4 ms·
Can you please elaborate?
by yetanother-1 5y ago
Can you please elaborate?
- capableweb 5y agoUsing the DNT (Do-Not-Track) header as an example. When you make a request to a service, you're browser can attach this DNT header to signal to the service that you don't want to be tracked. But since services that you're getting responses from can just ignore that (no repercussions for ignoring it really), it becomes another data point they can use to separate you from other users who's headers would be the same as you.
- gruez 5y ago1. resistfingerprinting (RFP) doesn't affect DNT. it's also not some sort of flag that nicely asks services to stop tracking you. 2. That's not a good analogy. If we're looking at a single choice in isolation, it's true that opting into DNT (or RFP) makes you stick out compared to everyone. There's only two options (DNT header being present or not), and one option is obviously more common than the other. However, the difference with RFP on/off is that there aren't really two options. Yes, RFP can only be on/off, and "on" is much more rare than "off", but leaving it "off" also uniquely identifies your device through fingerprinting. You're not really choosing to blend into the "all the people with RFP on" group vs "all the people with RFP off" group. You're choosing to blend into the "all the people with RFP on" group vs "all the people with RFP off and has the fingerprint as you" group[1]. Whether that's more or less identifiable is unclear. If you have the most run of the mill setup[2], then RFP might indeed make you stick out more compared to your normal setup. However, if you have an uncommon setup, it might make you stick out less, because the amount of RFP users is greater than the amount of users with the same fingerprinting attributes as you. [1] in reality it's not really one group for RFP users and separate groups for everyone else. There are fingerprinting attributes that RFP doesn't block, so it's more like a set of groups for RFP users, and a separate set of groups for non-RFP users, but there are less distinct elements in the RFP set, since various fingerprinting attributes are spoofed to be the same. [2] see https://wiki.mozilla.org/Security/Fingerprinting https://wiki.mozilla.org/Security/Fingerprinting for list of features that are spoofed, and make your own determination how common your setup is.
- deleted 5y ago[deleted]
- perryizgr8 5y agoI am not very well-versed in this, but I have read many pieces like this: https://forum.vivaldi.net/topic/52638/to-resist-fingerprinting-you-want-to-browse-the-web-as-normal-as-possible-to-avoid-identification https://forum.vivaldi.net/topic/52638/to-resist-fingerprinti... > So in short: your normal browser does not have to be honest about it's properties, but it won't make you more anonymous because you still stand out from the other people and content on the web will break. Tor works because everyone has the same properties, including resolution. You can surely change your resolution, but there is just simply a chance that you will be standing out from other people. It's just safer to keep it the way it is. If the "resist fingerprinting" feature changes anything in the data that is read by trackers, you will stand out like a sore thumb among the millions of browsers with the default settings.
- tinus_hn 5y agoTor Browser also quantizes document width so it’s much less of a fingerprint.
- TonyTrapp 5y agoWhen you are one of the few people that enable this feature, you are part of a smaller group of people. Maybe you are the only person in your own using this feature, so seeing a single client with the "resist fingerprinting" characteristics and correlating that with things that the browser cannot avoid (e.g. IP address mapping), you might now be uniquely identifiable.
- chaosite 5y agoYou turn on the option. This causes your browser to act in a different, specific way, that can then be detected. Most people do not change default options, so just turning on that option is something that identifies you.
- no_time 5y agoFingerprinting resistance should be more focused on feeding false information to these algorithms rather than crippling their functionality and thus sticking out from the crowd. To my knowledge, resistFingerprinting mostly does the latter.
- gruez 5y agoThe problem is that "feeding false information to these algorithms" only really works if the algorithms are naive and don't try to detect whether you're lying. If your "feeding false information" mechanism can be detected, you're still in the same position.
- no_time 5y agoNow that I think about it more, yeah sadly. Even worse, it could be only effective on a per script or even just a per site basis.