31 ms·
Anti-fingerprinting extensions tend to make fingerprinting easier
- gorhill 6y ago> This bind() call makes sure the getter looks like a native function. Exactly what we needed. Even the example given as finally working will show difference with the native method, the bound function will have a property `name` set to `bound`, while the native one has a `name` property set to `get width`. My opinion on this is that only the browser can really foil fingerprinting based on surveying the properties of DOM objects.
- hyperpape 6y agoProbably true, however, is it feasible for anti-fingerprinting technology to be sufficiently standardized that website authors can tell "oh, they're using anti-fingerprinting", but not derive more details? If a piece of anti-fingerprinting software hides more information than it reveals, it's a net positive. If it does the opposite, it's actively harmful. There's probably a nice formulation of this in terms of entropy, but I can't quite state it, so hopefully this makes sense.
- iguy 6y agoMy guess is that "sufficiently standardized" has to come from browser-makers. If what my browser reveals (at the default settings) is that I'm using Safari 13, and little more, then it could actually be low-information.
- numpad0 6y agoaaand Google develops Chrome, Mozilla is 90+% funded by Google, and Edge is a fork of Chrome. On mobile? You’ve either got an Android phone, or iOS device, either way they ping Gmail and whatnot so Google knows your IP to correlate with.
- deleted 6y ago[deleted]
- GoblinSlayer 6y agoTurn off javascript, that's your gold standard anti-fingerprinting.
- thotsBgone 6y agoNo
- kube-system 6y agoTwo problems with that: 1. Everybody uses js. If you have it turned off, you are in a very tiny group, and now you’re easier to track. Remember that js is not the only mechanism to fingerprint a user. 2. Much of the web does not work with js turned off.
- GoblinSlayer 6y agoMuch of the web you visit logged in anyway, like facebook.
- nalekberov 6y agoThere is no better way against fingerprinting than disabling js, you might be in a very tiny group, but tons of tracking scripts will fail to work, which means you will traceable by less parties. If a website forces me to use js in order to use it, I will question it, 98% of them is not worth it in my case. Remember js was invented to add websites dynamism, not to serve for surveillance capitalism. (Okay, Big corporations was involved in creation of js, but that does not constitute every action they take)
- Santosh83 6y agoWell that meshes rather conveniently with the fact the almost crushingly dominant browser out there now has little incentive to really foil fingerprinting.
- palant 6y agoNote: I’m the author of the article. I know, the solution presented there isn’t perfect. But IMHO it’s as close as it gets, and it should be sufficiently advanced that detection should be complicated due to differences in browsers and extensions.
- minitech 6y agoNo, as close as it gets is privacy.resistFingerprinting. Extensions shouldn’t even try to do this. (I’ve actually never heard of an extension that tries to do this.)
- the8472 6y ago> But IMHO it’s as close as it gets How about replacing the original method (on the prototype) with a proxy to that method that intercepts apply?
- rasz 6y agowouldnt it make more sense to overwrite toString? original_functions[Function.prototype.toString.toString()] = originalToStringStr;
- palant 6y agoYes, I’ve been doing this in the past elsewhere. Quite a messy affair, you have to overwrite `Function.prototype.toString` – meaning for all functions, no real way to do it for a single function. And then you have to be very careful because your overwritten functions runs in an environment you don’t control. Not sure whether implementing this in a completely tamper-proof way is possible.
- the8472 6y agoFor screen height specifically there may be an alternative way to get to that information that would be more difficult to patch: css media queries. It says deprecated but not unsupported. https://developer.mozilla.org/en-US/docs/Web/CSS/@media/device-height https://developer.mozilla.org/en-US/docs/Web/CSS/@media/devi...
- pmoriarty 6y ago"Is this magic? No, just how JavaScript prototypes work." Yet another reason to avoid JavaScript.
- horsawlarway 6y agoIf you mean "turn off JS in your browser" then fine, I think that's your choice to make (although I don't agree with you). If you mean "don't write JS" because you, personally, don't understand prototype-based languages... then you're a fool.
