21 ms·
Apple adds a tracker blocker to desktop Safari
- vim_wannabe 9y ago>“It’s not about blocking ads, the web behaves as it always did, but your privacy is protected,” he added. Does this mean browser fingerprint is somehow scrambled before it is sent to the tracker instead of blocking?
- ceejayoz 9y ago> Does this mean browser fingerprint is somehow scrambled before it is sent to the tracker instead of blocking? It might be homogenized instead of scrambled. Every iOS device could be given (barring IP etc.) the same fingerprint.
- pmiller2 9y agoI don't think that's even theoretically possible. How do you block JS font enumeration without crippling the browser font API?
- ceejayoz 9y agoBrowsers already treat first-party cookies differently than third-party ones. Report a homogenized fingerprint to Google Analytics, but a real one to the main site.
- tinus_hn 9y agoOffer the same basic set to every site. Why does a website need to know the fonts you've installed?
- gsnedders 9y agoYou can't block font enumeration without crippling the entire CSSOM. But that doesn't affect iOS, because you can't install fonts on iOS.
- dsp1234 9y agoyou can't install fonts on iOS. Custom fonts can be installed via custom configuration profiles[0], which is what some font applications do[1] I'm not sure if this is exposed via Safari or not, so it could still be a moot point. [0] - https://developer.apple.com/library/content/featuredarticles/iPhoneConfigurationProfileRef/Introduction/Introduction.html#//apple_ref/doc/uid/TP40010206-CH1-SW43 https://developer.apple.com/library/content/featuredarticles... [1] - https://itunes.apple.com/us/app/anyfont/id821560738 https://itunes.apple.com/us/app/anyfont/id821560738
- derefr 9y agoSimple way would be tainting any JS/DOM data that interacts with the font metrics API (or one of a number of other similar APIs) and then not allowing tainted data to be used as parameters in network requests.
- gsnedders 9y agoYou don't even need the font metrics API. Draw a span containing the character "m", measure the width of the span using Element.clientWidth. Unless you taint (almost literally) the entire CSSOM, you can pull off similar things.
- derefr 9y agoIs there a reason to not taint the entire CSSOM? Alternately: why not anonymize CSSOM return values? Your browser might have access to OS fonts A+B+C, but if your JS asked the CSSOM about the size of characters on the page, the answer it would give would come from an "alternate world" where the browser only has access to the web-safe fonts, and so is using one of them.
- Arnavion 9y agoPixel-correct measurement of fonts / text is a must-have for certain specific applications like subtitle renderers. (I maintain one.) For a specific example, it's more pleasing to split a long line of text in a way that all the split lines have roughly the same length - "a a a b b b" -> "a a a\nb b b". But CSS only gives you one way to split lines - as much text as possible in all but the last line and whatever's leftover in the last line - "a a a b b\nb". This means a renderer library has to be able to measure the width of text to be able to insert linebreaks itself.
- gsnedders 9y agoHuge amounts of the web will break: anything doing anything layout-related with JS will likely break. Changing line-lengths will cause odd bits of layout breakage, so just giving bogus results as if rendered with a different set of fonts won't work properly either.
- dangayle 9y agoIsn't this one of the stated features of the Tor browser?
- om2 9y agoOne way would be to not expose any installed fonts to web content other than the system default ones.
- rapind 9y agoBut then sites could easily identify and choose to react to that fingerprint. (But maybe that's OK)
- Darthy 9y agoI doubt the next Safari also addresses browser fingerprinting. Otherwise, Apple would have mentioned it. Most likely, ad networks will adopt browser fingerprinting over the next few months, and then Apple will introduce some solution to that in a year or two.
- 3pt14159 9y agoStopping fingerprinting right now is essentially impossible for a motivated attacker. It's enough to block the dumb trackers, but as long as performance is a consideration caches will exist. And as long as caches exist, so will fingerprinting.
- oliyoung 9y agoIt looks like the same pattern as the way Apple scrambles Bluetooth MAC addresses and credit card numbers
- hellofunk 9y agoIt's unclear to me how these "trackers" work? How do they track you, is it cookies, or what?
