8 ms·
Havent they thought about not broadcasting the window size... wtf. We are doomed apparently.
by trumped 8y ago
Havent they thought about not broadcasting the window size... wtf. We are doomed apparently.
- burtonator 8y agoApps need it to determine where to place elements. If it wasn't you would still be able to reverse engineer it by sticking elements outside the viewport and seeing if they're hidden or not. Turns out anonymity is super freaking hard. :-/
- CharlesColeman 8y ago> Apps need it to determine where to place elements. Could they hide the actual window dimensions from website javascript by only allowing a special kind of sandboxed function to access it? The website's code only really needs to do arithmetic on those values, so the browser could deny access to the actual values and force the code to manipulate them symbolically.
- tedunangst 8y agoAre you also going to download every resource listed in every @media section of the CSS regardless of screen size?
- oftenwrong 8y agoThe browser could pick a fake screen size, and behave in a way that is consistent with that fake screen size. This would probably break many sites, but it would mitigate fingerprinting if a common size was used.
- pmoriarty 8y agoThis solution is just begging for side-channel attacks. Firefox had better make sure its timing is not affected by such shenanigans, for instance.
- oftenwrong 8y agoI doubt that is avoidable, as the browser would still probably need to render at the false viewport dimensions. For a common adversary, fingerprinting based on timing would be more involved and less useful.
- blotter_paper 8y agoThat part doesn't seem too unreasonable to me, but you could also just go with the largest available size and then scale it as necessary on the client.
- missblit 8y agoScaling down the largest size isn't always appropriate (though would probably work in most cases). One example might be a set of images where the smaller images wrap text more agressively to work better on a screen that's not as wide.
- blotter_paper 8y agoGood point, I've seen comparable use cases in the wild but it slipped my mind!
- blotter_paper 8y agoIf I'm allowed to query the position and/or size of anything else in the DOM I can figure out window size by aligning elements at the edges or making one 100vw x 100vh and querying the position/size of those, so you really can't let me access the position or size of anything. I might have elements styled based on media queries, or old-fashioned DOM queries, so if I'm allowed to change how a button looks based on window size I can then check something about this element that isn't directly related to size or position. For example it doesn't make since to have a "download the app" button on desktop, but if you let me make it invisible then you can't let me query the visibility of it. This is true of all styling, if you let me derive it from vh/vw then you can never let me query it after that, which makes a lot of things tricky. Trading functionality that relies on DOM/media queries for privacy is totally valid, I'm just saying that it will make some non-obvious things impossible for a developer to do, and there are sites today that people enjoy using that will have their core functionality broken if this is the future. Browser-based CAD tools were recently discussed on HN, and those are right out. Really, I think the future is both, but I'm not quite sure how they'll coexist.
- zimpenfish 8y ago> Trading functionality that relies on DOM/media queries for privacy is totally valid Perhaps it should be a site-specific permission like the microphone or camera. Your generic news site doesn't need that functionality (and shouldn't ask for the permission - you'd know something shady was going on) but your browser-based CAD tool would and you'd grant it there.
- ringaroll 8y agoThis will cause a permissions fatigue. Only the most sensitive things should have permission. The usage of these capabilities is large enough that it should not be behind a permission.
- CharlesColeman 8y agoIf we went down this path, I think that the any permissions dialog would come at the end of a very long PR campaign and feature ratcheting to get developers to update their sites to not need the permission unless absolutely necessary. Sort of like what's happened with the deprecation of Flash.
- ehsankia 8y agoI don't get it. Don't the majority of people browse at full screen, on common devices which all have the same fullscreen dimensions? Who out there browses to a size, resizes there window, then browses to another website, then resizes again and so on? That makes no sense.
- Swenrekcah 8y agoI would actually really like an answer to this question, I’ve often thought about it!
- mrmekon 8y agoHuh, I thought the original was a sarcastic question. In that case, let me explain: I keep a browser window open at all times. It is never full screen, because if it were full screen I wouldn't be able to see multiple windows at the same time. I keep my browsing window as close to 1024x768 as possible. In 2019, a lot of websites can't handle a browser window using a mere 75% of the laptop screen, so they either render incorrectly or, worse, switch to a mobile view. When that happens, I either blacklist the website forever in a contemptuous fervor, or just resize the window. Apparently, this resizing action is trackable. When I say "as close to 1024x768" as possible, I mean exactly 1024x768 unless I have resized it and forgotten. I use a little AppleScript thing to resize it to 1024x768, precisely for browser fingerprinting reasons. When you resize the window by hand, you typically end up with a VERY unique window dimension.
- meruru 8y agoThe privacy.resistFingerprinting option will always launch your browser at exactly 1000x1000 size. It's probably preferable to your script.
- Swenrekcah 8y agoThanks for the answer. I just thought people usually kept their windows at full screen, but reading all the replies perhaps I am the outlier here!
