Web fingerprinting is worse than I thought
491–500 of 524 posts
Re: Web fingerprinting is worse than I thought
#492Earlier quoted context omitted.
I often see the narrative on here that consumer VPN providers are almost useless for privacy due to other fingerprinting methods, which I've never really bought.
I just tested at fingerprint.com using mullvad. Brave browser, no VPN, they recorded one visit, one IP. Brave browser, no VPN, incognito, they recorded two visits, one IP. Brave browser, with VPN, incognito, recorded three visits, two IPs. I'm pretty impressed / surprised. A fresh incognito session, through a VPN, still matched the same fingerprint. Especially surprising since TFA indicates Brave randomizes the finge…
Based on this test I'm surprised Brave's fingerprint resister did not work for you. But on firefox the enhanced privacy protection (strict) and the resistfingerprinting option are two different knobs.
Re: Web fingerprinting is worse than I thought
#493Earlier quoted context omitted.
Even if this were the case - which I don’t actually believe, but… - it would be straightforward for that law to also constrain these purposes and prevent data sharing with non-worthy operations. At present it’s basically a free for all.
That is literally what GDPR is. Somehow it got reduced to cookie banners in HN psyche, but the whole idea of GDPR is to make sure that the data can be collected and used for well defined purposes that are either necessary to provide a service (preventing CC fraud would qualify), or are explicitly consented to.
Re: Web fingerprinting is worse than I thought
#494Earlier quoted context omitted.
I think we will end up with something like permissions grants (including granular JS APIs available for the website, as we do for the location, camera APIs etc, at the moment) per website and convenient tools built-in browser that allow you create/re-use patterns so you don't actually interrupted by this strictness too much.
> per website and convenient tools built-in browser Per-website, for dozens (if not hundreds) of APIs and convenient? These are contradictory :)
Re: Web fingerprinting is worse than I thought
#495Earlier quoted context omitted.
> It also was a time where companies were paranoid into letting employees access the internet, but at the same time had abysmal security In the early 2000s I was working at an insurance company. They used some kind of blocker in their outgoing firewall that prevented access to certain sites. At one point the blocklist included sourceforge, which threw my team's work a wrench because at the time a lot of the packages…
Company I work for still blocks SourceForge because... something bad happened 15 years ago (?).
Re: Web fingerprinting is worse than I thought
#496Re: Web fingerprinting is worse than I thought
#497Earlier quoted context omitted.
Because some browser-makers (Firefox at least) believe that the identity of those browsing the web should be protected. Legislators do not believe that. (At least, a majority of legislators do not.)
Would you consider the entire European Union a minority of the legislators? Because that's what GDPR is designed to do, make identifying customers well controlled and expensive whatever the method. Granted, the enforcement should be stepped up.
No, I was referring only to my own legislators (in the US, and not specifically California). Many other places in the world are doing better.
Re: Web fingerprinting is worse than I thought
#498Earlier quoted context omitted.
To me this seems extremely elitist. Non-technical people deserve to have their personal data stolen because they don't know about javascript for example?
Have you ever tried to talk to "non-technical" people about this subject? They treat you like you're one of those tinfoil hat crazies. At this point I'm 100% OK with us being the only ones able to protect ourselves. We warned them and they didn't care. Allow them to remain uncaring. We don't have to help everyone. People must want to be helped.
When people don't understand the implications or full ramifications then governments and lawmakers have to step in as they have a duty of care to protect citizens. It's one of the principal reasons for having government.
There are any number of examples, regulating the use of poisons, putting protection fences around cliff top lookouts, specifying the breaking strain of elevator cables, aircraft compliance design, removing lead from petroleum, and so on.
Unfortunately, governments have failed to act despite many warnings about these privacy matters.
Incidentally, there's an uncanny parallel between this example of governments failing to act even when in presence of the facts and my last example. In 1923 when Thomas Midgley and cohorts—engine makers and petroleum companies—sought permission to put tetraethyllead in fuel governments already knew the dangers of lead poisoning. Not only did they ignore all scientific warnings about the dangers of using the additive but also they embraced Big Business and approved the move at the citizenry's great expense.
Re: Web fingerprinting is worse than I thought
#499https://niespodd.github.io/webrtc-local-ip-leak/ still? leaks local IP in mobile safari. On browserleaks local ip check fails, giving false feeling of safety.
Re: Web fingerprinting is worse than I thought
#500Earlier quoted context omitted.
That is literally what GDPR is. Somehow it got reduced to cookie banners in HN psyche, but the whole idea of GDPR is to make sure that the data can be collected and used for well defined purposes that are either necessary to provide a service (preventing CC fraud would qualify), or are explicitly consented to.
The problem with the consent part is that you basically can’t take part in the modern world if you don’t. The theoretical possibility of opting out is undermined bu deliberately bad ux