- Sir_Cmpwn 9y agoThere are a number of ways. Cookies are one, but you can also collect other kinds of data from a web browser to uniquely identify a user across multiple sessions. Generally speaking, if you can run JavaScript, you can track the user. This is done by all advertisers and most little widgets like Facebook or Disqus comments, like and tweet buttons, etc.
- amelius 9y ago> This is done by all advertisers and most little widgets like Facebook or Disqus comments, like and tweet buttons, etc. Why isn't this illegal already?
- notalaser 9y agoBecause it's highly lucrative.
- oneplane 9y agoAnd because it's very functional and easy at the same time.
- JumpCrisscross 9y agoMost people don't know nor care about the issue.
- bauerd 9y agoProbably most (if not all) fingerprinting sources are showcased by fingerprint.js: https://github.com/Valve/fingerprintjs2 https://github.com/Valve/fingerprintjs2
- 9y ago
- deleted 9y ago[deleted]
- jasonkostempski 9y agoDoes Apple have access the data? Because that wouldn't be any better.
- matt_wulfeck 9y agoAlmost everything in the keynote happens on device (deep learning, etc).
- josefresco 9y ago"the web behaves as it always did" Uhhh, not really. Even if the behavior is unwanted, the web will not "behave" the same - otherwise the feature does nothing.
- ceejayoz 9y agoThey pretty clearly mean that the web behaves the same from the user's perspective.
- josefresco 9y agoFor example: The user will no longer see the ads for items they may have previously searched for (even if this is unwanted/unpopular) - that's a a change. Sorry to be so pedantic but it's not accurate to say nothing behaves differently.
- binthere 9y agoLater they demoed they can track your interests in what you've read on the web to show you personalized news on their news app and keyboard autocompletion.
- ceejayoz 9y agoThat'd be first-party tracking. If I'm using an Apple app I expect Apple to know it, but I don't necessarily expect Mixpanel or Google Analytics or Segment.
- ksk 9y agoThe net result is the same regardless of whether it's an expectation in one case versus an outrage in the other.
- draw_down 9y agoThey're also very careful to specify that this computation takes place locally on the device.
- ocdtrekkie 9y agoAnd if this is true, this is a huge plus, because nobody else is doing it. Because Windows is cloud-based for this stuff, just like Google. None of the 'smart' features of Windows 10 work unless you enable what amounts to a keylogger and the ability to send a lot of extra data about what you do to their cloud service. (Well above and beyond the telemetry most people worry about here.)
- andreyf 9y agoWhich would be super creepy if they were a company which is beholden to advertisers for their revenue. But alas, they are not.
- oculusthrift 9y agoneither is MS but every thread about them seems to have a top comment crying about telemetry
- tannhaeuser 9y agoThumbs up for Apple distinguishing themselves by their pro-privacy stance, as opposed to MS, who don't have anything to win by Win10's excessive "telemetry" IMHO.
- ch4ck 9y agoInternet Explorer has tracking protection since IE9.
- ocdtrekkie 9y agoGoing to my IE right now to activate it, I have to say this is a janky solution. It opens the Add-ons window, where you can see you have no Tracking Protection Lists. Then you can click to browse the add-on gallery for them, and then you have to scroll down and pick a list from a set of options. While this is flexible, open, and that's all good, the lack of a common sense default and a multi-step setup process is probably why like... even I am not using this right now. If Apple does this by default, it's gonna make a huge dent in Google Analytics' numbers, whereas probably almost nobody uses the feature in IE.
- tpush 9y ago"it's gonna make a huge dent in Google Analytics' numbers". Very unlikely, since almost nobody uses desktop Safari.
- tyingq 9y agoThe big question to me is whether it's enabled by default, and whether it blocks requests to Google Analytics. If so, that's an interesting shot across the bow.
- magicalist 9y agoWhat would it block? The JS file? Analytics only sets a cookie on the site using it, not one that works across sites.
- tyingq 9y agoCookies are one way to track users. They are not the only one. Google Analytics is so ubiquitous...I can't see Google missing the opportunity to leverage it.