- pmoriarty 6y agoIn the context of the article I was commenting on, which is titled "Anti-fingerprinting extensions tend to make fingerprinting easier" what do you think I mean?
- ogre_codes 6y agoCan't answer for the above poster. But after reading both your posts, I'm not entirely sure what you mean in any context. It could mean any of the below in this context and none make sense. Don't use Javascript to do anti-fingerprinting? (JS is the only language available to extension writers) Disable JS in your browser? (Breaks much of the web) . Don't use JS for web development? (I need to pay my bills) PS: Guessing games are a poor means of communicating a point.
- pmoriarty 6y ago"Don't use JS for web development? (I need to pay my bills)" This is not what I meant, but I will say that you don't need to pay your bills by making the web any more of a spyware and adware infested sewer than it already is. You as a developer and a human being have a choice of what to do with your life and your career. No one is forced to be a JS developer, and it's ridiculous to pretend you are.
- 6y ago
- gruez 6y ago...and that's why you should be using firefox with resistfingerprinting enabled.
- palant 6y ago…which has its own track record of subtle website breakage, something that is difficult to notice and impossible to mitigate short of disabling this globally. Don’t get me wrong, it’s nice that this exists, but it’s disabled by default for a reason. There are no silver bullets here. Note: I am the author of this article.
- Forbo 6y agoI find it helpful to realize when websites are taking measures to track me. If their site is broken by privacy protections, maybe I don't want to be using that site any more.
- palant 6y agoIt tends to make animations sluggish, see for example https://github.com/framer/motion/issues/441 https://github.com/framer/motion/issues/441. That’s not because they are trying to track you but simply because requestAnimationFrame (which has its legitimate uses) can potentially be used for fingerprinting. No regular user is going to make the connection between broken functionality and this setting, and I’ve seen developers waste lots of time on this.
- viseztrance 6y agoI did not knew this! But on the other hand, I've seen "performance.now" in the wild being used to track people.
- jedimastert 6y agoresistfingerprinting works by making JS APIs less useful, even if used legitimately. If you rely on something that is both accurate and distinct to a user for functionality, that functionality os going to be broken by fingerprinting mitigation. There is no "fingerprinting API" that can simply be disabled, it's a combination of many APIs that all have real-world not-evil uses.
- jonplackett 6y agoWhen I first read this headline I was imagining physical extensions to my finger tips..
- nwsm 6y agoLife imitates code
- eeZah7Ux 6y agoTL;DR: browser anti-fingerprinting is difficult Use Tor Browser so that your fingerprint will be identical to many thousands of other users.
- duskwuff 6y agoThat's one way. Another way is to use Safari on an iOS device. This has the advantage of making your activity look exactly like other ordinary iOS users, rather than painting a huge "hey, I'm using Tor Browser" target on your head.
- thotsBgone 6y agoYeah, but then you start getting ads for skinny capris and pumpkin spice frappuccinos.
- h-1 6y ago> rather than painting a huge "hey, I'm using Tor Browser" target on your head. Huge problem for criminals. Excellent solution for innocent people wanting to anonymize their browsing.
- eeZah7Ux 6y ago> your activity look exactly like other ordinary iOS users Plain false. It will leak a lot of stuff, starting with your IP address.
- duskwuff 6y agoYou're missing the point. What's being discussed here is anti-fingerprinting, not anonymization.
- nomdep 6y agoThe solution is very simple, but is not technical: make advertising targeted with personal data illegal.
- Spivak 6y agoI don’t think that’s the whole picture though. There would still be a valuable business interest in collecting all of this data even if it wasn’t used to directly advertise products to people. An easy example in the ad tech space would be ad attribution. You don’t have to use any personal identifying information to actually run the specific advertisement to the user for but the PII is then used to correlate whether the ad was effective or contributed to a purchase.
- WaitWaitWha 6y agoHow would you implement it that there are real-world ramifications to breaking your law? For example, what if you are a Nigerian prince? On a more serious note, do we have any data on how well the "do not call" list worked out?
