is worse than I thought

#467

Earlier quoted context omitted.

Have you ever tried to talk to "non-technical" people about this subject? They treat you like you're one of those tinfoil hat crazies. At this point I'm 100% OK with us being the only ones able to protect ourselves. We warned them and they didn't care. Allow them to remain uncaring. We don't have to help everyone. People must want to be helped.

What they want is things to be easy and require a low to non existent cognitive load. You start confusing them with details of what could happen etc and all the gyrations they have to do to avoid it, they tune out and look at you like a tinfoil hat crazy (are you sure they aren’t right?) As the techno elite, it’s actually our job to create the underlying reality everyone else participates in when using technology. So…

> are you sure they aren’t right?

Yes, I'm absolutely sure. Do I really need to justify myself here on HN of all places? On a thread about the fingerprinting implements of the surveillance capitalism industry?

> that doesn’t mean they’re sheep for slaughter

Welp. If they don't want to be slaughtered like sheep, they better start caring then. I'm done with that.

At this point what I really care about is strengthening my own privacy by having more users in the anonymity set. The more indistinguishable users there are, the more effectively we are protected. I figure that if they're apathetic enough to allow corporations to exploit them with absolute impunity, they're also apathetic enough to join the anonymity set. Browsers just need to make that choice for them. It needs to be the new default.

> we can’t expect people to turn off the cat video for long enough to listen to us

I can and I do. What we're saying about this matter is important. People should listen, join the discussion even. When we reach out to people about matters we consider important, we do it with the best of intentions. We expect they'll at least put some thought into it. If not that, we expect they'll at least treat us with some respect, not like some schizophrenic off his meds. Can't expect anyone to continue caring after multiple instances of that.

> What our challenge is is - how do we improve internet technologies sufficiently that everyone enjoys what we know is important but we don’t require them to care?

Someone's gonna need to have the balls to make the choice for them. I don't have the resources to just make a better browser though. I do what I can by installing uBlock Origin on every single browser I come across. Everyone loves it and tells me that the web "feels" much better, though they can't quite explain why.

Re: Web fingerprinting is worse than I thought

#468

As the years pass, I keep thinking back and realize that Richard Stallman was right all along: > For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time.

I think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built…

Wget can mask the User Agent and lots of variables.

Re: Web fingerprinting is worse than I thought

#469
post #186

Earlier quoted context omitted.

I actually did exactly that a while ago. Where I worked, we didn't have internet access but we had email access, so as a workaround, I made an email server on my home machine that fetched web pages for me. A coworker took it even further and made a proxy server that automated the process so you could actually browse the web, although very slowly. Just to say that Stallman is not the only one with this idea. It was in…

I recall one time in 2015 or 2016 when I had only a very weak 2G signal, but wanted to check a couple of pages (at least one of which was several hundred kilobytes). Connections always timed out in browsers, but I got it working by SSHing into my VPS, downloading the page with curl, then copying that down with scp. My recollection is that the file size would increase by 32KB every 15–30 seconds. Fun times!

Mosh works over 2.7 KBPS capped data plans. I connected to a tilde and just use lynx/links/edbrowse for light www/irc/jabber and gopher. It runs much faster than being connected natively to the inet. I can read everything and even answer in fora with Edbrowse.

Re: Web fingerprinting is worse than I thought

#470

Earlier quoted context omitted.

I will admit that it always made me confused as to why browser has access to detailed hardware information. I can understand OS. I can understand resolution. I can rationalize GPU. I don't understand though why it should be able to access .. well, everything about the machine. edit: It is still impressive. Even with the firefox settings on, the website was able to identify me. I am not entirely certain how I want to…

Because the browser has become a vendor neutral, architecture neutral app engine and people want to do things like play MIDI instruments, use serial ports, use proprietary USB check scanners for accounting/ERP apps that work on the web and don't need SCCM to manage, etc.

yeah, but it should ask you if you want to allow the website to know this kind of stuff instead of just allowing it by default
Post reply on HN