The privacy nightmare of browser fingerprinting
kevinboone.me
The privacy nightmare of browser fingerprinting
1–10 of 456 posts
Re: The privacy nightmare of browser fingerprinting
#2Basically, we can identify browsers based on the supported ciphers in TLS handshake (order matters too AFAIK). Then when your declared identity is not matching the ja3 hash, you're automatically suspicious, if not blocked right away. I think that's the reason for so many Capchas.
Re: The privacy nightmare of browser fingerprinting
#3I am concerned about the detail here: does this mean per hardware class (e.g. same model of GPU), or per each individual device?
Is the implication that there are certain graphical operations that - perhaps unintentionally - end up becoming akin to a physically unclonable function in hardware?
Re: The privacy nightmare of browser fingerprinting
#4You missed one of our best guarded secrets: ja3 hashes and their successors. Basically, we can identify browsers based on the supported ciphers in TLS handshake (order matters too AFAIK). Then when your declared identity is not matching the ja3 hash, you're automatically suspicious, if not blocked right away. I think that's the reason for so many Capchas.
Re: The privacy nightmare of browser fingerprinting
#5You missed one of our best guarded secrets: ja3 hashes and their successors. Basically, we can identify browsers based on the supported ciphers in TLS handshake (order matters too AFAIK). Then when your declared identity is not matching the ja3 hash, you're automatically suspicious, if not blocked right away. I think that's the reason for so many Capchas.
What’s ja3?
It's a better explanation that I can provide.
Re: The privacy nightmare of browser fingerprinting
#6Re: The privacy nightmare of browser fingerprinting
#7Re: The privacy nightmare of browser fingerprinting
#8Re: The privacy nightmare of browser fingerprinting
#9You missed one of our best guarded secrets: ja3 hashes and their successors. Basically, we can identify browsers based on the supported ciphers in TLS handshake (order matters too AFAIK). Then when your declared identity is not matching the ja3 hash, you're automatically suspicious, if not blocked right away. I think that's the reason for so many Capchas.
Re: The privacy nightmare of browser fingerprinting
#10I agree with the points in the article. Fingerprinting of any kind is a major risk for personal freedom. At the same time I want to make sure that content creators are compensated for their work. Ad firms that employ fingerprinting stand between me and the content creator. That said, I'm not going to pay $5/month for every blog that I occasionally read. The ad based model provides a more streamlined approach to compe…
Sending emails costs $0.50.