23 ms·
Web fingerprinting is worse than I thought
- sluuuuurpey 4y agoIf you buy two of the same exact model iPhone and boot/config IDENTICALLY, on the same Wi-Fi network, they would have the same fingerprint, right?
- dariosalvi78 4y agothe problem is that the alternative, that is native applications, is even worse. Let's face it, some level of identification comes with networking, there are ways to anonymize connections, but none is perfect. Tracking should be limited with legal means.
- Isaac57 4y ago[flagged]
- arcanemachiner 4y agoWow, that really is a shameless plug.
- intelVISA 4y agoFor a crappy product as well, double shameless..!
- suprjami 4y agoJust because you can doesn't mean you should. Worst ethics ever. I hope you go broke.
- Isaac57 4y agoThe main use case that we're tackling is financial fraud, scams, account takeover and more. - Over $32billion is stolen yearly online due to financial fraud, and browser fingerprinting has proven to be one of the most reliable way to combat sophisticated fraudsters
- zelphirkalt 4y agoNext you tell me this thing will be saving us from child porn or even terrorism.
- unnouinceput 4y agoI disagree. I hope the guy becomes wildly successful, so a leak of his methods get in the news here so we know how to protect against that as well. What you suggest is to put our heads in the sand instead. No, no and no. I prefer to be exposed to the worst so we learn how to protect ourselves. That's why this is Hacker News and not PutOurHeadInTheSand News.
- dmitrygr 4y agoWhat makes you think that this is a worthwhile addition to the world?
- walrus01 4y agoIf you don't pay attention to it you might be surprised how non dynamic your residential internet last mile DHCP assigned IP really is. It's not uncommon to go many months or a year with having it always renew to the same address. That, combined with all the fingerprinting mentioned in the article...
- pbhjpbhj 4y agoThis would be one of the things about IPv6, we'd have lifetime fixed IP addresses (or address ranges at least). Wouldn't we?
- intelVISA 4y agoThen IPv6 adoption must be frustrated at all costs, in the name of liberty ...of course.
- perlgeek 4y agoThere's "Privacy Extension" for that, from https://labs.ripe.net/author/johanna_ullrich/ipv6-addresses-security-and-privacy/ https://labs.ripe.net/author/johanna_ullrich/ipv6-addresses-... > The IPv6 Privacy Extension is defined in RFC 4941. It is a format defining temporary addresses that change in regular time intervals; successive addresses appear unrelated to each other for outsiders and are a means of protection against address correlation. Their regular change is independent from the network prefix; this way, they protect against tracking of movement as well as against temporal correlation.
- pbhjpbhj 4y agoThanks, can you answer a couple of questions: So carriers (ISPs) still would need to do NAT, the RFC didn't seem (I skimmed) explicit? Isn't the removal of processing traffic a large part of the sell for IPv6. Also, surely the ISP can sell IP-to-user correlation lists as I assume they do now? They can presumably do it anonymously bit with some other party seeking the other part of the data that allows deobfuscation of users (eg to comply with GDRP)?
- matheusmoreira 4y agoI wish browsers did more to combat this. There should be ways to randomize or normalize every bit of information they try to gather.
- donatj 4y agoIt’s a double edged sword you need to walk the edge of. Almost everything they use to fingerprint you has a fully legitimate use case which is why it was added. The more you do to prevent fingerprinting the more you hobble the web as a platform. A lot of restrictions that got placed on the canvas tag to help prevent fingerprinting for instance really limited its functionality. In my opinion a workable solution would be to make more of these things opt-in by the end user to high accuracy data for the page.
- aaomidi 4y agoMost of those APIs should be default closed. Incognito should definitely be default closed.
- pipo234 4y agoBut it's not just a matter of "open"/"close". It's more like signal/noise. Much of the signal is legit: source IP is needed to deliver response, screen resolution, audio/video codec support, transfer protocol, cache headers are all needed to render the page correctly and as quick as possible. Unfortunately, much of that signal persists across sessions as well as websites and can therefore be aggregated into a hash that works as a "super cookie". The signal is based on the device, the connection, not so much the HTTP/HTML you're looking at. The best approach to mitigate is therefore: adding noise: add random gibberish to User-Agent, tunnel IP though VPN/NAT, lie about codecs or screen resolution. While that degrades user experience, it give no guarantees to actually preventing fingerprinting. So, the good news, if that fingerprinting is hard too, and doesn't work as well as is usually claimed!
- iudqnolq 4y ago
- chaosite 4y agoIt's important to know that the mentioned "resistFingerprinting" breaks a lot of the web. Examples include the back button, uploading photos on some websites uploads random data instead of the photo, etc.
- db48x 4y agoIf it breaks uploading a photo, it’s because the page unnecessarily copies the image into a <canvas> and then tries to upload the data from the <canvas> instead of the original image.
- codetrotter 4y ago> the page unnecessarily copies the image into a <canvas> and then tries to upload the data from the <canvas> instead of the original image. Surely there could be valid reasons for doing so? I imagine for example that: 1. It ensures the selected file is a valid image before uploading it 2. It strips meta data like GPS position from the image before uploading it 3. It could reduce the size of the image, by either scaling it down, or compressing it more, or both, before uploading it
- deleted 4y ago[deleted]
- TylerE 4y ago3 sounds incredibly undesirable to me, assuming we’re dealing with a jpeg. Go through 3 or 4 rounds of that and compression starts to get pretty visible.
- kevincox 4y agoMost websites will recompress user images. Although you probably don't want to do it client side. The biggest reason is if course cost saving. Store and transfer smaller images. This could be done client side with a server side check on max size. Another big reason is metadata stripping. Both to protect the user (can be done client side) and to avoid unintentional data channels being provided. Another reason is to avoid triggering exploits. If a major browser has a JPEG rendering exploit Facebook doesn't want you to be able to pwn everyone who sees your post. By using a trusted encoded it is very likely that the produced image is more or less following the standards and not likely to trigger any exploits (as exploits usually require invalid files).
- victorbjorklund 4y agoDamn yea I didn't know it was so easy to do in practice (I just heard about theoretical approaches)
- oellegaard 4y agoActually quite surprised to see that this identifies me on Safari in Incognito, after visiting in regular mode first.
- helsinkiandrew 4y agoAnd on Chrome - even counts the number of times you visit in incognito
- momentoftop 4y agoI don't understand the test on this page. It says we should be worried because a fingerprinting website generates the same hash even after you clear your cache and site-data, and even if you go into a private tab. But I'm not overly concerned by this, provided I share that hash with other people. The worry would be that the hash is unique to me (i.e. a fingerprint), but I don't see the evidence that it is.
- geysersam 4y agoSure, the advertisement graph only showed recall and not precision. Maybe everyone gets the same hash! That'd explain their excellent results. However, I doubt that's a problem in practice. I'd assume these finger printers know what they're doing. It certainly seems so. How could one make an experiment collecting lots of these finger prints and determine the false positive rate?
