9 ms·
Tor NoScript visit tracker
- hackuser 11y ago> NoScript Tracker is a basic tracker that makes use of iframes and the Refresh HTTP header to measure how long users spend on web pages. > It is ideal for getting basic usage statistics on the Tor network, where JavaScript is not an option for most users. NoScript can block iframes; will that disable this tracker? Also, does the Tor Browser, which includes NoScript, default to blocking iframes?
- MajesticHobo 11y ago> Also, does the Tor Browser, which includes NoScript, default to blocking iframes? No. Tor Browser defaults to the lowest security level, allowing all scripts, media, iframes, etc.
- alphapapa 11y agoNoScript->Options->Embeddings->Additional restrictions for untrusted sites->Forbid <IFRAME> Just turned that option on, myself. I might have had it on years ago--can't remember for sure--but now that I know it's being abused, I'll definitely leave it on. IFRAMEs are generally poor practice, anyway.
- deleted 11y ago[deleted]
- jakobdabo 11y agoAlso, pay attention to these settings in about:config page: accessibility.blockautorefresh noscript.forbidBGRefresh noscript.forbidMetaRefresh Additionally, you can cherry-pick options (or just use it all) from this repository at https://github.com/pyllyukko/user.js https://github.com/pyllyukko/user.js for more privacy.
- alphapapa 11y agoThanks! I'll look into those.
- jakobegger 11y agoWhat else, besides using Tor, and turning off Javascript, does a user have to do that a website operator finally gets they don't want to be tracked?
- ironsides 11y agostop using repeat offending website
- hackuser 11y agoVery few users can detect that they are being tracked, so they can't avoid it. The tracking methods are designed to be undetectable; web beacons are invisible pixels; sites don't tell users: we track this info and share it with these people; even privacy policies usually are ambiguous, and they are too long and complex to read for every site someone visits.
- foobiekr 11y agobecause sites can be hacked or changed at any time, the ability of users to avoid offenders is basically zero.
- korm 11y agoBut this can't track individual users, it just provides general usage statistics, like visitor retention. I'd be interested in a viable example of this being used to identify users.
- Leon 11y agoThat can help with fingerprinting. Any entropy escaping from a users session is useful.
- korm 11y agoThis can be used to make a user's fingerprint stand out based on their browsing patterns. However, it is very fragile in practice. The tracker would need both a rare fingerprint, as well as a rare browsing pattern in order to identify a user. This is pretty hard, considering the Tor Browser does a good job at having a common fingerprint at it's highest security setting (Javascript disabled, which is what this tracker is for).
- somebody1 11y agoWhy wouldn't you open a web socket
- korm 11y agoBecause you can't use WebSockets in the browser without Javascript.
- buro9 11y agoBefore Microsoft gave us the XMLHttpRequest, and before IFRAMEs were everywhere, this is exactly how, and with FRAMESETs and target="" one could track session length, reload other parts of a page after some given time, allow forms to interact with complex flows and various other things. The "virtually invisible frame loading in the background" trick is going to be around for a long-term and seems destined to be re-learned many times over.
- achairapart 11y agoI will not be surprised at all if something like this will be soon used to circumvent adblockers replacing classic javascript based analytics on the "bright" side of the web.
- kaugesaar 11y agoAdBlockers will still block iframes and already does. Those I've seen blocks the full request based on a list of known domains. Many 3rd-party tracking cookies is often placed with help of iframes or a img-pixel. With Google Analytics you have the option to actually do all the tracking server-side so AdBlockers shouldn't be an issue tracking-wise.