- mosselman 6y agoWhat is wrong with fines? I am not sure what you mean with 'Nigerian prince', but since a lot of e-mail scammers claim to be nigerian princes I will assume you meant that. The problem isn't that some tiny website somewhere uses fingerprinting, because they can't follow you around the web. The problem is companies like Google tracking people around the internet. You can fine them if it turns out that they use fingerprinting techniques to track people. Seems pretty straight forward to me.
- pydry 6y agoI don't think that could happen. Government wants in on this data too.
- TedDoesntTalk 6y agoAnother solution is to click on every damn ad you are shown. Millions of people doing this to billions of ads will collapse the value and make this kind of advertising a waste of money.
- mastre_ 6y agoWhat about randomizing some values on every load to make existing, and additional values (as described in the article), result in new (and therefore useless) fingerprints on every load?
- ffpip 6y agoBrave does that. Its the best way and breaks no websites. https://brave.com/brave-fingerprinting-and-privacy-budgets/ https://brave.com/brave-fingerprinting-and-privacy-budgets/
- palant 6y agoThen you will be the one presenting a new bogus value on every page load – something that makes you recognizable as part of a very small group. As explained in the article, random values are not the way.
- antpls 6y agoI do not agree. First, being recognized as part of a group is better privacy-wise than being uniquely identified. And second, yes your unusual values will stand out, but as they always change, it makes it harder to link the browsing sessions together, and lower the confidence of the algorithm. It makes it harder to _track_ the profile in the long term.
- palant 6y agoFingerprinting works by grouping people. The smaller the group, the better. And the group where values change constantly is bound to be very small. Your assumption seems to be that these changes won’t be recognized. But they are very easy to recognize, e.g. by grouping the values by IP address. Same IP address but constantly changing random values? Yes, that’s a very reliable fingerprint.
- deleted 6y ago[deleted]
- qdhqdhqdg 6y agoWe should make fingerprinting illegal. Fingerprinting is an exploit, an attack on the person and machine. It is tracking using mechanisms that were not meant for tracking. It is without consent and it is without user control (you can clear cookies, you can't clear the fingerprint you've let on thousands of website you browse every week). Cookies, Local Storage (and IP) should be the only legally authorised means of tracking
- godelski 6y agoHow does this protect from nefarious actors? Shouldn't we (also) find ways to make fingerprinting impossible?
- scrollaway 6y agoYes and no; it's still a cat and mouse game. You prevent one way, fingerprinters will find another way. And sometimes, the cure may be worse than the disease. What also makes this a little different is that there's not many nefarious actors that truly benefit from fingerprinting random people. Fingerprinting is very useful in large scale operations, and it's hard to maintain a large scale web presence as an outlaw. I fully agree that fingerprinting should be outlawed by privacy directives. But writing such a law correctly is really tough.
- godelski 6y agoYeah I'm all for better privacy laws. Highly in favor actually. But this seems like the type of problem where you can't tackle from a single direction. I have to imagine there is a way to combat many of these tactics (at least enough to make them difficult) but I don't have the faintest clue of how to combat something like canvas fingerprinting which essentially is exploiting the silicon lottery. I do not think laws go far enough because we live in a global society and laws don't exactly apply globally.
- expect 6y agoNot really. If this large scale operation is run by a government. And law is country-divided mostly.
- WaitWaitWha 6y ago> What has been is what will be, and what has been done is what will be done, and there is nothing new under the sun. This a cat & mouse game and the leaders constantly change. Sometimes the mice are ahead, sometimes the cats.
- avastel 6y agoI worked on browser fingerprinting and countermeasures during my PhD. In one paper, we showed that in the case of an anti canvas fingerprinting extension (canvas defender I think) we were able to extract the seed used to randomise the canvas on each. Since by default the seed was constant, you could use it for tracking: https://hal.inria.fr/hal-01820197 https://hal.inria.fr/hal-01820197 (the paper also talks about other anti fingerprinting techniques). There is also a shorter version in a blog post: https://antoinevastel.com/tracking/2018/07/01/eval-canvasdef.html https://antoinevastel.com/tracking/2018/07/01/eval-canvasdef... (Evaluating the privacy implications of a canvas fingerprinting countermeasure)
- TedDoesntTalk 6y agoWhy would they use a constant seed? How difficult is it to use a time stamp?