- mejutoco 4y agoHere is evidence that the hash can be unique, or narrow down a small group of people https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- jefc1111 4y agoThis is a nice website.
- suprjami 4y agoThe likelihood that you have the same hash as other people is exceedingly small. So if I fingerprint you on a site which is using my commercial fingerprint service, then I can sell your hash to other places and tell them all about your browsing habits. The more places run my fingerprinting service, the more data I can collect on you.
- momentoftop 4y agoI understand the principle. I'm saying that the test on this page isn't demonstrating uniqueness, and so isn't demonstrating fingerprinting. The first time I heard about fingerprinting was with EFF's panoptoclick, which stated how many hashes had been generated from visitors, and how many you shared with them.
- toldyouso2022 4y agoGDPR should have been approached at browser level. But there would not have been money to make for those that provide "compliant" banners. I guess the economy needed the stimulus.
- pavlov 4y agoIt's not too late. The EU is breaking Apple's and Google's mobile app store monopolies next year with the Digital Markets Act. Those same two companies effectively control the browser market. If there's political will in Europe, they can be forced to implement working privacy controls.
- illiarian 4y ago> GDPR should have been approached at browser level. GDPR. isn't. about. browsers.
- fstrazzante 4y agoI totally agree with you! .. and second: the website navigation would be smoother without those banners!
- geysersam 4y agoGDPR isn't about cookies, browsers or the web. > But there would not have been money to make for those that provide "compliant" banners. Are you serious? Do you think WordPress addon makers lobbied GDPR through the European parlament?
- Kaotique 4y agoToo bad the biggest violator also created the biggest browser.
- illiarian 4y agoNote also: As the number of APIs increases, so does the fingerprinting. E.g. MIDI device enumeration (no prompt in Chrome, prompt in FF, not implemented in Safari): https://twitter.com/denschub/status/1582730985778556931?s=20 https://twitter.com/denschub/status/1582730985778556931?s=20
- factormeta 4y agoWe need 2 classes of web. One for document based that doesn't require JS to run (secure). Insecure, all the SPA and anything that require JS to see the full content.
- grishka 4y agoBack in the day, we had a nice boundary between the document and the "app". Then for some reason we decided that Flash doesn't need to be a thing any more and erased that boundary by building the app functionality into browsers themselves, making the app and the document inseparable. We should have invested that effort into building an open source Flash player instead. One of the nicest things about Flash was that you could set your browser to only load and run Flash content after you click it.
- giancarlostoro 4y agoJava Applets were worse though, every time I got a virus of any sort from merely browsing generic sites, it always happened due to Java in the browser. I finally stopped installing Java for the web and my security problems went away. Flash had some security nightmares all the time too if I remember correctly but I dont think it ever screwed me over like Java did. I think unless we lock down new APIs that aide in fingerprinting to only be accessible to WebAssembly and let people block or enable WASM theres not too much else we can do. It would be nice to be able to block web APIs selectively to limit what a JS script can do.
- nordsieck 4y ago> I think unless we lock down new APIs that aide in fingerprinting to only be accessible to WebAssembly and let people block or enable WASM theres not too much else we can do. IMO, it should be enough if incognito mode presents an identical fingerprint on everyone's browser.
- 1vuio0pswjnm7 4y ago"That's how web works." Nah. I make an HTTP request and I get a response. That's how the web works. Perhaps people can have different opinions on "how the web works". Web fingerprinting relies on a heap of assumptions. For example, that someone uses a web browser to make HTTP requests, that the web browser sends certain HTTP headers in a certain order, that the web browser runs Javascript, that it processes cookies, recognises HSTS response headers, and so on and so on. If all the assumptions are true, maybe web fingerprinting is effective. But if the assumptions fail, maybe web fingerprinting does not work so well. I have only ever read blog posts about web fingerprinting that take all the assumptions as true. The majority of traffic on the internet is said to be "bots". Not web browsers running Javascript, processing cookies, and so on. It seems to me that someone should discuss what happens when the assumptions fail. Do advertisers care about computer users who do not use graphical browsers much. As such a user, IME, the answer is no. (Interesting to see how defensive replies get. It's obvious the "tech" crowd intent to spy on web users is heavily reliant on certain assumptions to remain true forever. It shows that there is necessary pressure to keep web users using a "preferred" web browser and web ""features" that will subject them to "web fingerprinting". Perhaps the assumptions will always be true, conditions will never change, in the same way that interest rates could never change.)
- twelve40 4y ago> "bots". Not web browsers running Javascript, processing cookies, and so on even the simplest bots nowadays can run Javascript and process cookies. What's much harder for a bot (or some other actor that has been doing shady things across many websites) to uniquely fake are things like the graphics card (WebGL Vendor & Renderer), audio and other hardware, which gets queried during fingerprinting. Full fingerprinting is relatively expensive, so it originally was used by fintechs to combat fraudulent/automated signups, but with the third-party cookie situation it might be already economical to track regular users for ads/retargeting.
- JD557 4y agoI think you can still be fingerprinted without cookies or Javascript (e.g. with HSTS supercookies). It's obviously not as effective.
- kapsteur 4y agoYou can try https://www.amiunique.org/fp https://www.amiunique.org/fp to get a view of all params can used to track you
- stefncb 4y agoIt's interesting that they can narrow me down to less than 0.1% with just my language list (en-US,en,fr,ro). My user agent is practically unique as well, since I'm running an unusual configuration. I've never thought of that as a disadvantage when it comes to tracking, hah.
- Semaphor 4y agoI have "prefer English, German as fallback". That alone makes me almost unique as well. Not fully (like your special config :D), but enough that other resist fingerprinting options become meaningless.
- iudqnolq 4y agoThey narrowed me down to an order of magnitude less based on just my browser user agent (latest Firefox Android). I'm not sure what that actually means.
- throwaway202302 4y agoI observed this too, but I cannot really believe it. For me it finds just german on the iphone. I get 0.88% for it. But if all Apples do it the same, I can hardly believe this provides already such selectivity. The problem with such test sites seems to me that only nerds visit them, and therefore the database is small and biased.
- helsinkiandrew 4y agoSurely if your website collects data using browser fingerprinting this is covered by GDPR and you have to tell your visitors/ask for permission? https://www.eff.org/deeplinks/2018/06/gdpr-and-browser-fingerprinting-how-it-changes-game-sneakiest-web-trackers https://www.eff.org/deeplinks/2018/06/gdpr-and-browser-finge...
- PrimeMcFly 4y agoGDPR doesn't really apply outside of Europe, despite what the EU might claim.
- twelve40 4y agoalso, one could just roll it up into a wall of fine print or something, no? who reads these things anyway?
- Semaphor 4y ago> also, one could just roll it up into a wall of fine print or something, no? That also violates it. Facebook just lost in court in the first instance trying that.
- kalleboo 4y agoGDPR requires an opt out available, that is just as easy to opt out of as it is to opt in. Fine print disclaimers are illegal.
- akie 4y agoThe EU does not claim that it applies outside of Europe, just that the law applies to all your customers/visitors that are within the EU.
