6 ms·
window.navigator.hardwareConcurrency [edit: well this is more of a 'how' than a 'why']
by tomg 6y ago
window.navigator.hardwareConcurrency
[edit: well this is more of a 'how' than a 'why']
- Sephr 6y agoThe answer to why: It helps with efficient allocation of worker thread pools. I helped make a timing attack[1] as justification for adding this API, and then presented this suggested API to each browser vendor along with the timing attack. The result was that every browser has adopted my suggestion. If this API was not present, ads could get this data in a more resource-intensive manner anyways. 1. https://eligrey.com/blog/cpu-core-estimation-with-javascript/ https://eligrey.com/blog/cpu-core-estimation-with-javascript...
- simias 6y agoAhah, I like the "give up" approach to fighting browser fingerprinting! "If ads can track us, we might as well make it efficient".
- moron4hire 6y agoThe threshold of information needed to gain reliable fingerprintability is so low that we could rewind the browser development clock 20 years and still be nearly 100% identifiable. We'd gain nothing in terms of privacy, but we'd lose everything in terms of the first and only application platform that runs on every system short of a greeting card, is free to use, easy to use, not tied to an app store, not tied to a single vendor.
- AnthonyMouse 6y agoThe original sin of the web is that the code comes from the server again every time you run it. That means you need robust sandboxing and anti-fingerprinting etc., because you're running potentially hostile code that nobody has been able to audit. Other types of programs don't have that problem. If you get some code from Github, you can review it yourself before the first time you run it. Then every time after that, it's still the same code so you only have to do it once. And you can have someone you trust do it for you, like a Debian package maintainer. But with nobody reviewing the code, the machine has to do it, i.e. there have to be a bunch of technical constraints on tracking and malicious behavior. It's a terrible rubbish fire that we don't have any kind of real application platform for real applications that runs the same on every system and doesn't have a monopolist dictating terms. We should fix that. But we could fix that, and be better off than by giving up and conceding the world to surveillance dystopia.
- TeMPOraL 6y ago> Other types of programs don't have that problem. Well, they didn't. They do now, as you're expected to update everything continuously. A typical user of a PC or a smartphone has something downloading an update pretty much every day. Even a tech-savvy user can't hope to keep up with trying to track down all sneaky automatic updates and read a changelog before applying them (assuming there even is one, beyond "This update improves experience and fixes bugs" zero-information boilerplate). At this point I'd be willing to pay for a service that would intercept all automatic updates on my devices and warn me about the ones that bring in telemetry, malware, performance degradation or other misfeatures. Unfortunately, such a service would require impossible feats of crowdsourcing to keep up with the deluge, and itself would be a huge privacy/security risk.
- AnthonyMouse 6y agoAren't you just describing a package manager or an app store? The reason mobile app stores are garbage is that the store is glued to the platform, making it high-friction to switch to another one if they do a bad job. Then they do a bad job by allowing things you don't want and prohibiting things you do want (and charging high fees etc.) and get away with it. There is no reason for this to be centralized into a single approver. If you got 90% of your software through the Debian package manager but specifically need a newer version of Blender than they package, you could get that in particular directly from the Blender developers because you trust them not to intentionally distribute malicious code, while still relying on the package maintainers to do the work for all the other software you use. That's possible right now on Linux. The problem is mostly that it's not possible right now on everything.
- TeMPOraL 6y agoYou're right, in a way. What I described would be a reality under a package manager with curated repositories, if I sourced all my software from there. My wish came from the opposite end - I have all this software on my devices that's sourced from a lot of different places, and some of the software on my PC has built-in auto-update that's independent of the original installation method. What I want is a curation add-on - a single (at least per-device) component that would intercept all automatic updates of everything, coupled with a database (the service part) that could tell me roughly what the update contains, and flag anything problematic (telemetry, ads, feature removals, performance degradation, ...). Your reply made me realize two things: 1. I used to hate default package sources on Debian for shipping a small selection of outdated software. I formed this impression back when I was young and naïve, and didn't question it since. But now I can see the value in having actual humans curate the software. I need to get out of the habit of adding random sources and PPAs just for the sake of having everything bleeding edge. 2. I'm really mostly pissed about this on behalf of other people. I've learned to manage my devices - mostly by being very selective about the software I run. Most people I know in the meatspace don't have the necessary experience and time, and helping everyone individually doesn't scale.
- seniorgarcia 6y agoSo... you are an "expletive deleted"? Actually you are an "expletive deleted" that is fine with his work used in fingerprinting. "If we would not have provided this API, ad providers would have gotten it anyways"... Unless, maybe websites do not need to know how many worker threads I can provide and your spec is part of the problem. Maybe you are part of the problem. Pretty ironic that your last tweet was: >Federated Learning of Cohorts is harmful to your privacy. This is literally additional tracking. Nobody is asking for this except for advertisers. Ad networks should target their ads based on the content being viewed, not on the person or 'cohort' viewing the content.<
- moron4hire 6y agoI actually use this feature for a VR app I'm building. I'm so sick of the privacy fetishism. You're fingerprintable, ok. You're so fingerprintable that to make you not fingerprintable, we'd have to make browsers only do static document retrieval. Oh, wait, no, not even that would really be enough. Your IP address plus the pages you visit at which times of day is enough. The browser hasn't been a document-reading platform since CGI was invented. What is that, 30 years now? You don't like that apps are built in browsers? I don't care. Functionally nobody cares. If we couldn't, we'd be building Java apps instead, someone would have invented an open source, live, searchable, distributed system for finding apps, and then you'd still be fingerprintable. Go sit in a cave if you don't want anybody to know who you are. The rest of us have work to do.
- seniorgarcia 6y agoAnd I do not get this at all. For my desktop you would get 12, I'm on a i7-8700k with a base frequency of 3.7GHZ and a permanent boost of 5.1GHZ. This rig runs Oculus VR/Steam VR all the time. If I ran that site from my Surface laptop the response would be 12 as well. The 12 cores on my surface boost is 12 1.3GHZ cores though if they boost. The cooling might work out to boost 2 cores to 1.9GHZ. Or however the Intel boosting works out in this thermal constraint. So, what is the useful info you get for your VR app from these values?
- 6y ago