- extrapickles 6y agoInstead of timestamps, use the browsers built-in secure random number generator. Anything else can be guessed/computed.
- deleted 6y ago[deleted]
- palant 6y agoBecause any kind of predictable noise can be easily calculated and removed. And randomized noise that changes on each call can be removed by making the call multiple times and averaging out the values. So a constant noise value isn’t the worst possible idea, as long as it cannot be retrieved of course.
- cookiengineer 6y agoI have a dozen of questions... Did you also evaluate fingerprintjs in that context? Also, did you use css tracking techniques, too? Because there are hundreds of them, especially since the logical conditions spec. In my own Browser I'm trying to "fake" behaviours, so that it looks like an e.g. Chrome useragent is browsing the website. I'm also filtering a lot of CSS and HTML that could be abused to track users which is, honestly, a lot. Even the Accept header alone is enough to identify the engine. If you then use a clever webfont you'll have the navigator's version and OS identified due to antialiasing behaving differently... I'm also curious how you evaluated the fingerprintability...is there a project that you were using for that, which someone could maybe test their own browser against?
- 1vuio0pswjnm7 6y ago"It doesn't matter what the data is, it should be: - unique to a sufficiently small group of people" "What you'd rather want is finding the largest group out there and joining it." Presumably there is a threshhold for how large the group must be before the value of fingerprinting to advertisers drops. That is one question. Another question is what value to the advertiser is there, if any, in the data contained in the fingerprint itself (beyond its value in forming a fingerprint). Hypothetical. User disables Javascript, CSS, does not send Cookies, does not send User-Agent. User only sends a minumum number of headers needed to retrieve the page. For example, Host: and Connection: only. Putting aside arguments about whether or not this user is more or less "unique" than other users (the size of the group sending minimal data may be small), as well as any arguments about "breaking websites", is the data in the fingerprint valuable to advertisers. For example, is the advertiser interested in guessing whether the user is using a Javascript and CSS-enabled browser that stores cookies, etc. Will the advertiser perceive the user as a more or less worthy target than another user due to the specifics of the fingerprint.
- Zarel 6y agoThe point is that the fingerprint identifies you, that's why it's called a fingerprint. A user only sending `Host:` and `Connection:` bought a Nintendo Switch on Site A last week. Another user only sending `Host:` and `Connection:` visited Site B, so we assume it's the same person and show them an ad for Breath of the Wild. It's not like anyone targets ads to people with specific screen resolutions (and I don't think people would care if they did). The problem is that the data is used to track your activity. The information it contains is "are you the same person as that other visit we tracked".
- 1vuio0pswjnm7 6y agoThis is valid point if the user is making a purchase. In that case, the user will likely need to be using a popular browser loaded with graphical features, with images, CSS, Javascript and cookies enabled. In practice, it would be impossible to make a purchase via web with only Host: and Connection: headers. (How many websites engaging in online commerce require neither images, Javascript nor cookies.) That said, there may be instances where web users are not engaging in commerce or other uses that require graphics, cookies and interactivity (submitting forms, etc.). It would seem futile to show ads to users who may not see them due to their client potentially not showing images or running Javascript.
- paulie_a 6y agoI say just ruin the information collected. let them fingerprint you all they want, make the data collected extremely useless
- ardy42 6y ago> There you go, the website will now see the same display resolution for everybody, right? Well, that’s unless the website does this: delete screen.width; delete screen.height; > And suddenly screen.width and screen.height are restored to their original values. Fingerprinting can now use two data points instead of one: not merely the real display resolution but also the fake one. Even if that fake display resolution were extremely common, it would still make the fingerprint slightly more precise. > Is this magic? No, just how JavaScript prototypes work. See, these properties are not defined on the screen object itself, they are part of the object’s prototype. So that privacy extension added an override for prototype’s properties. With the override removed the original properties became visible again. This seems like a flaw in the browser extension model. There should be a way of overriding these properties outside the page's javascript environment itself, before it's initialized, in a way that's immutable to anything that runs afterwards.