- Zurrrrr 4y agoIIRC they do try to claim it applies outside of Europe; they say their laws apply to any entity processing data of EU citizens, regardless of where the data or website actually lie.
- throwaway2056 4y agoIt is interesting that the site can fingerprint individual profiles/dir easily: For example chromium-browser --user-data-dir=/tmp/profile_A chromium-browser --user-data-dir=/tmp/profile_A --incognito chromium-browser --user-data-dir=/tmp/profile_B chromium-browser --user-data-dir=/tmp/profile_B --incognito For each command + its incognito it can detect them as separate profiles. For ultimate privacy one needs to everytime launch browser with a new profile.
- vesinisa 4y ago... on a new computer, each time ordered from a different brand and reseller, paid with a unique type of cryptocurrency and delivered each time to a new dead drop in a different country.
- throwaway2056 4y agoI tried live boot of ubuntu. Every time it can detect accurately. Looks like the whole privacy thing is OVER. Unless lawmakers do something - (i.e) not going to happen! Atleast they can use this to prevent reCaptcha - and make passwords disappear!
- than3 4y agoUbuntu has a lot of unique information that is readily accessible. Machine-ID in /etc being one, but there's various other items that can be used in the same way from d-bus activation, and something like 20 different other places, another large number in snap.
- throwaway202302 4y agoWebsites can access machine-id?
- ale42 4y agoI guess they can't unless somebody had a great idea in the speficiation osome web API...
- noduerme 4y agoLook, forget about threat models. It's relatively trivial these days to avoid fingerprinting attacks if you want to (as a private, web browsing individual). I use fingerprinting actively in enterprise apps as a form of silent 3FA. It's a useful backstop. If I have a user who forgot their password but retrieves it via email, I'll usually let them pass if their fingerprint matches one of their priors; otherwise my software shoots off an email to their immediate superior to make that manager validate that the machine the employee is using is one they can vouch for. I've always viewed browser fingerprinting as something that can be leveraged as a security feature. It's far more useful for that than for some sort of distributed tracking. I'd never want to live in a world (ahem ... China) where submitting to such fingerprinting actively was mandatory, or politically punishable if you didn't. No society should be run like an employer/employee organization with that sort of lack of trust. No sane free person would allow their own browser to transmit a fingerprint. But for employer/employee systems management? It's a great tool in the box.
- ashildr 4y agoDunning and Kruger agree.
- rat9988 4y ago"It's relatively trivial these days to avoid fingerprinting attacks". Why should it be on me to avoid them? And more importantly, it's NOT trivial.
- noduerme 4y agoreally? it takes a minute to set up a VPN and do your web browsing through a virtual machine. I guess it's not "trivial" for the average American, but it definitely is for the average terrorist or child pornographer, so it's easy compared to surmounting most other threat models faced by people intending to evade detection. Therefore, "trivial". [edit] also, the less trivial it is, the better for corporate security.
- defrost 4y ago
- ManiAbod 4y ago[dead]
- Isaac57 4y ago[dead]
- tgv 4y agoYour customers perhaps, but google and facebook definitely use it for tracking.
- raverbashing 4y agoThere's a flipside question as well, how many users have the same fingerprint as you?
- speedgoose 4y agoIt depends on your browser. You have a common iPhone with Safari in your local language, many people have the same fingerprint. You configure your iPhone with Chrome (that is a webkit view on iOs) and another language, you are suddenly much more rare. You compile Firefox on your ArchLinux with Nouveau drivers and a 16/10 screen, you are unique in your area. You can experiment there: https://coveryourtracks.eff.org https://coveryourtracks.eff.org
- zamubafoo 4y agoAs the years pass, I keep thinking back and realize that Richard Stallman was right all along: > For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time.
- Technotroll 4y agoI think Stallman just shot himself in the foot by even revealing that much. Unless a lot of people do the same thing, it's very easy to conclude that it was Richard Stallman who sent that WGET request, granted a few variables. The difficult part is perhaps tracking it back to its actual source, but I don't think Stallman is that hard to find. All this is of course extremely chilling. I'm sure a profile could be built up around WGET requests, and then employing some "likelihood machine" on it, to make educated guesses as to how likely it is that the WGET request was actually from Richard Stallman. I think we've just stumbled upon a new and "fun" Where's Wally game here!
- BeefWellington 4y agoWGET can be pretty trivially told to send custom headers.
- bigfudge 4y agoIt would be a lot of work to make it mimic a common profile though.
- justinclift 4y agoThat work was probably done once, years ago. Might need a few string tweaks every few years, which could be automated.
- bigfudge 4y ago
- ThePhysicist 4y agoUsing the IP address & user agent alone already gives you nearly 100 % accuracy, so the fact that they can re-identify you when these things stay identical isn't surprising at all. I tested that website as well and if you take care to rotate your IP address their re-identification rate becomes abysmal, especially if you're using a privacy-focused browser and extensions like Privacy Badger / uBlock.
- misja111 4y agoExactly. IP address identification is the elephant in the room that the article just briefly mentions. Nearly all websites that want to target adds to you use that. It's just so simple to use, you can't switch it off like you can with cookies, except of course by using a VPN but almost nobody does that.
- ridgered4 4y agoI often see the narrative on here that consumer VPN providers are almost useless for privacy due to other fingerprinting methods, which I've never really bought.
- tejohnso 4y agoI just tested at fingerprint.com using mullvad. Brave browser, no VPN, they recorded one visit, one IP. Brave browser, no VPN, incognito, they recorded two visits, one IP. Brave browser, with VPN, incognito, recorded three visits, two IPs. I'm pretty impressed / surprised. A fresh incognito session, through a VPN, still matched the same fingerprint. Especially surprising since TFA indicates Brave randomizes the fingerprint. I even changed my fingerprint block setting to "strict, may break sites" and it's still recording the same visitor ID from Brave, even with incognito.
- figglestar 4y agoJust tried this with VPN + firefox resist fingerprinting. I cleared cookies and session data and reloaded, it recorded 1 visit 1 ip for the first (obviously) and second tries. I did not change my VPN connection between attempts. Based on this test I'm surprised Brave's fingerprint resister did not work for you. But on firefox the enhanced privacy protection (strict) and the resistfingerprinting option are two different knobs.
- brunoqc 4y agoI wonder if https://jshelter.org https://jshelter.org helps with that. And if it's not too slow.
- hilbert42 4y agoHa! I followed the instructions and went to fingerprint.com and it all 'crashed' because I had JavaScript turned off—that's my normal default setting. I have five different browsers on my smartphone and three on the PC all sans JS and none of them are Chrome. Also, normal operation is to automatically delete all cookies at session's end. My smartphone and PCs are de-googleized and firewalled and I never see ads in my browsers nor in apps. The apps are mainly from F-Droid and sans ads and the few Playstore ones I use are via Aurora Store and are firewalled from the internet when in use. Honestly, I cannot remember when I last saw an app display an ad, it has to be years back. In the past I used to go to more extensive measures to stop the spying but I found it was unnecessary as the spy leakage was essentially negligible with much less stringent efforts. It's pretty easy to render one's online personal data essentially wothlesss if one wants to. On the other hand if you insist on using JS, Gmail, Google search, Facebook etc. then you're fair game and you only have yourself to blame if your personal data is stolen.
