22 ms·
Why are websites requesting access to motion sensors on my desktop? (2019)
- dspillett 3y agoFingerprinting would be my guess. It could give at least one extra bit of data about your device (has motion sensors or not). Could also help detect agent string falsification: why would a device claiming it's UA is legacy IE have motion sensors?
- ericskiff 3y agoThat was my assumption as well, but the author makes a good case for it being an Akamai bot detection script designed for mobile responsive sites, and inappropriately implemented on desktop by these big sites.
- TomK32 3y agoBad code being copied from stackoverflow was my first guess as well.
- buro9 3y agoThat is still fingerprinting. Bots will either all have the same (or a low diversity of) fingerprint, or if not then they will have the same randomisation techniques to mask the fingerprint. Some of the additional browser features that access devices do reveal the most trivial way to determine "this is not a bot as bots don't have this fingerprint". Of course that has implications, if privacy makes you look like a bot (it does), then the web has more friction the more private one is.
- bombcar 3y agoIf you want to experience that, download Brave, open a Tor window, and try to do anything online. Now you’re playing botsimulater 2023.
- toastal 3y agoOr download the Tor Browser?
- didntcheck 3y agoI just use an "ordinary" consumer VPN service and it's bad enough. It really seems to have ramped up in the past two years, and now it's a daily occurrence to find a site which won't even serve me a response body when I connect via VPN
- repelsteeltje 3y agoWeb client to web server: I'm not sure I can trust you with my user's privacy, so I'm going to give you as little cookies/telemetry/side channels as I can. Web server to web client: I'm not sure your so-called "user" represents a real-life human user. Can you at least prove that you're a real-life web browser? Web client to web server: hmm, well okay, here's my User-Agent header. Just curious why you care about who's sending the request? Web server to web client: Still not convinced, can you give this CAPTCHA to your so-called "user"? As to you second question: bots, spam. And the ad network sponsoring me doesn't trust my tally. Web client to web server: My human hates CAPTCHAs, and AIs are better at it anyway. Web server to web client: Ghrmbl. Okay let me talk to Widevine/FairPlay/PlayReady DRM or your microphone/gyroscope/battery level/uptime/... ... The arms race of surveillance enshittification.
- petespeed 3y agoHow difficult would it be for a bot developer to write avoidance to such detection?
- danielbln 3y agoJust slightly more difficult than punching "give me javascript that returns fictional but plausible motion sensor data to a website that asks for it, to spoof that we are on a device that actually has a motion sensor" into ChatGPT.
- petespeed 3y agoFrom the text, feels like user agent should be capable, it should let site request sensor data and randomly reject certain requests after X (random) seconds, while providing fake data in other cases.
- guidedlight 3y agoI understand that Akamai’s new bot manager does more than just grab telemetry data. It’s more like a captcha for browsers, i.e. if the user is using a real browser it should behave in a way that pre-scripted bots can’t easy replicate. The payload is auto-injected by Akamai so the expected behaviour can be altered in a non-deterministic way.
- mordae 3y agoJust record couple hours of phone usage IMU data and then feed it to them with random segments added together and they won't by any wiser. Or just rock the phone in it's cradle. There are companies with robots tapping the screens, adding some rocking movements is not going to be that hard.
- phyzome 3y agoExtremely easy. You use a headless browser. This is already used heavily for automated testing.
- 3y ago
- motbus3 3y agoIt is time to make it illegal. It is clear that we need ways to keep our privacy and they are making even creeper ways to bypass. This is already 1984 level of privacy invasion
- pavlov 3y agoThe clocks were striking thirteen, and Winston Smith was irritated by a pop-up in the corner of his telescreen asking for permission to measure the room temperature.
- bottled_poe 3y agoBravo. Freedom is not taken with a booming voice but a tide of whispers.
- phailhaus 3y agoI think that was poking fun at OP, because the idea that asking for permission is "literally 1984" is pretty funny.