- dbbk 9y agoThis is actually really concerning to me. If they blocked Google Analytics, it would severely damage that data. It'd be bad news for site owners who just want to quantify their traffic.
- icelancer 9y ago....so? Site owners are not guaranteed this access; their script runs on the client computer. I say this as someone who does a lot of analytical research and re-targeting and would be hurt if this was rolled out on a larger scale; I just don't think I have a right to the data.
- ksk 9y agoWell, if don't care about things that prevent you from doing your job, then what exactly is the point of working in that field?
- Spivak 9y agoImagine you were a police officer with this mentality. "As someone who investigates lots of crimes, it's totally fine if someone invokes the fifth amendment, I don't have the right to compel them to answer." "I mean if you don't care about something prevents you from doing your job, why even join the force?"
- tptacek 9y agoThis is great, but unfortunately, until Apple ups its browser security game, Safari is a non-starter. On macOS, switching from any other browser to Chrome is in the top 3 things you can do to materially improve your security in ways that actually matter in the real world.
- JumpCrisscross 9y agoWhat are the other two (for macOS)?
- QuinnyPig 9y ago"Use a password manager, enable MFA" unless I miss my guess.
- wolf550e 9y agoI guess password manager and U2F yubikey.
- tptacek 9y agoI'd combine those two, and then my #3 would probably be making sure that you can't easily click on things in emails that open documents in local applications, and my #4 would be some combination of FDE and encrypted DMGs for projects and sensitive files.
- yladiz 9y agoCan you give specific examples why Chrome is significantly better than other browsers, including Firefox, Opera? Chrome is a non starter for me because of its resource usage and battery hunger. One specific area where Safari is better than Chrome is in private browsing mode. In Safari, each tab is completely separate, and the cookies aren't shared (as far as I can tell) whereas in Chrome, it's only separate as a whole "private browsing session." They each have their pros/cons but I prefer Safari's model.
- M4v3R 9y ago
- deleted 9y ago[deleted]
- kgabis 9y agoFinally, I hope this becomes a common practice from other vendors as well.
- code4tee 9y agoSounds like this is more in line with what they did with ApplePay vs traditional credit cards--I.e. They give you randomized IDs each time so the other party can't track you from transaction to transaction. Adds can still appear but they won't know who you are, so it's a direct shot at Google and others looking to give people "targeted" adds based on user behavior. I agree it's an issue that needs addressed. Just because I searched for X two days ago doesn't mean i want to see adverts on X for the next two months.
- Artemis2 9y agoNote regarding Apple Pay: due to the way credit card networks implement network tokenization, online merchants can actually track you across multiple transactions. You get a per-device ID, of which you can have at most 10 per card (for Visa). Ideally, unique payment tokens would be derived from these IDs for each transaction. In reality, the ID is sent along with a random cryptogram for each transaction, leaving tracking possible (on the same device only). This is because these tokens have to be in the same format as card numbers, and the ranges available to issuers are rather limited.
- Darthy 9y agoThat's actually not how ApplePay works. You get a new randomized credit card number, but only once. Shops can still track you by checking for the number. You can check that yourself by looking at receipts when you pay with ApplePay - each receipt features the same numbers (most receipt only show the last 4 digits, but they are always the same when you pay with ApplePay).
- jarcoal 9y agoIndeed, I observed this because our local grocer asks for your email address when checking out so it can send receipts there. After providing mine it never asked again. It would be really cool if it generated new numbers each time and had an amount coded to that number. So when I wave my Apple Pay device over the reader it would display the amount on the device, I would approve, and then a number would be handed back that's only good for that amount.
- 9y ago
- l0stkn0wledge 9y agoYes, and in the same keynote, they let Siri track stuff down you 'might' be interested in based on patch searching.
- Eric_WVGG 9y agoIt says a lot about the state of the web that both Apple and Google are looking at publishers and saying "Look, if you won't fix your websites, we'll fix them for you" (Google in the form of AMP on mobile devices). However, as one of those who subscribes to the opinion that AMP breaks the web, I greatly prefer Apple's approach. It makes me wonder how many publishers at national newspapers and magazines are even aware of what’s going on.