- comboy 4y agoThe more you customize the more unique your session becomes.
- kuschku 4y agoNot if you disable JS, cause the website then can't see any of these customizations.
- Dah00n 4y agoYou are easily tracked without JS. It is much easier than tracking a default settings browser.
- d-z-m 4y ago> It is much easier than tracking a default settings browser. Not true. Especially if you mean a default browser with Canvas/WebRTC APIs enabled. It is much more difficult for fingerprinting companies to get a high entropy fingerprint from a no-JS user.
- izacus 4y agoWhy is this being fought with technical measures (which are ineffective and cripple the web as a platform) instead of legal consumer law where you can easily fine and punish companies that do the fingerprinting? EDIT: Note that you can do BOTH - but one without the other is just a game of whack-a-mole.
- siquick 4y agoBecause like the climate crisis, it’s easier to make the individual clean up the mess and make the changes than hold large organisations accountable.
- masklinn 4y ago> Because like the climate crisis, it’s easier to blame the individual than clean up the mess and make the changes. FTFY?
- mcherm 4y agoBecause some browser-makers (Firefox at least) believe that the identity of those browsing the web should be protected. Legislators do not believe that. (At least, a majority of legislators do not.)
- giancarlostoro 4y agoWhat kills me is the cookie consent stuff, they should of enforced that Do Not Track is honored, and have fees that make sites ensure compliance or be sued over not honoring DNT which iirc was sent as a HTTP header, it would of actually been a meaningful solve.
- dgroshev 4y agoWould you consider the entire European Union a minority of the legislators? Because that's what GDPR is designed to do, make identifying customers well controlled and expensive whatever the method. Granted, the enforcement should be stepped up.
- luckystarr 4y agoI use the usual adblocker UBlock and: * https://addons.mozilla.org/de/firefox/addon/canvasblocker/ https://addons.mozilla.org/de/firefox/addon/canvasblocker/ which prevents fingerprinting via Canvas elements, additionally warns you if a site does it. There are more sites out there than you would assume. Some stupid blogs even. * https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/ https://addons.mozilla.org/en-US/firefox/addon/multi-account... This splits your tabs into different categories, each with their own cookie storage. The fingerprinting website in the article didn't manage to correlate me visiting the website concurrently from two distinct container tabs.
- stinos 4y agoThe fingerprinting website in the article didn't manage to correlate me visiting the website concurrently from two distinct container tabs. But that's merely because of the canvasblocker (or something else you have), because just separate containers doesn't cut it?
- Technotroll 4y agoI'm just guessing here, but I'm fairly sure that they use a model that updates dynamically as the "user" or victim changes his or her web browsing settings, and even when the user tries to hide. It easily sounds like some kind of Bayesian filtering going on, or some sort of Markov Chain or decision tree. That is to say that their model tracks the likelihood that you're the same unique user that reloads the page based on the information it can glean from you. This makes it exceedingly hard to hide from such a filter, because in communicating with these sites, you are bound to reveal at least some information about yourself. And then the "likelihood-machine" does the rest by connecting the dots, even if you gave them "fewer dots." It's also quite interesting - or perhaps chilling - to see how fingerprinting through NLP and other language tracking algorithms can also track just about any forum post you do, even if you're using a pseudonym.
- Jaer3hah 4y agoWell, I'm glad to report that my efforts to fight fingerprinting have paid off. I use a text based browser, with no js, no cookies, no css, no external requests past the first html page download, no user agent, no etag, I connect through Tor and I've modified the browser to randomize http headers. And of course, it sometimes happens that I want to see something that is refused to me with that configuration (like, seeing anything behind the big internet killer, aka Cloudflare - thanks archive.org for existing), so I have also a classic browser for the occasional lowering of barrier. At first, I thought fingerprint.com did identify it, giving me the hZ4W5oQ7pJVIHbW2fBXA id. Then I realized it was giving the same id when using curl with and without Tor. Then I realized, by googling and ddging that id that it's the one reported as well to search engines. So it's not unique and it's basically a "dunno" reply.
- trizzzzyump 4y ago[dead]
- Semaphor 4y agoFor anyone who this is news to: This is why I always call the "I don't care about cookies" extension an adtech submarine, because it deceives you into thinking it’s all about cookies, when the permission you give automatically in many cases are about tracking, so using that extension will often have you consent that fingerprinting you and creating a profile based on that is perfectly fine.
- meghan_rain 4y agoImplying they actually stop tracking when you press "Reject"
- TeMPOraL 4y agoThey may not, but if you're in/from the EU and press "Reject" and they still track you, they're breaking the law.
- zatni 4y ago"break the law" means nothing when you're a large corporation that makes more money from breaking it than you spend on fines. Tech companies routinely get fined for what may seem like massive amounts to us. https://www.businessinsider.com/the-7-biggest-fines-the-eu-has-ever-imposed-against-giant-corporations-2018-7?r=US&IR=T https://www.businessinsider.com/the-7-biggest-fines-the-eu-h... If "breaking the law" meant something they would try to avoid doing it so often. Microsoft in the 90s was recognized guilty of abusing their monopoly. What were the consequences? nothing. This sort of thing used to mean something, see: Standard Oil v United States. But the current world is a world that belongs to megacorporations. Tracking people against their will is a drop in the ocean of what corporations get away with. This, in many ways, is like a billionaire getting a ticket that doesn't amount to more than the hundreds of dollars for bad parking. The billionaire doesn't care. Law only has meaning when the punishment is coercive.
- miggol 4y agoTo me, the thing is that I can't count on the consent modals to actually do anything. Am I really going to invest time into checking their word? How would I even do that? That's on top of all the time wasted moving sliders or hiting "reject all". For me, the cookie consent modals are the submarines. Why would I outsource the responsibility not to track me to the people with the incentive to track me? IDCAC, Cookie Autodelete, and strict tracking protection feels like the better alternative for me. (From today onwards, I'll add resistFingerprinting=true to that list as well.)
- jamesfisher 4y agoWhy do these systems use hash-based fingerprinting? Wouldn't it be "better" to have a "browserspace vector", or "browser embedding"? So that if one fingerprint tactic fails in incognito, you don't completely lose the fingerprint, you just get a slightly different vector?
- KoftaBob 4y agoI was able to "trick" the fingerprint.com test by opening it first with firefox, then with tor browser. Gave two different visitor IDs. So as suspected, it largely relies on IP address.
- aembleton 4y agoA different browser with the same IP also gives you a different hash.
- reportgunner 4y agoSeems like a disguised ad for that fingerprinting service. Resist fingerprinting was already set to true in my Firefox. "Worse than I thought" apparently means "I thought there was no fingerprinting but I found out there is fingerprinting."
- SV_BubbleTime 4y agoTry to get a non-unique on iPhone. I’ll admit it’s worse than I thought.
