5 ms·
> This bind() call makes sure the getter looks like a native function. Exactly what we needed. Even the example given as finally working will show difference w
by gorhill 6y ago
> This bind() call makes sure the getter looks like a native function. Exactly what we needed.
Even the example given as finally working will show difference with the native method, the bound function will have a property `name` set to `bound`, while the native one has a `name` property set to `get width`.
My opinion on this is that only the browser can really foil fingerprinting based on surveying the properties of DOM objects.
- hyperpape 6y agoProbably true, however, is it feasible for anti-fingerprinting technology to be sufficiently standardized that website authors can tell "oh, they're using anti-fingerprinting", but not derive more details? If a piece of anti-fingerprinting software hides more information than it reveals, it's a net positive. If it does the opposite, it's actively harmful. There's probably a nice formulation of this in terms of entropy, but I can't quite state it, so hopefully this makes sense.
- iguy 6y agoMy guess is that "sufficiently standardized" has to come from browser-makers. If what my browser reveals (at the default settings) is that I'm using Safari 13, and little more, then it could actually be low-information.
- numpad0 6y agoaaand Google develops Chrome, Mozilla is 90+% funded by Google, and Edge is a fork of Chrome. On mobile? You’ve either got an Android phone, or iOS device, either way they ping Gmail and whatnot so Google knows your IP to correlate with.
- deleted 6y ago[deleted]
- GoblinSlayer 6y agoTurn off javascript, that's your gold standard anti-fingerprinting.
- thotsBgone 6y agoNo
- kube-system 6y agoTwo problems with that: 1. Everybody uses js. If you have it turned off, you are in a very tiny group, and now you’re easier to track. Remember that js is not the only mechanism to fingerprint a user. 2. Much of the web does not work with js turned off.
- GoblinSlayer 6y agoMuch of the web you visit logged in anyway, like facebook.
- nalekberov 6y agoThere is no better way against fingerprinting than disabling js, you might be in a very tiny group, but tons of tracking scripts will fail to work, which means you will traceable by less parties. If a website forces me to use js in order to use it, I will question it, 98% of them is not worth it in my case. Remember js was invented to add websites dynamism, not to serve for surveillance capitalism. (Okay, Big corporations was involved in creation of js, but that does not constitute every action they take)
- Santosh83 6y agoWell that meshes rather conveniently with the fact the almost crushingly dominant browser out there now has little incentive to really foil fingerprinting.
- palant 6y agoNote: I’m the author of the article. I know, the solution presented there isn’t perfect. But IMHO it’s as close as it gets, and it should be sufficiently advanced that detection should be complicated due to differences in browsers and extensions.
- minitech 6y agoNo, as close as it gets is privacy.resistFingerprinting. Extensions shouldn’t even try to do this. (I’ve actually never heard of an extension that tries to do this.)
- the8472 6y ago> But IMHO it’s as close as it gets How about replacing the original method (on the prototype) with a proxy to that method that intercepts apply?
- rasz 6y agowouldnt it make more sense to overwrite toString? original_functions[Function.prototype.toString.toString()] = originalToStringStr;
- palant 6y agoYes, I’ve been doing this in the past elsewhere. Quite a messy affair, you have to overwrite `Function.prototype.toString` – meaning for all functions, no real way to do it for a single function. And then you have to be very careful because your overwritten functions runs in an environment you don’t control. Not sure whether implementing this in a completely tamper-proof way is possible.
- the8472 6y agoFor screen height specifically there may be an alternative way to get to that information that would be more difficult to patch: css media queries. It says deprecated but not unsupported. https://developer.mozilla.org/en-US/docs/Web/CSS/@media/device-height https://developer.mozilla.org/en-US/docs/Web/CSS/@media/devi...