- floatboth 9y agoFirefox (Nightly at least, I don't follow stable :D) also has built-in tracking protection, only in Private Browsing by default (about:config to enable everywhere).
- truth_speaker 9y agoYou are an unadulterated jackass.
- dang 9y agoWe've banned this account for trolling and detached this comment from https://news.ycombinator.com/item?id=14491639 https://news.ycombinator.com/item?id=14491639. Posting like this will get your main account banned on HN as well.
- ghughes 9y agoHere's the official blog post explaining the feature in depth: https://webkit.org/blog/7675/intelligent-tracking-prevention/ https://webkit.org/blog/7675/intelligent-tracking-prevention...
- aaronbee 9y agoThis suggests that Google/Facebook/Twitter will still be able to track you, assuming you use their websites regularly, but advertising companies that don't have pages frequented by the average internet user won't.
- Eridrus 9y agoThis is going to be a pretty interesting case study in deploying ML in adversarial contexts :)
- Eridrus 9y agoThis is going to be a pretty interesting case study in deploying ML in adversarial contexts :)
- majewsky 9y agoIf I understand this correctly, the obvious counter-measure is for all links on example-recipes.com to go through example-tracker.com, which then immediately redirects to the original website with the linked-to content. Sort of like the weird link URLs in Google's SERPs.
- theprop 9y agoI read https://webkit.org/blog/7675/intelligent-tracking-prevention/ https://webkit.org/blog/7675/intelligent-tracking-prevention... which details this. They're just being a little sophisticated in how they block third-party cookies. This will hardly stop other tracking scripts, tracking images, widely-used fingerprinting techniques and related js calls. So nothing remotely close to even Brave let alone a TOR or the Epic Privacy Browser.
- om2 9y agoWe're trying to do the most extreme thing we can do short of blocking ads. To be more effective, you end up blocking ads, whether intentionally or as a side effect. This blocks more than just cookies by the way, it affects all client-side state. And client-side state is still the primary and most reliable tool used for tracking, even though other methods exist, such as browser fingerprinting, behavioral fingerprinting, and IP-based tracking.
- dzhiurgis 9y agoAnd something says me that ability to completely block third party cookies is going to just as magically disappear.
- suyash 9y agoThank you Apple for taking a stand for user's privacy.
- mmanfrin 9y agoThe cynic in me sees this as cutting off Google, and then tracking within the browser so they become the source of cross-internet tracking. I'd be on the lookout for any new 'personalization' feature that comes in to the browser. E.g. WWDC 2018: 'Today we're happy to announce Siri integration with safari! She will provide personalized recommendations and results by applying machine learning to your documents and data!'
- atestu 9y agoThey showed this on iOS Safari today: > Siri now suggests searches in Safari based on what you were just reading. And when you confirm an appointment or a flight on a travel website, Siri asks if you want to add it to your calendar. Search for "Smarter about you." on this page: https://www.apple.com/ios/ios-11-preview/ https://www.apple.com/ios/ios-11-preview/ Looks like it's done on the device though, End-to-end encrypted with your other devices.
- webuser321 9y agoMeanwhile Apple is tracking users 24/7. There is no option to turn off phoning home to Apple in Apple's pre-installed operating systems. Every user of iOS is constantly pinging Apple servers all day every day. Connect an iOS device to the internet and watch the network. The user is given no control over this. All users are assumed to need Apple's help setting the system time. The networking functionality of NeXT/Apple's operating systems is based on open source BSD operating system code. But BSD does not phone home to some organization when you install it. Why not? Surely Apple's approach is the best one for all users, right? It is amusing to watch these companies proclaim they will block others from tracking and serving ads while continuing to siphon user data themselves, often in ways that are all but transparent to users. Apple can block everyone else, then I can block Apple. OK by me. Someone in this thread made some comment about Microsoft Edge not tracking users. Do people seriously believe nonsense like that? MS was dumping debug output via DrWatson to the network long before collecting user data for profit was even a strategy. Connect a Windows computer to the internet and watch the network. All on by default. Unlike Apple, they have no prepared explanation/justification why they need to do this. And even if they did, who cares? Users prefer not to be tracked. Companies are admitting they know this. Users could opt-in to tracking if they believed they were getting some benefit. But that is not how this game works. There is no "opt-in". It is on by default. There was no intention to make tracking a "choice". Probably because companies know what the choice of users would be and it would not be favorable to the company. But that is not something we are allowed to discuss.