- alkonaut 4y agoWhat is the use case for these fingerprints when adhering to the GDPR? You can't store them in a DB and use them to target your returning anonymous visitor with products relevant to their last visit. You can't send them to a third party ad service to get more relevant ads. Isn't the whole point of the fingerprint to maintain an pseudonym for your users over some time window? But that requires storing them which would be against the GDPR?
- charcircuit 4y agoTo prevent spam. If someone is spamming your site how do you tell if a request is coming from a legitimate user or if it is coming from the spammer. Fingerprints are how you can tell the two apart.
- alkonaut 4y agoI thouht that was most commonly dealth with with a first party cookie. I.e. show the captcha to anyone who doesn't have the cookie. At least that's how it feels when you browse incognito.
- charcircuit 4y agoWhat happens if they solve the captcha? If a captcha service costs $0.02 per 1000 captchas that means they can post. That means it costs $10 to post a spam message every minute for an entire year if they get banned after every post. If you want to annoy some site owner that would be an easy way to do so.
- darefalcon 4y agoAgree - cross site tracking of devices without consent is going the way of the dodos. With respect to fraud prevention, being able to analyse device signatures along with identity and behavior on a per-site basis is the only reason we are enable to enjoy what’s left of the ‘open web’
- beeforpork 4y agoWhen I switched off fingerprinting in this browser, the font size here on Hacker News changed. I suppose it just uses the user agent to set a certain font size, or does Hacker News track based on fingerprinting?
- richthegeek 4y agoThe CSS for HN is very terse, and aside from a mobile-specific set of rules it doesn't really do any variation. Is it possible you had set the zoom level previously, which the browser remembers between sessions, and turning off the tracking reset the zoom to 100%? Do you have any extensions like Greasemonkey or Stylus for per-site customisation?
- red_trumpet 4y agoYou mean `privacy.resistFingerprinting` in Firefox? I guess that disables custom font configurations.
- EastSmith 4y agoIt is sad that Brave + uBlock Origin + DDG Privacy Essentials does not seem to be able to fight this.
- CatWChainsaw 4y agoWouldn't the browser and extensions make you more unique?
- redbell 4y agoAnother method for web fingerprinting is called GPU-Fingerprinting [0], codenamed 'DrawnApart', it relies on WebGL to count the number and speed of the execution units in the GPU, measure the time needed to complete vertex renders, handle stall functions, and more stuff.. _______________________ 0. https://www.bleepingcomputer.com/news/security/researchers-use-gpu-fingerprinting-to-track-users-online/ https://www.bleepingcomputer.com/news/security/researchers-u...
- est 4y agoWhat the world needs: <body onload="javascript.disable()">
- danbruc 4y agoCan we fingerprint fingerprinting code and block it? At first glance it seems like code accessing all kinds of unrelated high entropy APIs should be something detectable. But then static analysis might be too hard in face of obfuscation so it would have to be done using dynamic analysis which kind of means you let the fingerprinting happen but are now at least aware of it. So how do you prevent the fingerprint from being used? In principle one could maybe mark values from entropy sources as tainted [1] an taint all the variables potentially influenced by those values and prevent them from leaving the browser. Not sure if this would be practical and I am even more skeptical that this could be easily added to existing browsers. [1] https://en.wikipedia.org/wiki/Taint_checking https://en.wikipedia.org/wiki/Taint_checking
- than3 4y agoThe short answer is no you can't block it because that identifies to the site owner that you are blocking it (as a negative match). You'd have to mask every informational API with a suitable corrupted alternative that is plausible.
- danbruc 4y agoThis is confusing whether it can be blocked and whether it would be effective. Every time you do something unique, you of course become identifiable. But the idea is of course that you are not the only one blocking these scripts which will only make the entire group identifiable. You could for example try to block those scripts with a widely used ad blocker which would make you not stand out any more than any user of that specific ad blocker. It would probably not be too effective as URIs and file hashes or whatever ad blockers use are relatively easy to change, but in principle you do not have to become uniquely identifiable by blocking fingerprinting scripts if enough people are doing so.
- than3 4y ago> This is confusing whether it can be blocked and whether it would be effective. It shouldn't be confusing because its really fairly simple. The gist is this... so long as determinism as a systems property holds true in a system, you can leak information by the absence of something when compared to another expected thing. This is how inference works in many respects, you have properties and you can deduce or infer from whether those are present additional information that is not necessarily given. Most gifted problem solvers probably couldn't tell you that is what they are doing because its unconscious often a result of years of observation. Computers fundamentally require certain system properties such as determinism to do work in the first place, and you can inject non-determinism into those processes in ways that won't break underlying subsystems as long as its within an expected range and that can make it indeterminate. An indeterminate fingerprint is useless. In the case of outright blocking the code from running, you leak information that you are blocking it by preventing it from running since they expect a range of values back and a null (the response when nothing gets sent back) is itself a value (or state if you want to be technical). The site then only has to test for this semi-unique case (i.e a null represents a single group of people who are blocking it) and then prevent the site from responding to you. They are the gatekeepers because they control their infrastructure. Incidentally this is how almost all the Are you human tests work. It collects an intrusive fingerprint, and if its within a range that corresponds to a known user spectrum of values then it allows you to continue to the site. This is a rough boiled down explanation, it can get quite a bit more abstract and technical when talking about whether determinism is present (i.e. how do you test for it). Ultimately, if you can understand determinism, you fundamentally understand the limits of computation and how computers work at a barebones level. It also gives you the ability to find whether certain types of problems are impossible (and thus you don't waste your time on them, or unproductive avenues).
- t0bia_s 4y agoMull (FF fork on Android) and LibreWolf (FF fork on desktop) has privacy.resistFingerprinting = true by default. Highly recommended! https://f-droid.org/en/packages/us.spotco.fennec_dos/ https://f-droid.org/en/packages/us.spotco.fennec_dos/ https://librewolf.net/ https://librewolf.net/
- timbit42 4y agoDo they remember site zoom levels?
- mihaic 4y agoFingerprinting is doing terrible things for big-tech data collection, and at the same time it's excruciatingly hard to protect against bots, spammers, fraudaters etc without it. Few people seem to try to reconcile this, since neither side cares about the other. I personally think that discussion about fingerprinting as raw tech, without mentioning the size of the company collecting the date or the purpose is meaningless, and only leads to a few tech savy users having less data collected on them. Most people want to use Javascript, use the default setting and not be afraid of clicking on links. I can't really see a good solution without a coordination of regulation and tech standards, so I'm hopeful at least for decent solutions.
- enjoytheview 4y agoYou don't need to precisely identify users across sessions without their consent to detect bots, advanced anti-bots make heavy use of biometrics to detect bots and don't rely too heavily on fingerprinting, mostly because they're easy to spoof in general, but generating human-like mouse data is a bigger challange.
- paleotrope 4y agoI wonder if you could use a chicken like in the old chicken tic-tac-toe machines to mimic real user behavior.
