Live data from Hacker News

Supercookie: Browser Fingerprinting via Favicon (2021)

github.com

71–80 of 105 posts

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#71

I use a browser that does not support favicon Wondering why users of popular browsers believe favicon is needed (I'm assuming users asked the authors of those browsers for favicon)

Popular browsers support tabs. When you have many tabs open, it's hard to show a meaningful title for each one. An icon takes up less place and is easier to scan for visually.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#72
Totally unrelated, but what I found interesting: the README hasn’t been touched for years, yet it looks entirely AI generated. Including the commits.

People actually wrote READMEs / commit messages like that before? Have I been living under a rock?

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#73

At some point we need actual consequences for sites that intentionally hide their tracking. It should be criminal. It is stalking and has real world consequences. Just because an exploit exists doesn't mean it should be used. That logic is like saying it is OK to break into a house because the lock on the door was weak. If we don't get real protections, at what point does it become justified to go offensive against s…

Isn't this covered by GDPR?

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#74

I use a browser that does not support favicon Wondering why users of popular browsers believe favicon is needed (I'm assuming users asked the authors of those browsers for favicon)

Do tabs in the popular graphical browsers display a number on each tab by default

This might be useful when switching from, e.g., tab#1 to tab#7, using keyboard shortcut Ctrl-7

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#76

At some point we need actual consequences for sites that intentionally hide their tracking. It should be criminal. It is stalking and has real world consequences. Just because an exploit exists doesn't mean it should be used. That logic is like saying it is OK to break into a house because the lock on the door was weak. If we don't get real protections, at what point does it become justified to go offensive against s…

Umm...But it is criminal. The GDPR, at least, doesn't care how you track users - whether through cookies, local storage, favicon or whatever other mechanism you've developed. If you track users you must follow certain rules, and if don't, you will be facing fines if/when you're caught.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#77

At some point we need actual consequences for sites that intentionally hide their tracking. It should be criminal. It is stalking and has real world consequences. Just because an exploit exists doesn't mean it should be used. That logic is like saying it is OK to break into a house because the lock on the door was weak. If we don't get real protections, at what point does it become justified to go offensive against s…

I am not concerned with bieng tracked, and assume that large entities on the net have the ability to track and find anything or anybody, ho hum, but my simple personal requirement is not to be then sold to petty merchants and harassed in my own home with adds and fake "personalisations", and offered unasked for "help", so I watch closely, and go to any length to disable adds, or "fingerprinting", "profiling", or whatever. The net is horrible, I need socks, but as I am now sensitised to bieng tracked and followed, I will just get socks at the hardware store, rather then try and track down what were mentioned as perfect travellers socks and other gear, because the mountain of equipment relentlessly devoted to selling me anything from the waist down herafter is impossible to contemplate, and I now only use search for items required for my business, but am often forced to give up, as the vast majority of the web has been co-opted by major retailers. Even though I have never been on social media, have no accounts with any of the retailers, people are telling me that they found me and my business through an LLM, of some flavor, and/or were convinced of my abilities from my "5 star ratings", I am too busy currently to unravel, exactly how the data is put together and then used, but quite clearly, there is no way to use the net(however "lightly"), and not be swollowed up and commodified.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#78

At some point we need actual consequences for sites that intentionally hide their tracking. It should be criminal. It is stalking and has real world consequences. Just because an exploit exists doesn't mean it should be used. That logic is like saying it is OK to break into a house because the lock on the door was weak. If we don't get real protections, at what point does it become justified to go offensive against s…

If you visit my eg. physical clothing store I'm allowed to monitor your in-shop behavior to better optimize my store for your needs. Same for a restaurant etc. That's how _you_ get _much improved services_ and I get _happier customers_. Ofc I'm not allowed to freaking resell that data. THIS is the problem in online: releseling and data-brokers. Just KILL these categories of businesses off completely and make _them_ c…

> As long as you're on _my (online) property_ and using _my services_ I can of course see EVERYTHING you f do

That's fine, but you are not allowed to send me malware, that runs on _my property_ and snoops on _my data_.

Also data doesn't stop being mine, just because you have it. You also can't take photographs of random people and claim this is yours now. That's an important difference between the USA and European countries.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#79
post #2

I was sure this has been a thing for a while, either that or safari has a UI bug since forever. I regularly get the wrong favicon in specific sites, for example ars technica favicon in reddit

My hacker news icon has been stuck as the icon for a weather site that I sometimes check. It’s been stuck that way for close to a year now, and has survived an iOS update too. It persists across profiles and into private browsing mode.

You guys have favicons? I don't have any in my tabs, but maybe I have turned that of at some point. I'm using Mozilla Firefox.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#80

Totally unrelated, but what I found interesting: the README hasn’t been touched for years, yet it looks entirely AI generated. Including the commits. People actually wrote READMEs / commit messages like that before? Have I been living under a rock?

Where do you think the AI training data comes from?

Emoji-heavy documentation/commit messages always seem very popular in JS projects, as this is seems to be the project of a 12 (Edit: It's 20, misread) year old I'm not too surprised that it's a bit unusual compared to others.

Post reply on HN