Live data from Hacker News

Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

zdnet.com

91–100 of 216 posts

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#91
post #5

> The general idea is that "letterboxing" will mask the window's real dimensions by keeping the window width and height at multiples of 200px and 100px during the resize operation --generating the same window dimensions for all users-- and then adding a "gray space" at the top, bottom, left, or right of the current page. > The advertising code, which listens to window resize events, then reads the generic dimensions,…

Presumably the implementation is smarter than being defeated by this easy trick, but I too wonder how it works.

> Finally, an extra zoom was applied to the viewport in fullscreen and maximized modes to use as much of the screen as possible and minimize the size of the empty margins. In that case, the window had a "letterbox" (margins at top and bottom only) or "pillbox" (margins at left and right only) appearance. window.devicePixelRatio was always spoofed to 1.0 even when device pixels != CSS pixels.

So presumably the window size is not being reset to real size - firefox just does a smart zoomin. In other words the fake size remains throughout entire session.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#92

Earlier quoted context omitted.

I don't get it. Don't the majority of people browse at full screen, on common devices which all have the same fullscreen dimensions? Who out there browses to a size, resizes there window, then browses to another website, then resizes again and so on? That makes no sense.

I would actually really like an answer to this question, I’ve often thought about it!

Even if you had 100 users with 1024x768 resolution for their screen they can be fingerprinted further because of small differences in the browser. Zoom setting, toolbar size, bookmarks button showing, full screen mode, small icons, additional toolbars, task bar auto hide, larger than standard taskbar all affect the viewable area of the browser and this is what the site operator or analytics will see.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#93

Earlier quoted context omitted.

There is a way to stop fingerprinting. That way is serving pages via distributed network (over a WoT or torrent-like thing). All these other ways do is give people the illusion that they're safe from being tracked, when the reality is that they're tracked just the same, but by fewer people so the data is more valuable. This means that the money is centralizing around the actors with the most inexplicable methods of t…

> In the long run this will either be solved one way or another, and all these online surveillance capitalism companies will crash and burn. I sincerely hope that happens without causing more harm to people. It also seems to be a long way away.

https://en.wikipedia.org/wiki/Accelerationism

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#94
Maybe firefox should also install ublock origin by default?

This isn't just for some power users- it will increase their share among regular people whose pages will load even faster making Firefox popular.

Or are they waiting until the user share falls below 5%? Maybe they should listen to Andy grove and prepare now.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#95

Earlier quoted context omitted.

Or maybe it's to make it obvious that a tile has changed...

No, sorry but that's nonsense. reCAPTCHAv2 doesn't do the tile fade in unless your v3 score is low. The fade in I'm talking about can take one to five seconds per tile, plainly designed to annoy the user. Here is a video of the fade-in in action: https://youtu.be/zGW7TRtcDeQ?t=89 (Note that you do not need to be on a shared IP to experience this. Merely using firefox with resist fingerprinting and a adblocker is enou…

This happens to me all the time at home, I use Safari with uBlock Origin and reCaptcha never fails to decide to fuck with me.

I have a static IP address, and Google will happily give me a not-dick captcha if I use another browser without anti-tracking features enabled (even with a clean profile).

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#96
post #15
post #13

I recommend the privacy.resistFingerpriting about:config mentioned. It's been available for a while and does other things too, like changing your user agent.

I've been using privacy.resistFingerprinting for a while and also recommend it, but there is one major "side effect": your reCAPTCHA score will drop to 0.1 making many websites really tedious to use. It's a price I'm willing to pay though...

Just install Buster, it'll solve reCaptcha for you (just make sure to set a non-google STT engine)

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#99
post #20

Earlier quoted context omitted.

Havent they thought about not broadcasting the window size... wtf. We are doomed apparently.

Apps need it to determine where to place elements. If it wasn't you would still be able to reverse engineer it by sticking elements outside the viewport and seeing if they're hidden or not. Turns out anonymity is super freaking hard. :-/

> Apps need it to determine where to place elements

Annoying apps which control the layout in JS instead of letting the browser do it will need it.

Re: Firefox to add Tor Browser anti-fingerprinting technique called letterboxing

#100
post #69

Earlier quoted context omitted.

> guessing that it wouldn't be in Google's interests to add any feature that would thwart profiling users online I would actually think the opposite. Wouldn't it be better because then only Google would have that information? Only Google would be able to fingerprint. This is of course under the assumption (which is currently accurate) that Google has the majority share of browsers. But maybe it wouldn't be, because i…

I suspect that's the biggest reason Google was so interested in "https everywhere". That removed detailed browsing visibility from a lot of entities, but not Google.

Can you elaborate on that? Are you talking about the https everywhere extension from the EFF, because I wasn't aware Google had a part in that.
Post reply on HN