4 ms·
It's unclear to me how these "trackers" work? How do they track you, is it cookies, or what?
by hellofunk 9y ago
It's unclear to me how these "trackers" work? How do they track you, is it cookies, or what?
- Sir_Cmpwn 9y agoThere are a number of ways. Cookies are one, but you can also collect other kinds of data from a web browser to uniquely identify a user across multiple sessions. Generally speaking, if you can run JavaScript, you can track the user. This is done by all advertisers and most little widgets like Facebook or Disqus comments, like and tweet buttons, etc.
- amelius 9y ago> This is done by all advertisers and most little widgets like Facebook or Disqus comments, like and tweet buttons, etc. Why isn't this illegal already?
- notalaser 9y agoBecause it's highly lucrative.
- oneplane 9y agoAnd because it's very functional and easy at the same time.
- JumpCrisscross 9y agoMost people don't know nor care about the issue.
- bauerd 9y agoProbably most (if not all) fingerprinting sources are showcased by fingerprint.js: https://github.com/Valve/fingerprintjs2 https://github.com/Valve/fingerprintjs2
- Cyph0n 9y agoFor a second I thought "why in the world is Valve maintaining this". Confusing username to be frank.
- throwaway2048 9y agoIt is essentially impossible to enumerate all the ways browsers leak fingerprintable information.
- bauerd 9y agoYeah true, should've put it another way.
- olivierlacan 9y agoI'd go with !Tor.
- TallGuyShort 9y agoIn practice, User-Agent strings (which are just HTTP headers) have been shown to be pretty effective at uniquely identifying and tracking most people. So even disabling JavaScript and Cookies only goes so far.
- gruez 9y agoSource? Because the only information contained in user-agent strings in modern browsers are browser version (realistically limited to vendor since browsers auto-update) and operating system version. So basically all you're going to get is (Chrome/Firefox/Edge/Internet Explorer/Safari on Windows/Linux/Mac), which isn't much.
- wil421 9y agoA quick Wikipedia search turns up more fields [1]. Although some of these fields are not 100% accurate due to historical reasons (I'm looking at you IE). I'd bet there are a couple other data points they gather via JS to finger print. Example: Mozilla/5.0 (iPad; U; CPU OS 3_2_1 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Mobile/7B405 1. https://en.m.wikipedia.org/wiki/User_agent https://en.m.wikipedia.org/wiki/User_agent
- gruez 9y agoI compared 2 chrome versions and it seems that most of the version numbers there are static. Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2979.0 Safari/537.36 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.10 Safari/537.36 As for iOS 10 it's pretty sparse as well. Mozilla/5.0 (iPhone; CPU iPhone OS 10_0_1 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A403 Safari/602.1 It's slightly worse than windows because it probably discloses your device type, but there are tens (hundreds?) of thousands of users for each iphone variant.
- wil421 9y agoGood read here.[1] An example could be using your installed fonts. Like I was saying they probably use a bunch of other JS tricks. These 3rd parties aren't going to disclose anything.
- fjarlq 9y agoA decent overview: https://panopticlick.eff.org/about https://panopticlick.eff.org/about Test your browser: https://panopticlick.eff.org/ https://panopticlick.eff.org/
- tr1ck5t3r 9y agoIts all in the JavaScript.
- hellofunk 9y agoThat site is interesting, and it shows you that 1 of X browsers resemble a particular fingerprint ingredient. I found this one rather interesting, it was the most unique of the ones listed: HTTP_ACCEPT Headers One in several thousand have the same headers as me. But the headers themselves are quite a small little string, I'm surprised it is that unique.
- om2 9y agoMost trackers use cookies or other client-side state to track you across the web. There's also various fingerprinting techniques but they are less reliable.
- frio80 9y agoIt's cookies and the change isn't really earth shattering but it does close the "redirection trick" loophole that some companies were using to track you across domains. See my example here for more specific details: https://news.ycombinator.com/item?id=14493373 https://news.ycombinator.com/item?id=14493373