- jsmith45 4y agoSure, but on the other hand, a lot of anti-fingerprinting efforts strive to reduce the info available including things like mouse movement data. Mouse movement data is a fairly potent fingerprinting vector. Bucketing the average spouse speed and acceleration rates could provide provide useful information. This may imply specific OS speed settings, or physical mouse DPI. A machine learning system would likely be able to distinguish traditional mouse, vs trackpoint, vs touchpad, vs trackball. Etc. Also it is not just bots that have non-human like mouse movement. Many assistive technologies would have no mouse movement, or would auto snap the mouse to relevant spot. That is actually a quite powerful for fingerprinting, since assistive technology users are a pretty small subset of internet users, so only a relatively small amount of additional data is needed to uniquely fingerprint that user/machine.
- zer00eyz 4y agoTarget and the model that found the pregnant girl (bad counter argument here: https://medium.com/@colin.fraser/target-didnt-figure-out-a-teen-girl-was-pregnant-before-her-father-did-a6be13b973a5 https://medium.com/@colin.fraser/target-didnt-figure-out-a-t... There are three options: 1. Prevent/Stop it: This ship sailed long ago. Not to be grim about it but pandoras box got opened. 2. Fight it: Tool up, change your print, your behavior, your place. Build focused VM's that you use per topic. Simply do a WHOLE lot less. In the grand scheme, its a lot of work for low return. Note: there are exceptions. 3. Increase Noise: The whole point of most data collection is to sell more to you. Because most people are sheep, a fairly simple model can be surprisingly accurate (over targeting is an issue). Don't be a sheep, diversify, make more noise in the system, search out side your comfort zone and change it up often.
- cuu508 4y agoRegarding the more noise strategy, Mozilla has this fun tool: https://trackthis.link/ https://trackthis.link/
- avnigo 4y agoI thought about the noise route, but doesn't that make you more unique? Maybe if many users share the noise, but then that makes it easier to identify what's noise and what's not.
- zer00eyz 4y agoAny thing that doesn't impact the signal, or can be separated from the signal does not qualify as noise. You want to quickly throw targeting systems off your scent (or get them distracted) see how sticky high value sales are for the ad's you see on line. Start looking for a new car, use the word wedding too much (god help you if your a woman) or say vacation 3 times near search engine and watch how quickly your ad experience changes. This won't work "long term" As an example: You get an ID as a 24 year old male, who likes his local sports ball team, drinks canned domestic beer... that's a profile that is perfect to sell you a BBQ grill and a subscription to the meat of the month club. Spend an hour or two a week pursuing sewing, the engine is going to get confused! Maybe you share a device with your wife, or she got on it... This is the sort of noise you create, its not random its "more" and you do it by going off type for a while. Have a friend who is into something you aren't (music, art, and so on) ask them some questions and go spend a week getting more informed on their hobby and have a chat with them. Suddenly the systems will see you as MORE...
- ergonaught 4y agoEven after discovering it is worse than they thought, it remains far worse than the author thinks. Public knowledge is far behind the actual capabilities in practice.
- d-z-m 4y agoThis is easy to say, but not always true. Can you elaborate about concrete details of the "capabilities in practice"?
- ergonaught 4y agoI can but frankly I'm pretty happy about the lack of lawsuits in my life currently.
- IvanK_net 4y agoThe idea of the Incognito mode is, that the website should be unable to detect that you are using the Incognito mode. There is a bug in Chorme, which I reported, but they told me they will not fix it: https://bugs.chromium.org/p/chromium/issues/detail?id=1204850 https://bugs.chromium.org/p/chromium/issues/detail?id=120485...
- Brigand 4y agoYou are not detecting incognito mode but another attribute that correlates with incognito mode.
- switch007 4y agoOn iOS I visited fingerprint.com on safari twice and then opened used Brave with its “Block fingerprinting” setting enabled and it registered it as my third visit! They should label it as “resist” as it’s a lot more honest And https://www.amiunique.org/ https://www.amiunique.org/ says I’m unique in Brave compared to “nearly” in Safari haha
- SV_BubbleTime 4y agoSame. I did iPhone with VON change, cleared cache, firefox or IOS, blocking extensions, and… it gets me every time.
- dean2432 4y agowith resist fingerprinting enabled in FF, it resets the zoom level i have set on each individual site, so it's just annoying.
- darefalcon 4y ago“Worlds most accurate”: Source, fingerprintjs. Sounds legit.
- someoneFromWeb 4y agoI tested it on Brave mobile (Android) and I got different fingerprint each time
- fnord77 4y agothe demo got my browser totally wrong. it has me showing up in various places around the country and I don't use a VPN. One of the dates I was out of the country and my laptop was at home, turned off
- SV_BubbleTime 4y agoYou are using cellular data then. Your exit point when using 3-5G can be a lot of strange places. Not unusual.
- mwexler 4y agoThe EFF has tried to get folks to pay attention to this for years. See https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ aka Panopticlick And it probably understates the problem these days, missing some of the more recent techniques.
- cobbaut 4y agoHow many websites do you need to visit before being unique in the world? Say I follow AS Monaco football, then look for Lego Castle figurines and finally visit a forum on Alaskan Malamute dogs. The combination of these three websites is pretty close to unique in the world imho. Surely most people can be uniquely identified after visiting a couple more, unless we change browser and ip-address and GPU and set resistFingerprinting=true and ... and clear cookies after every website we visit.
- shashashank 4y agoI remember once in college I'd shared my phone's hotspot to connect a TV to the internet after it had abruptly stopped working. And all of a sudden the ads being shown (on YouTube) switched from the local language to mine, both of which are completely different.
- ttyprintk 4y agoThe combination of IP, language preference and available fonts is very potent and not obvious to Americans.
- tomxor 4y agoI think Firefox might actually enable this by default for third party sites, but not 100% what this about:config one does: privacy.trackingprotection.fingerprinting.enabled This would make sense since messing with values for the root frame could cause unwanted side effects, but you're not likely to care if some iframe gets your screen resolution or CPU count wrong.
- bawolff 4y agoI dont think this is a proper way to test it. It matters more how unique your fingerprint is than how consistent or reproducible it is. Just testing if you get the same fingerprint back on your second visit doesn't tell you much if you don't know how many people "share" your fingerprint. As a silly example, if you gave all users the same fingerprint, it would be very consistent but also useless as a tracking method.
- jamespking 4y agoOn the demo they have previous visits from your fingerprint listed (so you can get an idea of how common the fingerprint is... at least once enough people have tried the demo). Mine had two visits listed which are not mine when using Safari and private relay. On Firefox there were none (and it tracked in normal and private mode).
- lh7777 4y agoOn my iPhone, I was surprised to see I had made 20+ visits when in reality that was my first visit to fingerprint.com. It makes me feel better that my fingerprint isn't actually unique!
- aaronrobert 4y agoFrom my testing, this doesn't seem to work on Safari. But it actually works on Chrome. Another reason for using Safari instead of Chrome.
