7 ms·
Just wondering - would it be possible to send a header back to webservers forbidding them to fingerprint my browser? Would that have any chance legally?
by arviewer 10y ago
Just wondering - would it be possible to send a header back to webservers forbidding them to fingerprint my browser? Would that have any chance legally?
- enthdegree 10y agoIf I understand it correctly, the way this fingerprinting works is just by using questions you need to show the website properly. 'What is your screen resolution? What HTML5 features do you support? Do you have this font/plugin?' Bar giving up all those facilities, the best you can do is ask and hope they comply....
- mpeg 10y agoThere's browser extensions that will fake all of those to a standard value. The tricky part is that with fingerprinting, depending on your chosen faked value you could end up being more identifiable, if not enough people use it. For instance, you can change your user agent and headers to some generic Windows Chrome one but a savvy tracker will fingerprint your TCP connection and realise you are actually on a Mac, and that can be used as a further source of entropy to better identify you. I've spent more time than is healthy looking into ways to uniquely identify devices on the internet. While the company I was working for was always on the safe side in terms of privacy, the more blackhat methods can be useful in collaborating with law enforcement to deanonimise Tor users (think pedophiles, not drugs) Tor Browser devs have in turn been really good at hardening fingerprinting attack vectors related to it (and rightly so, browsers don't rape people — people rape people) but unless you're super paranoid it's not a great experience for the average user. I think a better solution will come (at least in the EU) from the proposal to extend cookie law to any kind of fingerprinting (regardless of storage), which takes use case in account and can be enforced through big fines.
- pavel_lishin 10y ago> There's browser extensions that will fake all of those to a standard value. The tricky part is that with fingerprinting, depending on your chosen faked value you could end up being more identifiable, if not enough people use it. Couldn't this be worked around by reporting random values every time?
- mpeg 10y agoKinda, but then the random values just become a flag for "has x browser extension installed" and the trackers will still use the things you can't change, like the OS networking stack, GPU, audio, etc. to track you. It's very hard to get away completely... even with Tor, if you are the only person who uses Tor to visit a certain site you are as trackable as anyone else for that site.
- jessaustin 10y ago...collaborating with law enforcement to deanonimise Tor users (think pedophiles, not drugs) It would be interesting to see some reports on that question. Of course, the Law would never abide such accountability, but one can dream...
- mpeg 10y agoWell, in my experience it was done in a case-by-case basis and led through the great work of NGO "Thorn" (the one founded by Ashton Kutchen & Demi Moore) I don't know about accountability, but we provided support in a proactive way and never more than we were comfortable with (no carte blanche access to data for LEOs, etc.)
- jessaustin 10y agoMy mistake; that certainly seems legitimate.
- onion2k 10y agoThe companies who would comply with a header are not the companies you need to worry about abusing browser fingerprinting.
- oneplane 10y agoNo, that doesn't work. 1. If this were purely based on a 'may I do this' concept, the server would simply ignore you. 2., it's actually 99% client-based, it's using questions that you can't really deny since it makes rendering any webpage useless. Unless you like empty screens as websites, it will be possible to fingerprint you.
- jessaustin 10y agoSince these questions are primarily used on the client side, better clients simply wouldn't forward the answers to the server.
- oneplane 10y agoAnd then the server wouldn't know what the specs of your browser are and either send you useless pages or not send you anything at all. The browser is designed to let the server and client side scripting languages know what it is and what it's capable off. There is simply no scenario where you can have a usable internet without sending any parameters on what you want to the party owning the website. It's like trying to use the internet without using TCP/IP...
- mpeg 10y agoIn the EU there's a proposal to extend the law around consent for storage (AKA the cookie consent law) to fingerprinting, whether or not it accesses device storage. The law even has exemptions for security-related applications — your bank already fingerprints your device and uses it as a first line of protection against card theft.
- throwawayReply 10y agoI look forward to "We fingerprint you for totally legit reasons. Click OK to hide this message. By continuing to use this site you consent to this." on every page.