- pavlov 3y agoWell, kind of both? It was a joke, but the “tide of whispers” sentiment is not wrong either. It’s fun to imagine a “1984” prequel that would take place in an era when the Party is not full-blown totalitarian, and the telescreen pretends to be a useful information source that asks for permissions so it can better serve you. “1969”?
- jowea 3y agoWhat about "2023"?
- yakubin 3y agoAt first I read that as “Winston Churchill”, which made it sound like a Doctor Who episode.
- deleted 3y ago[deleted]
- everdrive 3y agoThe more important question would be why does your web browser _ever_ need to be aware of your motion sensors?
- sofixa 3y agoSame as webUSB, webGPU, etc. - to allow for web-based applications that make use of motion sensors without having to develop a full-on mobile application. A good example was the Stadia flashing software which is just a website that uses webUSB.
- FireInsight 3y agoAn example for the sensors is AR; I've built web-based AR experiences and the underlying toolkit usually requires some access to device sensors.
- Zambyte 3y ago> without having to develop a full-on mobile application It sounds like you have developed a full-on mobile application at that point.
- sofixa 3y agoWithout all the hassle of a developer account (which costs money for Apple's walled garden), having to pass through reviews, updates being slow to roll out, etc. And I'm fairly sure it's easier to write an HTML page with a couple of lines of JS using webUSB than it is to develop a mobile all with all the boilerplate.
- bombcar 3y agohttps://experiments.withgoogle.com/lightsaber-escape https://experiments.withgoogle.com/lightsaber-escape
- mbork_pl 3y agoWhat is it supposed to do?
- 0xcb0 3y agoBecause web developers are sometimes lazy and copy code and think it will and should work on all devices. It would take a whole `if` statement not to do it.
- toastal 3y agoOr marketing/management is making them. You can only have the energy to push back against so many things.
- JohnFen 3y agoProbably so. Still, that doesn't absolve the devs of blame here as well.
- toastal 3y agoI would agree. Too often they are folding like lawn chairs. I push back against a lot of ideas, but I have my limits too. In the case of adding all of this invasive fingerprinting, it’s not really acceptable.
- 38 3y agowhy in gods name does FedEx of all websites need motion sensors, on any device?
- zeta0134 3y agoAh, this probably also explains why a bunch of sites have started requesting Speech Synthesis capabilities on Firefox, which it blocks (yay) but notifies about each time (less yay). I figured it was fingerprinting or some other nonsense.
- trustingtrust 3y agoA while back I stumbled upon google chromes privacy settings and found things like serial port on your computer to be accessed by websites. Turns out google has thrown everything in the mix because they probably want their 'Chromebook' users like children in school to use motion sensors for convertibles to maybe play games via a browser. Websites are just taking advantage of these things. The chrome browser has ruined the internet.
- afavour 3y agoI guess I don’t know how you got from A to B there. I love the idea of kids being able to experiment with serial ports (though I’m not sure what you mean in that context, WebUSB?) in a safe, locked down programming environment. Ideally it wouldn’t mean random web sites request motion data from you but I really don’t see this as ruining the internet.
- xyzelement 3y agoThe browser is essentially the operating system for most computing today so access to peripherals is reasonable. My current job uses USB security keys and I assumed I'd have to configure them in the OS before the browser was aware of them -nope! Chrome knows if the key is in the USB port and can interact with it with my approval, which is exactly right. The leap from access to USB to access to serial is minimal. As long as the right permission checks are in place.
- sznio 3y ago>The browser is essentially the operating system for most computing today so access to peripherals is reasonable. Sure, but the fact that browsers became operating systems is unreasonable in the first place.
- realusername 3y agoSeeing where the mobile world goes, I still prefer my browsers, at least I can modify the websites as I want. Sure it's not great, but the alternatives are worse.
- deleted 3y ago[deleted]
- cornholio 3y agoOr we could apply Hanlon's razor: someone probably copy pasted some magic code from Stack Exchange that grants them access to "everything" to solve any and all problems in perpetuity. Wham, bug fixed, another 10x day.
