9 ms·
EFF's Panopticlick 2.0 Launches with Tracker Protection Tests
- dest 11y agoIn fingerprinting, the browser plugins and user agent are the most identifying parameters as far as I'm concerned. Does anybody know workarounds to hide or standardize those parameters?
- blacksmith_tb 11y agoFor Firefox, you can automatically spoof the UA with a tool like https://addons.mozilla.org/en-US/firefox/addon/random-agent-spoofer/ https://addons.mozilla.org/en-US/firefox/addon/random-agent-...
- pde3 11y agoSpoofing your user agent on your own typically makes you easier to fingerprint, not harder. See footnote 3 of the Panopticlick 1.0 paper: https://panopticlick.eff.org/static/browser-uniqueness.pdf https://panopticlick.eff.org/static/browser-uniqueness.pdf It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.
- relkor 11y agoI used to spoof user agents, randomly mutating. Then last month I started to run into sites that refused to load/render for incorrect strings. It appears the Google and other large companies are now sending customized versions of their page based on the user agent which I can only speculate is an attempt to save bandwidth. By taking advantage of implementation specific features, they not only eliminate all of the extra JS and browser workarounds, but they also can take shortcuts.
- brokentone 11y agoI've been known to do something like this (rejecting unusual UAs) to avoid the added load of rogue scrapers.
- deleted 11y ago[deleted]
- rocky1138 11y agoHow about we get together and decide on a common string that all of us can use? We can set our browsers to use that, and our friends' as well. Theoretically, the more people that use the same string, the harder we'll be to track, correct?
- legind 11y agoThat's right, though it's a bit more difficult. Lots of sites use the User-Agent header to determine how to render a page, and may not render it at all if it's an unexpected value. Pages that allow you to install addons to your browsers also use this string to figure out if you're really running the target browser.
- schoen 11y agoTor Browser does that: https://www.torproject.org/projects/torbrowser/design/ https://www.torproject.org/projects/torbrowser/design/
- redwards510 11y agoYes! How would you say "I'm a generic modern browser that can interpret HTML5. Do not send me flash."
- r-w 11y agoJonDo has done exactly that: “Mozilla/5.0 (X11; Linux i686; rv:38.0) Gecko/20100101 Firefox/38.0”. It hasn’t changed things much, thanks to its relative obscurity and the network effect involved. You should try it out!
- Dylan16807 11y agoOkay, has someone made an extension that lets me pretend to have the most common set of plugins on the most common version of firefox?
- redwards510 11y agoYes, everyone knows you can change the user agent string, but how do you change the list of plugins returned by the browser? Do you have to actually patch the binary?!
- mpeg 11y agonavigator.__defineGetter__('plugins', function(){ return new Object(); }); Of course, you'd actually have to do a bit more work to make it bulletproof (otherwise fingerprinters could use the fact that you modified your default navigator object as a way to uniquely identify you !) I imagine ultimately it's almost impossible to defeat fingerprinters in JS, as they could do tricky stuff like timing attacks to get you. Use NoScript if you're concerned.
- throwaway252525 11y agoYou can set plugins.enumerable_names to the empty string, or to the plugins you want returned. Unfortunately, this was recently removed.[1] [1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1169945 https://bugzilla.mozilla.org/show_bug.cgi?id=1169945
- verusfossa 11y agoThis kind of works. Set a UA for all sites. https://addons.mozilla.org/en-US/firefox/addon/uacontrol/ https://addons.mozilla.org/en-US/firefox/addon/uacontrol/ https://addons.mozilla.org/en-us/firefox/addon/user-agent-js-fixer/ https://addons.mozilla.org/en-us/firefox/addon/user-agent-js... String... Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0 Update the string every now and then? https://techblog.willshouse.com/2012/01/03/most-common-user-agents/ https://techblog.willshouse.com/2012/01/03/most-common-user-... Disable all plugins. Best I got, sorry.
- relkor 11y agoIs there any solid guide to preventing browser fingerprinting? Or is the only protection constantly changing your accept headers + user agent?
