5 ms·
>CGNAT? ISPs and websites can still track you. Yes, ISP's can still track but the other websites-that-are-not-the-ISP that depend on logging unique ip addresse
by jasode 2y ago
>CGNAT? ISPs and websites can still track you.
Yes, ISP's can still track but the other websites-that-are-not-the-ISP that depend on logging unique ip addresses for tracking can't identify you behind a CGNAT. My previous comment about how CGNAT can be another layer of privacy for things like torrents: https://news.ycombinator.com/item?id=38176079 https://news.ycombinator.com/item?id=38176079
EDIT reply to : >Sure except for the like 800 other metrics they use to track you besides IP lol. Advertisers
Yes, browser fingerprints and "device behavior" heuristics etc demonstrated at https://amiunique.org/ https://amiunique.org/ and https://fingerprint.com/blog/browser-fingerprinting-techniques/ https://fingerprint.com/blog/browser-fingerprinting-techniqu... ... also exist but that's not what my reply was about.
My comment was specifically talking about those websites that depend on ip addresses and not fingerprinting. Examples are torrent trackers, torrent honeypots, and Wikipedia articles' edits history where their server logs keep track of ip addresses instead of browser fingerprints. CGNAT will make users more anonymous in those situations. Lawsuits and subpoenas from RIAA and movie studios against torrenters for copyright infringements were filed against ip addresses and not browser fingerprints.
As for Google/Facebook sophistication levels of browser fingerprints tracking and surveillance, I'm not so sure how paranoid I should be about it because they still think I'm in Idaho because I happen to open my laptop in a hotel one time there 10 months ago.
- datascienced 2y agoYou can have a different IPv6 every minute if you like. They are plentiful! Maybe have a fixed one for your web server too.
- alduin32 2y agoThat different IPv6 will still identify the subscriber, because it will have a shared prefix, usually statically allocated by the provider.
- datascienced 2y agoThat shared prefix would be no worse tban a shared IPv4. Unless the shared prefix is per user and immutable.
- beagle3 2y agoFor every ISP serving my area, it is indeed a "per customer, immutable" prefix. IIRC, some have a 96-bit prefix, some have a /64, but that's the kind of thing that a "maxmind" style database of prefix length per isp lets you nail down easily -- if those databases don't already exist today, they will soon. It's easier for the ISP to do it that way.
- cchance 2y agoSure except for the like 800 other metrics they use to track you besides IP lol. Advertisers don’t need your ip to track anymore
- beagle3 2y agoFor many people, that’s true. But not for those who care. The other metrics are under my control, and I actively scramble them to uselessness. An IP address … I can’t do much about.
- everforward 2y agoNo one “depends” on IP addresses. Wikipedia could very easily (and likely does) use browser fingerprints for some things. They don’t serialize to something human-readable, though, so I wouldn’t expect them to appear anywhere but debug interfaces. IPs havent been a viable way to ban or identify people since the early 00’s. For sure with the launch AWS, and the ease of swapping IPs there. It’s been laughably easy to swap source IPs on requests for at least a couple of decades. I think the only people you’re getting privacy from is people who didn’t really care enough to invade it in the first place.
- jasode 2y ago>No one “depends” on IP addresses. Wikipedia could very easily (and likely does) use browser fingerprints One of the tools Wikipedia gives admins to protect pages from vandalism/abuse is ip address blocks and not browser fingerprints: https://en.wikipedia.org/wiki/Wikipedia:Blocking_IP_addresses https://en.wikipedia.org/wiki/Wikipedia:Blocking_IP_addresse... >IPs havent been a viable way to ban or identify people since the early 00’s. You are factually wrong. Copyright holders have successfully won lawsuits as recently as 2023[1] by starting the process via subpoena of ip addresses from ISPs. The steps are: 1) obtain the ip addresses of anonymous users torrenting your intellectual property. (Because the studios monitor torrent trackers for ip addresses.) 2) Connect a real name to that ip address by having a court subpoena the ISP to reveal the owner of the ip address. If the ISP subscriber on the account is not the actual infringer, ask the owner of the account (via a court deposition) to further identify the actual user (e.g. a spouse, a roommate, etc) 3) get a financial settlement or judgement against that person That type of identity unmasking doesn't happen with CG-NAT or other shared NAT scenarios like libraries/airports because the torrent trackers logs only have granularity of ip addresses which is useless when a thousand people share it. [1] April 2023 defendent loses $27016.25 in lawsuit via ip address unmasking: https://casetext.com/case/strike-3-holdings-llc-v-john-doe-subscriber-assigned-ip-address-133 https://casetext.com/case/strike-3-holdings-llc-v-john-doe-s...
- everforward 2y agoTelecom operators have admitted to being able to identify people through CGNAT since at least 2015 https://torrentfreak.com/pirates-can-be-identified-despite-sharing-ip-addresses-isp-claims-130515/ https://torrentfreak.com/pirates-can-be-identified-despite-s... You just have to have the source port as well as IP instead of just the IP (which the MPAA et al surely gather). CGNAT is basically just port-based DHCP; it still has to keep an inventory of what ports are available, practically requiring the ability to tell who was using what port at what time. Even from a first principle's perspective, if they can't identify subscribers for relatively benign things like piracy, they also can't do it for something like CP. Those logs 100% exist, if only so the telecom has something to turn over when the FBI comes looking for pedophiles. > One of the tools Wikipedia gives admins to protect pages from vandalism/abuse is ip address blocks and not browser fingerprints: https://en.wikipedia.org/wiki/Wikipedia:Blocking_IP_addresse https://en.wikipedia.org/wiki/Wikipedia:Blocking_IP_addresse... And yet that very tooling will detect if a hard-blocked user tries to log in from a new IP address and block that new IP address. It's almost like IP address blocking doesn't work very well... You're of course free to do what you want, but it seems naive to me to assume that anyone operating even a moderately popular site isn't browser fingerprinting. Even if the site isn't, CloudFlare will if they use CloudFlare (and I wouldn't be surprised if other CDNs).