7 ms·
Tor's anti-fingerprinting measures are available in Firefox. They're off by default, but you can enable them by going to the about:config page, searching "priva
by modo_ 7y ago
Tor's anti-fingerprinting measures are available in Firefox. They're off by default, but you can enable them by going to the about:config page, searching "privacy.resistFingerprinting" and setting to "true"
Interesting discussion from six months back: https://news.ycombinator.com/item?id=19323032 https://news.ycombinator.com/item?id=19323032
- jcomis 7y agoTrue, but it seems to break some sites
- TooCleverByHalf 7y agoAt some point we'll either have to be okay with breaking sites that break our privacy or we won't.
- lbatx 7y agoWe fought a similar battle with Javascript-enabled sites (remember when sites worked without Javascript?) and lost...
- danShumway 7y agoI wasn't part of that battle. I fall into the camp of believing that clientside logic is often preferable to serverside logic, because users are more able to inspect, modify, and archive locally running code. So not only was I not a part of that battle, I was actively encouraging people to make your life worse. But I am a part of this battle. I don't want to start a fight about Javascript; that's a complicated issue. I just want to point out that the "we" you refer to in the privacy battle may be a fair amount larger and more diverse than the "we" was in the Javascript battle.
- lbatx 7y agoI get that they are different. It was an analogy. Either way, I don't think there's enough momentum to stop it this time either. BTW, your argument about being able to inspect local code still seems moot in light of the fact that if you interact with the server, you still have to trust it. 90% of the code might be local, but you still have to worry about that 10% that is opaque to you. And there's no practical difference between 10% of code being opaque and 90% being opaque. The "bad stuff" could happen in that 10%.
- jakeogh 7y agoI leave it off, rarely notice any problems. Using a browser with it on is annoying. Surf makes it easy: https://news.ycombinator.com/item?id=20806638 https://news.ycombinator.com/item?id=20806638
- lbatx 7y agoApparently you don't visit any sites using Angular?
- jlmorton 7y agoEven with `privacy.resistFingerprinting` enabled, my fingerprint is unique all-time on https://amiunique.org https://amiunique.org.
- shakna 7y agoThere's also other fingerprinting that you need to be aware of, like keeping the browser a default size rather than maximising it and giving away how big your screen is.
- shitgoose 7y agoeven with tor browser i am unique all-time
- jdc 7y agoIt seems to me that the Navigator interface is a pretty rich source of info for fingerprinting. For instance, even if I spoof my user-agent in the HTTP request, Navigator gleefully exposes the real one anyway.
- Santosh83 7y agoCurrently you will need to outright disable Javascript to defeat fingerprinting, and it will stay that way unless browsers actually cooperate and standardize ways to present a unified API and default values.
- raxxorrax 7y agoWith the option being enabled, there is 1 other guy that creates the exact same fingerprint. I hope he is not a serial killer... Currently using chrome for HN, but that also creates a completely unique print. I highly doubt it will ever be a focus of this browser to change that issue. And everyone should buy more widescreen monitors, they are awesome. I wonder if users of standard devices like iPhones fare much better. Not that I would want to use one... Curiously, Firefox gives me WebGL Vendor = not supported, which isn't true at all, while chrome gives the full driver name, which in my case is very uncommon (using an intel nuc).
- Quarrel 7y agoI wouldn't put much stock in amiunique right now. It might be great, but needs a bigger sample size. I am unique purely based on my content language: "en-AU,en,en-US" While we like to think we're special in Australia, I'm not THAT special.