- dclowd9901 3y agoHanlon’s razor in this case is a marketing manager who signed up for an analytics service and had one of their marketing dev flunkies throw the script up on the base page template for the site at the ignorance of the actual application developers. The application developers one day notice that we have no less than 10 different tracking pixels blocking page loads and eating page performance to death (not to mention sending tons of tracking data out to god knows where). They do a git blame, call the marketing manager into a meeting, who doesn’t know what anyone’s talking about because that was “years ago” and just gives permission to delete all of them. Then she comes back a couple days later upset because heap stopped reporting.
- _fat_santa 3y agoVendors, vendors, vendors. I work on one of the sites listed in the article and it's shocking how many external vendors they have for various things. Stuff like this is always a vendor adding in extra functionality.
- alt227 3y agoThis is blatently used for device fingerprinting. Maybe this wasnt a big thing back in 2019 which is why he doesnt mention it?
- karaterobot 3y agoNear the end, he tosses it out as a possibility. It certainly seems like the simplest explanation, doesn't it?
- nick_jackson 3y agohow is it being used for device fingerprinting? I don't understand
- avery17 3y agohasMotionSensors: 1 or 0. Add 20 more bits of info and you have a pretty decent fingerprint.
- nimbius 3y agodue to the increase in fingerprinting protection showing up in more and more browsers, advertisers are getting rather desperate to perform the ritual of establishing unique clicks. youll also see "enable DRM playback" on many news sites or aggregators. both of these actions are user-hostile attempts from not-google to target ads to you.
- rsaxvc 3y agoAliveness testing for mobile bot farms that got left on for desktop?
- mcbrienollie 3y agoIf the website contains a protection system such as Cloudflare, Perimeter X or similar, they run a small software in your browser called Challenge (which you might seen in Cloudflare also). This software is trying to understand if you are a bot or not by executing a series of internal functions on the browser which is also called Fingerprinting. They usually go hard on microphone, motion sensors, camera, location, navigator (language etc), WebGL and other similar technologies. Bots usually does not contain these functions. In my opinion, that would be the main reason for it.
- phneutral26 3y agoWow, what an interesting find. I think it's a really big stretch to request sensor data just for detecting if the user is a bot. Oh, and please add [2019] for clarity, thanks.
- flenserboy 3y agoIt's crazy that outside sites have the ability to know a system's capabilities. That info should only be available if the user makes it available to be known, &, as the baseline, all connections to one's system should only know that there is something there capable of receiving data — with no restrictions on connections for systems that do not choose to unlock this or that info about themselves.
- yar2987493 3y agoThe more I read about stuff like this, the more the idea of 'the browser' becoming the operating system starts to feel more real by the day. If you consider the stuff Google, microsoft or apple, etc do, claimed to be doing, being suspected of doing. I don't consider this to be a very positive development.
- agentultra 3y agoFingerprinting. Every w3c specification that adds features to the platform adds more unique data that can be used to identify you. They try to add security to the sandbox to make sure the user has to give permission to the website to use these APIs but it's always a cat-and-mouse game to make sure that there are no ways to break out of the sandbox and to educate users about what all these modals and features mean. Websites are getting obnoxious these days. Most tracking software on them will trigger all kinds of authorization modals for various APIs. And you can bet there will be a bunch it will try to use without authorization if there's a work-around. It's all fingerprinting to sell data.
- nick_jackson 3y agoI don't understand, how does me buying a product X on A result to me getting ads on B? Like how is the connection established between A and B? Sorry Im new to API's and programming in general but this is very intriguing
- codethief 3y agoNote that motion sensors can, in some cases, be used as a microphone: https://www.kaspersky.com/blog/non-standard-smartphone-wiretapping/47113/ https://www.kaspersky.com/blog/non-standard-smartphone-wiret...
- Animats 3y agoAnnoy Akamai by making a formal request under California law for any information collected from sensors in your device.
- xg15 3y agoAt this point I'm kinda glad Samsung has already patented the "use a builtin camera to track how many people are sitting in front of the TV" tech, because otherwise I'm very sure we'd soon be seeing it in every new device with a camera.
- fithisux 3y agoSoon they will request you your SSN to login