- 8y ago
- trumped 8y agoapps? do we consider websites apps now? but either way if you have the JS, CSS and HTML, you should know where to put elements. Are nyc (news yc com) people part of the problem?
- function_seven 8y agoWhat CSS file did the browser fetch? The one for screens less than 500px wide? Or the one for screens that are 504px wide? There are a million ways to exfiltrate UI parameters through JS and CSS. It’s hard to both prevent that and still allow JS and responsive pages.
- trumped 8y agojust grab them all... not a huge deal, they are so small.
- function_seven 8y agoOkay. Those different css files all specify different images on the server, depending on the media query. Are we downloading all those images as well?
- trumped 8y agoright... developers suck, overall ( I could not reply to the comment below because nyc would not let me)
- SmellyGeekBoy 8y agoIt's more a case of the web being used in ways in which it wasn't really originally intended. Of course developers can implement things poorly and create problems (and often do) but demand for things like responsive sites is user-driven in my experience. If you don't understand how the web works and actively dislike the community I don't understand why you keep commenting here.
- 8y ago
- renholder 8y ago>Apps need it to determine where to place elements. This determination can't be done client-side? In other words, if I resize the window, it's going to send the new size to determine where to place the elements in the "new" area?
- tedunangst 8y agodocument.Write("<img src=width.png?" + document.innerWidth + ">")
- jancsika 8y agoThat's a problem. The W3C should probably create a new, rich spec hundreds of pages long so that frontend developers may instead declare images as a unitless set of point relationships to be rendered at any resolution without digital artifacts. For example, instead of working on the pixel level, the developer would be free to simply declare, "an arc may exist in one of these four locations." Then, merely by declaring two further "flag" values, the developer can communicate to the renderer which three arcs not to draw, except for the edge case of no arc fitting the seven previously-declared constraints. Just imagine-- instead of a big wasteful gif for something as simple as an arc animation, the developer would simply declare, "can someone just give me the javascript to convert from arc center to svg's endpoint syntax?" And someone on Stackoverflow would eventually declare the relevant javascript.
- tedunangst 8y agoThe browser can also ship with a pretrained GAN, so the site just asks for a picture of a cat and then the GAN creates one as needed, but nobody will know exactly which cat you saw.
- oftenwrong 8y agoSome would take enhanced privacy over properly-functioning sites. I wonder how broken sites would appear if the browser simply lied about such things.
- dymk 8y agoThere’s like a billion side channels to determine how big the screen is unless you just want to entirely break basic css. Which is a pretty unreasonable way to address this problem.
- oftenwrong 8y agoI block CSS altogether on most sites with uMatrix, so I do not think it is that unreasonable.
- rocho 8y agoDoesn't that make most sites unusable?
- oftenwrong 8y agoSurprisingly, most sites are perfectly usable with CSS disabled. They end up looking a bit like "motherfucking website"[1], or what you see in a text-based web browser. [1] https://motherfuckingwebsite.com/ https://motherfuckingwebsite.com/
- blattimwind 8y agoDisabling both CSS and JS actually works around usability issues on a bunch of sites ¯\_(ツ)_/¯ It's like reader mode, except it works on more sites.
- def_true_false 8y agoWouldn't loading all external links right away (think background-image) solve this? How does the site exfiltrate the gathered information without javascript or tracking pixels? Edit: Having a bunch of html buttons/links, showing a different to agents based on their resolution and waiting to see which ones they follow would break this, unless everyone crawls a lot of stuff they don't need. Pretending to be one of a few common sizes is probably a better solution.
- adrianratnapala 8y ago> Apps need it to determine where to place elements Annoying apps which control the layout in JS instead of letting the browser do it will need it.
- gpvos 8y agoWould something like Perl's taint functionality work? I.e., all values derived from size, position, colour, pixel data, user agent, etc. are marked as tainted, and are stripped (or randomized or replaced with default values) from data that is sent over XMLHttpRequest and other communication methods. It's probably extremely hard to make that watertight though.
- thecatspaw 8y agoThat would make it difficult to serve different sized images to different sized screens
- Liquid_Fire 8y agoEven if it was implemented perfectly, you could work around that using timing side channels. For example, multiply the value (e.g. window width) by some huge number, perform a slow operation in a loop that many times, and finally clear a flag. Meanwhile another thread is filling an array one by one until the flag gets cleared. The last non-tainted index in the array indicates your approximate window width.
- enriquto 8y ago> Turns out anonymity is super freaking hard Indeed, but not revealing the screen size is super easy. Just turn off javascript (except, maybe, for a whitelist of 2 or 3 sites where you really need it).
- anoncake 8y ago> Turns out anonymity is super freaking hard. :-/ If you insist on letting random people run code in your document reader.