4 ms·
> What more do you want? Inform users when they silently pass garbage through web APIs such as HTMLCanvasElement.toDataURL(), when it happens. And the UX of th
by dessant 4y ago
> What more do you want?
Inform users when they silently pass garbage through web APIs such as HTMLCanvasElement.toDataURL(), when it happens. And the UX of that should also be very carefully considered.
Otherwise you might end up with some critical document scans on a government website being uploaded as striped nonsense images without your knowledge, and the "may degrade your Web experience" that you glanced over a year before when you enabled the option may not cut it when your Visa application is delayed or rejected.
- gruez 4y ago>Inform users when they silently pass garbage through web APIs such as HTMLCanvasElement.toDataURL() >[...] when your Visa application is delayed or rejected. Isn't that what the prompt (pictured in the article[1]) is for? It doesn't always show up, but AFAIK it only does that when the page tries to grab canvas data before the user has interacted with the page. For a page where you're uploading documents, that seems unlikely. [1] https://user-media-prod-cdn.itsre-sumo.mozilla.net/uploads/gallery/images/2020-04-24-10-28-54-496d8e.png https://user-media-prod-cdn.itsre-sumo.mozilla.net/uploads/g...
- dessant 4y agoIt can auto decline the canvas request and return fake image data from the API by default when privacy.resistFingerprinting is enabled. privacy.resistFingerprinting.autoDeclineNoUserInputCanvasPrompts must be set to false to always show the popup, and even then they shouldn't serve fake data when the user declines the request, but throw an error for the API call.
- gruez 4y ago>It can auto decline the canvas request and return fake image data from the API by default when privacy.resistFingerprinting is enabled. privacy.resistFingerprinting.autoDeclineNoUserInputCanvasPrompts must be set to false to always show the popup Right, it can auto-decline it in certain circumstances. As the name suggests, it auto-declines it when there there isn't any user input. That seems fairly reasonable to me, and is unlikely to cause issues with you uploading documents for a visa application (you need to interact with the site to upload the document in the first place). That said, I was playing around with it using various codepen demos and discovered that even if you interacted with the page, if the page was in an iframe it would always not show the popup. That might cause issues in certain circumstances and I do hope it will get fixed. >and even then they shouldn't serve fake data when the user declines the request, but throw an error for the API call. Whether that's the best approach is debatable. For the use case of uploading a document, I agree that would be the best behavior, but for other cases (ie. it's trying to display something), an exception would likely crash the app. In many cases (eg. google maps), the garbage data doesn't interfere with my use of the app, and crashing the app would be far more disruptive.
- pmontra 4y agoA better UX should be "I'm sending this image instead of this one, because of fingerprinting. Are you OK with that? Yes, No send the original image this time." This would prevent problems but I don't think it can cope with the number of requests in the normal flow of web browsing.
- gruez 4y ago> A better UX should be "I'm sending this image instead of this one, because of fingerprinting. Are you OK with that? Yes, No send the original image this time." I'm presuming you want the browser to somehow detect whether the garbage image data ends up in a POST request? I don't see how you can implement that in a reliable way, considering there are dozens of ways to go from canvas data to a POST request.
- pmontra 4y agoSome flag on the data carried on along the line (I remember Perl's tainting) but I'm not holding my breath.
- noizejoy 4y ago> Otherwise you might end up with some critical document scans on a government website being uploaded as striped nonsense images without your knowledge, and the "may degrade your Web experience" that you glanced over a year before when you enabled the option may not cut it when your Visa application is delayed or rejected. I use a different (from my regular privacy optimized) unmodified browser for such websites and use cases. While this is clearly not a perfect solution, I also subscribe to the adage[0], that “perfect is the enemy of the good”[1] [0] https://www.thefreedictionary.com/adage https://www.thefreedictionary.com/adage [1] https://en.wikipedia.org/wiki/Perfect_is_the_enemy_of_good https://en.wikipedia.org/wiki/Perfect_is_the_enemy_of_good