- macintux 9y ago"But that is not something we are allowed to discuss" I suspect you'd have fewer down votes (and thus perhaps some discussion) without this. Congratulations on the self-fulfilling prophecy.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- frio80 9y agoLooks like this will stop (after 24 hours) some companies from doing an initial redirection to set cookies for tracking purposes... Example: 1. Search Google for hockey sticks 2. Click on search result hockeystick.com 3. hockeystick.com issues a 302 to adcompany.com which then issues a 302 back to hockeystick.com Why the 302? Because in Safari, you could only access cookies in a 3rd party context if you've seen a domain in a 1st party context. Setting a cookie in adcompany.com in a 1st party context gives you the ability to read that cookie in a 3rd party context which could be used for tracking purposes.
- YPCrumble 9y agoWoah - is this what companies that "rent" other companies' pixels like perfect audience are doing to get the pixel data?
- flukus 9y agoWon't the browser show an error about a circular redirect? Or does that take a few bounces?
- styfle 9y agoIt wouldn't be circular if the URL was different, for example: website.com ad.com?u=website.com website.com?loaded
- frio80 9y agoThe URLS would be different. Companies also rewrite internal links as you're navigating a site to accomplish the same thing. Example: https://baycloud.com/thirdparty-redirect https://baycloud.com/thirdparty-redirect
- flukus 9y agoAdvertisers will finally move their tracking behind their CDN's, which was always the end goal for them and why they were free in the first place. Then we have a problem where the industry is reliant enough on CDN's that browsers can't simply block access.
- 659087 9y agoGlad to see a player big enough to cause some damage taking this up. At this point, anything that harms Facebook/Google and those trying to mimic their data collection tactics should be considered good for the web and internet.
- HNSucksAss 9y agoMore importantly: They're going to block auto-playing shit. As more and more sites offend readers by disturbing their coworkers, waking their companions, and interrupting other media with offensive NOISE; it's Apple, and not Google, stepping up to do something about it.
- webuser321 9y agoIt is well-known that Apple uses Omniture (acquired by Adobe, aka SiteCatalyst, aka 2o7.net, etc.). As in 192.168.0.2o7.net. Remember, "SWF" stands for Small Web File. Yes, they actually tried to get users to swallow this when Shockwave Flash started to be used in devious ways, such as to track users. Omniture's business is third party tracking cookies similar to Google Analytics or KISSmetrics. Not sure and don't care whether Flash is used so much anymore. If too young to rememeber search and ye shall find information about "permanent, Flash cookies" that could not be removed. Apple is not saying "We will not engage with companies selling third party tracking cookie services." Clearly they are not opposed to third party tracking cookies in principle. Instead they are announcing some change to their browser. Wow, exciting. It is not clear what exactly this announcement accomplishes for users. Probably nothing. If you are trying to avoid ads and tracking, popular browsers (without extensions, etc.) are not your friends.
- horsecaptin 9y agoFor those who are technically inclined: https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts
- quotemstr 9y agoDo you want crappy ads? Then go ahead, make tracking more difficult. Tracking helps you see ads for things you actually want to see. It's not some kind of grand conspiracy.
- greglindahl 9y agoI prefer crappy to creepy. You're welcome to embrace being tracked if you like the reverse.
- kalleboo 9y agoI have yet to see the supposedly relevant ads that all this targeting is supposed to get me. The closest to targeted I've gotten is seeing stuff I already just bought on Amazon.
- MarkMc 9y agoI wonder if this could be good for Google because it has the money and expertise to counter this move by Apple, while smaller ad networks do not.