- aktuel 4y agoIf I have a certain phone model with updates applied. Is there something that distinguishes me from other people with the same phone and browser version other than the IP address?
- mdorazio 4y agoI, too, would like to know this and find it odd it wasn't mentioned at all. Most web traffic these days is from mobile devices, not desktops/laptops. And Apple at least seems to try doing a decent job of obfuscating trackable info by default on top of massive numbers of people having the same device (probably not true for Android).
- SV_BubbleTime 4y agoI have been trying Apple devices for an hour now. Nothing I can do gets them to pass the eff or linked tracker sites. Firefox, VPN, privacy extensions, nothing works. Apple has work to do.
- 29083011397778 4y agoLiterally the comment below yours mentions GPU fingerprinting (0). Regardless of whether you won or lost the silicon lottery, you're different enough to be tracked. (0) https://www.bleepingcomputer.com/news/security/researchers-use-gpu-fingerprinting-to-track-users-online/ https://www.bleepingcomputer.com/news/security/researchers-u...
- boomlinde 4y agoDo you have the same localization settings? The same timezone? The same browser settings? The same screen orientation? The same model of bluetooth headset? These are all likely factors in a client-side fingerprint.
- funstuff007 4y agoWe use web fingerprinting and adjacent methods to crack down on ID sharing for our SaaS that charges (per person). I make no apologies for this practice.
- msm_ 4y agoHow does that work out for you? This doesn't strike me as a good use of fingerprinting: - Since you charge per person, what about people that use multiple machines and browsers (with presumably different fingerprints)? - On the other hand, unless two people share the same workstation and computer account, how do you expect to use fingerprints to detect license abuse?
- funstuff007 4y agoWe use other signals as well: time of day, ip address, new cookie logs out old cookie. At the end of day we are dealing in probabilities, but we can definitely find the most aggressive sharers.
- deleted 4y ago[deleted]
- chrisMyzel 4y agoI find it scary coming back to the fingerprint.js site after years and still being correctly identified and see the exact dates I visited
- dinkleberg 4y agoInteresting, despite me not using a VPN, it has me “identified” in the totally wrong location (in fact, multiple wrong locations within minutes).
- msm_ 4y agoMaybe your fingerprint is just common? Location probably comes from geoip.
- jefc1111 4y agoIs anyone trying to tie users to multiple devices, and consequently identify both fingerprints as being from one user? I.e. Let's say I visit HN on both my laptop and on my mobile phone, each will have a very different fingerprint, but not only do I visit the same site on both devices but I am unlikely to do so simultaneously across the two devices, and there are likely to be other factors such as not visiting on either device during sleeping hours, not visiting on either device before some date (i.e. when I got into HN). Perhaps you could call this something like 'cross-device fingerprint unification', idk.
- domh 4y agoI think it would have to have some code that tied those two fingerprints together... something like `fingerprint.identifyUser("jefc1111")` which would then store both of those fingerprints against your user id.
- jefc1111 4y agoAnother technique you that could be used would be to look for distinct fingerprints that both have visited the same extremely niche web addresses. Someone is surely doing this already.
- thakoppno 4y agoWe did a demo at CES in 2015 which retargeted users on a secondary device. The demo delivered an ad-unit on mobile after viewing an ad-unit on TV.
- domh 4y agoI just tried to turn on `resistFingerprinting` in Firefox and it meant that my zoom preference for HN got reset every time I opened a new page (I have it set to 120% by default). Anyone know why? Bug?
- largepeepee 4y agoYou don't want to be fingerprinted means default options for everything Firefox can do it on
- domh 4y agoOhhh that makes sense! Meaning there's a way for a website to detect my zoom level? I wonder how? Checking calculated font size via JS or something? Ugh
- xkcd1963 4y agoI guess we could hijack our browsers to lie about the parameters that are being collected at the fingerprinting, that would be far more convenient than disable JS etc. EDIT: Or block the extraction
- giancarlostoro 4y agoAnyone know if there's been any forks of Chrome that enforce more privacy features? I know Chromium is a thing, but I doubt the builds for Chromium (except when tweaked by some Linux distros) do much like Firefox does. I only use Chrome to test some things, or to create a completely isolated browser session disconnected from my use of Firefox.
- Tajnymag 4y agoBrave, Iridium, Bromite comes to mind
- giancarlostoro 4y agoIridium sounds like it might be what I want, thanks!
- jonhohle 4y agoUntil everyday people realize they’re being stalked, I don’t know what will change. I am seriously thinking about trying to go through the proposition process in my state to forbid selling of data (this should already run afoul of wiretapping laws, imho). I thought having an ad campaign that targeted subgroups very specifically and boldly might be enough drum up public interest. Something like: “Hello $name from $city. How did $recent_embarrasing_purchase work out? I hope you enjoy your birthday in $birth_month.” And then a link to the proposed policy. Unfortunately, marketers have neither scruples nor the ability to control themselves and have captured an asymmetric advantage. Technologists do what they do, preoccupied with whether or not they could, not stopping to think if they should. It seems like legislation may be the only remaining option.
- A4ET8a8uTh0 4y agoI will admit that it always made me confused as to why browser has access to detailed hardware information. I can understand OS. I can understand resolution. I can rationalize GPU. I don't understand though why it should be able to access .. well, everything about the machine. edit: It is still impressive. Even with the firefox settings on, the website was able to identify me. I am not entirely certain how I want to approach this.
- SV_BubbleTime 4y agoI got me on iPhone through VPN change, clear cache, private window, and reboot. I know what to think about this… I fucking hate it.
- A4ET8a8uTh0 4y agoThat I can relate to, but the more immediate question is whether you are willing to adjust your habits to nullify its impact. Most people would not.
- DavideNL 4y agoSo i just found that the "SnowHaze" browser prevents fingerprinting on fingerprint.com and https://browserleaks.com/canvas https://browserleaks.com/canvas • https://apps.apple.com/nl/app/snowhaze/id1121026941?l=en https://apps.apple.com/nl/app/snowhaze/id1121026941?l=en • https://github.com/snowhaze/SnowHaze-iOS https://github.com/snowhaze/SnowHaze-iOS
- cmrdporcupine 4y agoFingerprinting is one of those things where there's really been a slippery slope we've just slid further and further down it over the last decade; back when I worked at an ad-tech startup (almost 15 years ago) I ran an experiment myself with our data to see if a simple hash of IP, browser agent, and maybe a couple other signals we had in our logs (don't recall) would co-relate with the cookies we already had through cookie matching from other sources. And the answer was: yes, about 95% of the time. Enough to be reliable enough to do basic retargeting without worrying about excessive false matches. But at the time, it was considered to be a big do not touch -- just don't do this. Not so much for ethical reasons, but for optics in the industry. (I wasn't proposing doing it, was just curious) In the meantime, though, this seems to have just become standard practice, but way more sophisticated with way higher accuracy, as this article touches on. What was not acceptable a decade ago is now "ok." Not just by sketchy ad startups, but by major players. But this whole mess ties back to one of the things that worries me the most about the propagation of LLM type ML out into the general industry. It's only a matter of time before ad targeting takes on an extra dimension of creepiness through this (and I'm sure it's already happening in some aspects, inside Google & Meta.) In the past, in ad tech & search, etc. people could say things like: "Yes, it's highly targeted. Yes we've co-related an absolutely huge quantity of data to fingerprint you exactly, and retarget you. But it's anonymized. No humans saw your personal data. It's just statistics.". Not saying whether or not this argument has merit or not, just repeating it. But now, here we are, where "just statistics" is a far more intricate learning model. One which is capable not just of corelating your purchases and browsing activity, but of "understanding" you, and which -- while not an AGI -- is pretty damn smart. At what point does "a computer scanned your browsing for patterns and recommend this TV set" become ethically the same as "a human read your logs, and would like to talk to you about television sets..."? Having worked in ad-tech before (and having worked at Google, in ads and other things as well), I do not trust the people in that industry to make the right decisions here.