- legind 11y ago"For day-to-day use, the best options are to run tools like Privacy Badger or Disconnect that will block some (but unfortunately not all) of the domains that try to perform fingerprinting, and/or to use a tool like NoScript for Firefox, which greatly reduces the amount of data available to fingerprinters." https://panopticlick.eff.org/about#defend-against https://panopticlick.eff.org/about#defend-against
- rocky1138 11y agoWill blocking them at the HOSTS file level decrease exposure as well? My gut says yes, but I wanted to check. Also, does this test check for that and/or give points for that? Here is the HOSTS file I use to block ads: http://winhelp2002.mvps.org/hosts.txt http://winhelp2002.mvps.org/hosts.txt
- XzetaU8 11y agoIf you're on Linux i recommend 'Hosts-Update'[1], it's a bash script that generates a Host file from multiple sources: http://adaway.org/hosts.txt http://adaway.org/hosts.txt http://hosts-file.net/ad_servers.txt http://hosts-file.net/ad_servers.txt http://malwaredomains.lehigh.edu/files/justdomains http://malwaredomains.lehigh.edu/files/justdomains http://pgl.yoyo.org/adservers http://pgl.yoyo.org/adservers http://someonewhocares.org/hosts/hosts http://someonewhocares.org/hosts/hosts http://winhelp2002.mvps.org/hosts.txt http://winhelp2002.mvps.org/hosts.txt http://www.malwaredomainlist.com/hostslist/hosts.txt http://www.malwaredomainlist.com/hostslist/hosts.txt [1]: https://github.com/zant95/hosts-update https://github.com/zant95/hosts-update
- legind 11y agoYes, our test does work for that and various hosts-based blockers are supported (like AdAway for Android, for example). In order for our test to give accurate results, the host-based blocker has to add our simulated trackers to its block list, which some lists may not have done yet.
- jordanlev 11y agoI browse with cookies disabled by default, and when I ran the browser test it said this: Are Cookies Enabled? No one in x browsers have this value 3.94 ...so according to the EFF's data, almost 1 in 4 people also browse with cookies disabled? I thought I was in an extreme minority, and I know I come across a TON of sites that don't work without cookies or localStorage enabled (which is understandable for when you need to log in or if it's a more "app"-y thing, but for just reading content it's a ridiculous requirement).
- schoen 11y agoIt's presumably 1 in 4 people who have tried Panopticlick, which isn't a representative sample of general browsers (for example, a lot of people might try it with Tor Browser or with private browsing mode).
- Dylan16807 11y agoThat was weird, the no-js version didn't work. It just sat there spinning. >Does your browser unblock 3rd parties that promise to honor Do Not Track? X no What, why would I unblock those? Edit: Thanks HN for deleting the fancy X unicode!
- legind 11y agoWith certain rare configurations (if you have a domain-based blacklist blocker and javascript disabled) this may occur. I suggest turning your js back on just for the test.
- pde3 11y ago> That was weird, the no-js version didn't work. It just sat there spinning. What extensions do you have installed? There's a known and unfixable issue with browsers that both block JS and absolutely block all requests to tracking domains (eg AdAway, which modifies /etc/hosts). > What, why would I unblock those? To incentivise better behaviour by web publishers and advertisers!
- Dylan16807 11y agoublock was stopping requests to third parties. Though the javascript version didn't care that third party requests were blocked, only the no-js version. It's kind of weird for something specifically dedicated to measuring tracking to get so confused by an anti-tracking mechanism. > To incentivise better behaviour by web publishers and advertisers! Maybe if it could have some legal teeth to it, otherwise it's too easy to lie to get your tracker unblocked.
- dandelion_lover 11y ago>To incentivise better behaviour by web publishers and advertisers! I switched off "Do Not Track" in my options since only good-behaving websites listen to it, such as those using Piwik analytics, which respects privacy. Therefore I only would harm good people with Do Not Track on.
- r-w 11y agoThe test over at http://ip-check.info http://ip-check.info, by JonDo, is more comprehensive at the expense of not using information theoretical measures like those of Panopticlick, which would give a realistic (if biased) view of browser fingerprint uniqueness. They’ve developed a Firefox setup profile called JonDoBrowser that’s optimized for their own test. While the HTTP headers JonDoBrowser sends to sites can be easily distinguished from those of other browsers (though they’ve attempted to standardize HTTP headers within their own ecosystem), their proxying service compensates for that by withholding all traceable details and eliminating all forms of local storage, thus providing better privacy. They’re located in Germany—a big legal plus—and their service uses an international chain of independent servers, but they charge for data rates greater than a few hundred kilobits per second. Thankfully, the browser profile also supports faster Tor proxying while maintaining the same degree of personal privacy. It also supports anything you can configure from your computer’s settings, but if that means something other than Tor or JonDo, it’s probably not redundant (i.e., comprising multiple independent proxy servers) and therefore less reliable. It can be downloaded from https://anonymous-proxy-servers.net/en/software.html; https://anonymous-proxy-servers.net/en/software.html; for those who wish to try it, I’ve found it works best with Firefox ESR, which can be downloaded from https://www.mozilla.org/en-US/firefox/organizations/all https://www.mozilla.org/en-US/firefox/organizations/all.
- UserRights 11y agoI really like their humor - the share buttons on the results page are a wonderful piece of satirical reality.