4 ms·
Crazy idea, but why not put the onus on the browser and require that EU browsers have the ability to block and manage cookies and tracking scripts. Much less t
by everdev 8y ago
Crazy idea, but why not put the onus on the browser and require that EU browsers have the ability to block and manage cookies and tracking scripts.
Much less to regulate plus we wouldn't have ugly banners all over the place.
- pacala 8y agoIt is trivial to uniquely fingerprint a browser, even if there are no cookies involved. Surveillance can and should be fought off in the legal sphere.
- c22 8y agoSo some incentive to design non-fingerprintable browsers sounds great! Especially since such a product would require widespread deployment to be effective.
- Etheryte 8y agoI haven't worked through the grunt work myself, but I'm fairly certain it's basically not possible to design a completely fingerprint-proof browser so long as a browser includes a programmable Turing machine via Javascript, not to mention network request statistic info etc, all of which are used by completely legitimate websites to improve their experience & performance.
- pacala 8y agoModern ML can fingerprint you based on your mouse movements. Good luck selling a browser without mousemove events.
- wtallis 8y agoThe vast majority of web sites don't need mousemove events except to enable bad UI design. The exceptions that are trying to implement a desktop app or video game inside the browser can ask for permission. It's not at all hard for users to make the one or two clicks necessary to grant a domain permission to use the bundle of advanced features it is requesting, and it gives them a reasonable opportunity to provide informed consent before a website starts monitoring their every move.
- wtallis 8y agoIt is trivial to fingerprint the default configurations that browsers currently ship with, but it isn't very hard to make browsers much more resistant to fingerprinting. There's a lot of unnecessary information leakage in user agent strings that can be dropped. Most of the features that browsers have been adding in recent years as part of their quest to become full-fledged operating systems should be off by default for sites that the user hasn't approved. More than half of the estimated bits of identifying information identified by EFF's Panopticlick tool could be denied to trackers if browsers had better defaults.
- staplers 8y agoTor exists and is blacklisted by nearly all corporate sites. Technology is not the answer here. Can't tell that to computer programmers though.
- wtallis 8y agoTor has nothing to do with browser fingerprinting, except that browser fingerprinting is the main reason why Tor is relatively useless as a general purpose privacy tool.
- staplers 8y agoTor has nothing to do with browser fingerprinting So you're just purposefully being an idiot..
- dang 8y agoPersonal attacks are not ok here, and unfortunately it looks like you've posted a lot of them. We ban accounts that do that, so could you please review https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and follow the rules from now on? We're hoping for a bit better than internet default in this community. You might also find these links helpful for getting an idea of the spirit of the site: https://news.ycombinator.com/newswelcome.html https://news.ycombinator.com/newswelcome.html https://news.ycombinator.com/hackernews.html https://news.ycombinator.com/hackernews.html http://www.paulgraham.com/hackernews.html http://www.paulgraham.com/hackernews.html http://www.paulgraham.com/trolls.html http://www.paulgraham.com/trolls.html
- SiempreViernes 8y agoDude, it's not like GDPR is trying to solve some inefficiency in http caching, it tries to address a social ill where some people make profits by abusing the private information of others: it's not a technical problem so the solution won't be an browser extension.
- jdietrich 8y agoThe GDPR regulates the collection and processing of personal data. Not just cookies, not just tracking scripts, but any information about me that an organisation chooses to collect or store. It is important and popular legislation that has significant implications outside of the browser. A straightforward example is the current trend for consumer DNA testing. In the US, companies like 23andme or Ancestry.com can send you a cheek swab kit, charge you a hundred bucks to find out some trivia about your health or genealogy, then do pretty much anything they like with your genetic data thanks to some vaguely-worded terms of service and a lack of meaningful regulation. In the EU, those companies can only use your genetic data for explicitly stated purposes with the informed consent of the consumer; the consumer has the right to withdraw their consent at any time, to request a copy of all information held on them or to request deletion of their data.
- forgottenpass 8y agoBecause law should be tailored to the issue it seeks to address and written as close to the root of a problem as is practical? Cookies and tracking scripts are only one aspect of privacy invasion, not privacy invasion itself. You're looking at a cat and mouse game and suggesting the government put it's effort towards building a better mouse instead of telling the cat to fuck off.