- unrequited 4y agoAsking the wider audience here, I have uBlock origin installed on my Chrome browser, while I surf mostly on the incognito mode. I know this is no where close to an optimum setup, hence asking. What setup do you folks use to prevent the best you could from being tracked?
- royletron 4y agoI have a sort of love hate relationhip with this stuff. On the one hand, yes tracking me is bad if I am not aware, but on the other hand I work for a company that uses it's expert knowledge to help consumers purchase the right tools for them. Ideally we would like the end product to reward us for putting them in touch with the right customer that we've used our name to help land. Much like a hairdresser would recommend a certain brand of hairspray, or a mechanic who carries their preferred oil - there is always a need for a middleman 'tell Bob I sent ya!'. Obviously this an exception to a large majority of what tracking is currently in place for, but until we drop the whole 'tracking is bad we should just shut it all down', and start to think of a fair and reasonable way for users to say 'I am ok with company B knowing that I have a relationship with company A' then these increasingly nerfarious tracking efforts will happen.
- yjftsjthsd-h 4y ago> until we drop the whole 'tracking is bad we should just shut it all down', and start to think of a fair and reasonable way for users to say 'I am ok with company B knowing that I have a relationship with company A' then these increasingly nerfarious tracking efforts will happen. Given how companies have completely and utterly ignored the idea of consent banners, I am deeply disinclined to believe that most companies would ever actually be satisfied with a user controlled choice in the matter. Where we actually are is that companies will relentlessly attempt to stalk everyone all the time no matter what, and in face of that the only sane conclusion is that in practice tracking is bad and we should shut it all down.
- LeifCarrotson 4y agoActually valuable educational sales middlemen - making an individual aware of a tool that they didn't know existed but which solved a problem they already had - are such an infinitesimally small part of online advertising that those use cases can be completely ignored. This isn't a situation where one rotten apple spoils the whole bunch, it's more like one good apple inadvertently was dropped into a toxic cesspool of rotten apples.
- textread 4y agoEFF has an excellent tool to check your browser's fingerprint uniqueness:- https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ I use a lot of browser extensions. Unfortunately, this makes my browser easily identifiable.
- deleted 4y ago[deleted]
- throwaway202302 4y agoOh, finally I found an element of distinguation for the Iphone: The zoom settings in the display/brightness section of the iphone seem quite relevant for fingerprint.com algorithm. Toggling between standard/bigger text toggles the fingerprint value. This could be because the visible area in the screen size changes, as well as some value of the CSS-fingerprint.
- dcow 4y agoIn hindsight it’s clear. Why did we allow the web advertising mega corp to own the browser we use? Huge conflict of interest. There’s no way our privacy was going to survive.
- throwawayacc5 4y agoIs there a firecracker VM or something similar that comes preconfigured with a browser and VNC/RDP that can be used like a native browser but is running in a VM that's not fingerprintable?
- _Mobius_ 4y agoI tested this myself with librewolf and firefox. Librewolf that is supposed to be hardened and has resistFingerpinting by default couldn't stand a chance. The visitor ID was always the same in Librewolf. In Firefox the visitor ID was always different.
- AtNightWeCode 4y ago"Given there are companies selling fingerprinting as a service, if you want to really protect yourself from fingerprinting, you should use Tor Browser or Firefox with resistFingerprinting=true." Fingerprinting services tries to figure out browsing settings. Since very few people have this feature enabled. You might be easier to fingerprint by enabling it. A metric that historically been used for fingerprinting is the "do not track" feature which is a bit of irony.
- Operative0198 4y agoAs another vote against JS, this website is able to accurately tell at least half of the extensions I have installed on chrome. https://browserleaks.com/chrome https://browserleaks.com/chrome
- comfypotato 4y agoThis author doesn’t seem to know what they’re talking about. Just because the service generated the same ID for their Chromium sessions doesn’t mean that applies to all users’ Chromium sessions. Chromium just exposes more of their machine. My guess is that they, writing a computer-technical blog post, have a particularly unique machine. Even having 16Gb of RAM separates you from the masses and might make you unique depending on graphics card etc.. The fingerprinting discussion is relatively new. The first research paper’s author is only 35 or so. (Its title is Cookie Monster.) The discussion is also a little amusing on a site like Hacker News. A perfect example of someone who’s easy to fingerprint is someone who built their own computer (likely to be found on HN). On the opposite end of the spectrum, Safari iPhone users with the same model are impossible to distinguish. There’s a paper out there where the researchers worked with a public entity’s website to get more accurate fingerprinting data. There are very few unique fingerprints in reality and therefore no reason for any company to track them. This tech probably won’t ever identify users uniquely. There are actually some positive aspects of fingerprinting. Tor leaves a very obvious fingerprint, and it’s easy for banks to detect its use by criminals.
- npteljes 4y agoFingerprint.com gives me different IDs across different tabs, and also in private mode. I guess the privacy setup still works somewhat. The stack I use: - Firefox, Enhanced Tracking Protection ON - Multi-Account Containers + Temporary Containers addon - Privacy Settings addon, most settings private, but referrers enabled - uBO with lots enabled, Decentraleyes addon
- giuliomagnifico 4y agoIt would be nice to have also the Safari evaluation.
- OOPMan 4y agoTested fingerprint.com with Vivaldi Mobile and it didn't correlate me across a norm tab and an Incognito one, so it's not fool foolproof...
- throwaway202302 4y agoIs someone here working at apple? https://niespodd.github.io/webrtc-local-ip-leak/ https://niespodd.github.io/webrtc-local-ip-leak/ still? leaks local IP in mobile safari. On browserleaks local ip check fails, giving false feeling of safety.
- neop1x 4y agoIt is even worse than the OP realizes. They should run these EFF tests [1] to see how severe the problem is and that it is practically impossible to combat. [1] https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- DavideNL 4y agoStrange, `privacy.resistFingerprinting = true` did not solve the issue for me, i'm still fingerprinted by https://fingerprint.com/ https://fingerprint.com/. Even after clearing all cache and restarting Firefox. Adding the extensions `Canvasblocker` and `Temporariy Containers` did solve the issue though.