Live data from Hacker News

Firefox expands fingerprint protections

blog.mozilla.org

71–80 of 177 posts

Re: Firefox expands fingerprint protections

#71
post #57

Unfortunately, Cloudflare and other protections will keep working even less than they used to. I have started to not use Cloudflare protected websites because they don’t work with Firefox. But that is a fight I am going to lose.

Symptoms? Is it limited to when a site has Cloudflare's more aggressive protection turned on? I haven't noticed any problems I've attributed to Cloudflare, and I use Firefox exclusively.

Re: Firefox expands fingerprint protections

#72
post #67
post #7

Earlier quoted context omitted.

You are actually easier to track using these addons. By installing Canvasblocker, Decentraleyes and NoScript you are providing more entropy to trackers and thus making it easier to track you. Imagine how many people worldwide block specifically Canvas, have weird looking network requests to certain js libs and have JS disabled for some (/all) scripts combined with your general setup (window size, font size, and many…

I more or less use those addons (uMatrix instead of NoScript) plus uBlock Origin. uMatrix doesn't load a large number of JS files. An example from an ecommerce site I'm browsing right now: the site is functional (at least in browsing mode) without the scripts from bigcommerce.com classyschema.org doofinder.com elfsightcdn.com google.com grit.software gstatic.com hexgator.com klarna.com skeepers.io criteo.com googleta…

I don’t really mind first party telemetry. I’m already interacting with the sites, so they can build a nice profile if they want too. But my pet peeves are loads of non functional JS and not having an html render for web content for a non app website.

Re: Firefox expands fingerprint protections

#73
post #11

This is a good use of Firefox resources. Unfortunately Firefox is at a natural disadvantage for fingerprinting by virtue of being used by such a small number of users.

There was a commenter some time back showing that browser statistics were easy to skew. Safari and Firefox are less likely to show up in analytics, so website owners think they're less important than they really are. Conflating client-side with server-side analytics showed quite a gap.

Re: Firefox expands fingerprint protections

#74
post #2

I'm already using CanvasBlocker, Decentraleyes, and the NoScript Security Suite; but getting more protections will be nice. Even if it may take a while for them to land in Waterfox.

How is your browsing experience with that stuff? I used to go nuts with anti-tracking measures, but enough of my browsing experience kept breaking that it just didn't feel worth it.

My experience with uMatrix: most sites work right away. Others require fiddling with the matrix of media, script, xhr, frames and the third parties serving them. After a while it's easy to remember which ones must be temporary enabled and which ones don't. Sites with videos are a little more difficult. Sites with payments require care. I whitelist the minimum set of scripts that make the sites I use often work. There are usually many scripts that can be left out. If everything fails and it's a one shot site, I start Chrome.

Re: Firefox expands fingerprint protections

#75

One thing I found that broke tracking algorithms was the ‘every tab is a new random profile’ extension. I can’t remember the name as I haven’t used it in a while and it broke a lot of logins. They could not build a profile on you and it would break their system of tracking user login per device.

https://github.com/stoically/temporary-containers/wiki/Autom...

Re: Firefox expands fingerprint protections

#76
post #9

Earlier quoted context omitted.

How is your browsing experience with that stuff? I used to go nuts with anti-tracking measures, but enough of my browsing experience kept breaking that it just didn't feel worth it.

It's fine. Sometimes I get annoyed by websites which require JavaScript to show static text (apparently HTML is too difficult?) or which block me with a 'please unblock challenges.cloudflare.com to proceed' (that second one seriously pisses me off when I see it on, for example, the website of the Belgian railways), but by and large I'm fine with just saying 'if it breaks I don't need it'. But I handle my e-mail with…

Libraries documentation that requires javascript to load is the lowest of the bunch in my opinion.

Re: Firefox expands fingerprint protections

#77
post #61

Earlier quoted context omitted.

I don't think there's anything in GDPR or similar laws about disallowing paying for a subscription with money. It's merely about killing the practice of paying with your privacy for something otherwise labeled as "free".

The quote I gave was the context, not GDPR.

"not gating information behind said sign-ups" was in the context of regulations like GDPR. You twisted that into "People should do work for free" which is not at all the meaning of what you replied to.

Re: Firefox expands fingerprint protections

#78
The question that I have not see answered in the many, many forum threads on "browser fingerprinting", is specifically why a user seeks to avoid it

Is it (a) to avoid internet marketing, (b) some other reason or (c) both. What is the "threat model"

If the answer is (c) then is there a belief that a fingerprint collected for marketing purposes may be used for other purposes

I do not use a browser to make HTTP requests, I only send two headers, Host and Connection, unless I need to send more, e.g., User Agent, Cookie, Accept, etc. The vast majority of websites I access work with only two headers. The list of ones that require more is short and the local forward proxy adds them automatically for those sites

For me, the "threat model" is (a) internet marketing

I do not see any ads because (1) the computers I use cannot access ad or tracking servers^FN1 and (2) I use a text-only browser to read HTML. There is no Javascript interpreter, no way to auto-load resources, no way to display images, no way to store cookies, etc.

I have no issue with this information that I'm a text-only web user being revealed to any internet marketer. (More likely I am mistaken for a "bot" as a result of crude heuristics)

On the other hand, if I were using a popular browser to make HTTP requests, one that sends a "common" fingerprint to internet marketers, then this would signal a more viable target for ads and tracking. Popular browsers have default settings that enable Javascript, cookies, images, auto-loading resources, etc.

tl;dr The reasons a computer user has for avoiding fingerprinting may be different. For example, one user might want to "blend in" and "hide", i.e., avoid being "identified", whereas another user might want to "be left alone", i.e., avoid being the target of internet marketers

FN1. Markerters always seem to require access to DNS

Re: Firefox expands fingerprint protections

#79

I exclusively use private browsing, but I know that doesn't do much in preventing tracking, so it's nice to see this finally starting to roll out. The fact that I have to go to great lengths to browse anonymously - and companies desperately try to circumvent my genuine decision to opt out of their tracking - tells me everything I need to know about those companies. Words like sleezy, shady, and predatory come to mind…

Tor? Although I wish there was a way to make a reddit account.

Re: Firefox expands fingerprint protections

#80
post #7

Earlier quoted context omitted.

You are actually easier to track using these addons. By installing Canvasblocker, Decentraleyes and NoScript you are providing more entropy to trackers and thus making it easier to track you. Imagine how many people worldwide block specifically Canvas, have weird looking network requests to certain js libs and have JS disabled for some (/all) scripts combined with your general setup (window size, font size, and many…

There has to be a happy middle between "no protection" and "complete uniqueness" The web without ad blocking is revolting. Browsers building in these features makes them more popular. Aside: Fuck the Washington Post. They have a line in their privacy policy that acknowledges the existence of "Do Not Track" flags in browsers. Their acknowledgement: since there is no industry standard for responding to it, they ignore…

wow lmao

> Do Not Track. Some web browsers may transmit a “do-not-track” signal. Because there currently is no industry standard concerning how to treat such signals, the Services currently do not take action in response to do not track signals. We respond to legally recognized browser-based opt out signals such as the Global Privacy Control signal for California residents.

https://www.washingtonpost.com/privacy-policy/

Post reply on HN