- kurthr 6y agoPut them in a VM... it's the safest easiest way to be sure.
- joe_the_user 6y agoThe overall challenge for this seems similar to the challenge of reproducible builds. How do you eliminate every single measure to deal with a system quirk and so get the same VM results everywhere? Basically, you want the VM to encapsulate everything and give the same result everywhere. You need a theoretical approach, a system of encapsulation and testing. But if you get that, the benefits would extend beyond anti-finger-printing, to privacy and also to making the platform reliable.
- gzer0 6y agoWhonix [1] attempts to achieve this, if I am understanding what you are saying correctly. The operating system consists of two virtual machines, a "Workstation" and a Tor "Gateway", running Debian GNU/Linux. All communications are forced through the Tor network to accomplish this. [1] https://www.whonix.org/wiki/About https://www.whonix.org/wiki/About
- deleted 6y ago[deleted]
- red_hare 6y agoAs someone who worked on a system that did fingerprinting as an alternative to cookies for non-nefarious reasons, I can tell you the best way to not be fingerprinted is to just use Safari on the newest iPhone. Not because iPhones or Safari are any more private. Just because it's a fixed size browser that you can't customize with extensions and looks identical to 20% of all other sessions.
- nuker 6y ago> iPhones or Safari are any more private. Just because it's a fixed size browser that you can't customize with extensions Do Content Blockers qualify as extentions?
- surround 6y agoI’m not sure why this comment was downvoted. The use of certain content blockers can be detected, but it’s not a very consistent metric. Screen size, canvas, and user agent are use more often because they never change.
- h_anna_h 6y agoRecently Privacy Badger by EFF added a way for sites to detect if the user has it installed https://www.eff.org/gpc-privacy-badger https://www.eff.org/gpc-privacy-badger
- palant 6y agoDuckDuckGo Privacy Essentials implement GPC as well, not sure about any other extensions. So ideally it won’t be usable to recognize Privacy Badger, rather a comparably large group of users of privacy solutions. Ideally of course this would be adopted by browsers eventually. Not saying that this necessarily makes it a good idea, we’ll have to see whether this will do more good than DNT.
- jowq3rijofpg 6y agoFor those saying that fingerprinting should be illegal, how does this balance against the idea that a GET request should never be illegal? Not that I don't despise it, I just can't see how that's not a slippery slope.
- betwixthewires 6y ago>Now one could come up with schemes to change this value regularly, but fact is: making users stand out isn’t the right way. I don't know that I understand the reasoning behind this. The idea behind it is that it isn't the unique fingerprint that is valuable, it is correlation between different captures of the same unique fingerprint that is valuable. So a randomized fingerprint would he unique, but only for one session, and so the data has no value. If anyone understands the reasoning and could explain how I'm wrong I'd appreciate it.
- whatshisface 6y ago"Hey, it's that guy with a randomized fingerprint again. Yeah, we saw him come in yesterday."
- smichel17 6y ago"Are you sure it wasn't the other guy with a randomized fingerprint?"
- whatshisface 6y ago"No, he was randomizing his fingerprint with the Fingerprint Randomizer plugin. The other guy uses uPrint Origin."
- xwvvvvwx 6y agoOnly sure way to browse safely is with js disabled....
- octoberfranklin 6y ago... in gopherspace. And maybe using finger. You can use ytalk for chat.
- KarlTheCool 6y agoI've been using Tor with proxy disabled[1] ever since that fingerprint tester[2] was posted a while ago. I figure of all people forking and hardening a web browser, I trust the tor project the most. I'm no tracking expert, but it's the only way I've been able to score a non-unique fingerprint. [1] https://github.com/KarlTheCool/tor-without-tor https://github.com/KarlTheCool/tor-without-tor [2] https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/