12 ms·
Google starts tracking all your devices in 8 weeks
- hulitu 2y ago> Google Starts Tracking All Your Devices in 8 Weeks Those "journalists" were living in a bubble ? Google (and Facebook, and Apple, and Microfost) have been tracking our devices for years.
- thomassmith65 2y agoThe article is about Google's new focus on tracking users via device fingerprint, instead of (primarily) via cookies.
- conartist6 2y agoWhich is, depending on your perspective, either terrifying or just stupid. Right now anti-fingerprinting security is not very high on anyone's minds, but remember that your digital fingerprints follow you EVERYWHERE. You can't turn them off or disable them on your side like cookies. It's sort of like the wholesale elimination of privacy as a concept, you might say. But hence the stupidity! It's too bold a move not to elicit a reaction from developers and users (who have the power to discover just how many bits of information they are leaking about themselves using tools like https://pbtest.org/ https://pbtest.org/). So on one hand I can have websites that offer richer functionality by being aware of my time zone and locally installed fonts, or on the other hand I can have privacy. Hmm, which is worth more?
- uzername 2y agoIt's unfortunate that the pbtest.org tool links out to a service with an expired cert.
- everybodyknows 2y agoAlternative: https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- somedude895 2y ago> Your browser fingerprint appears to be unique among the 183,020 tested in the past 45 days. Damn how is this possible when I'm using a stock iPhone? I look at the characteristics and apart from timezone and language, how can they tell the same model iPhone apart?
- ndriscoll 2y agoTIL about Web Audio, an API that allows any web page to find out about the user's sound setup (e.g. channel count and some kind of transfer function of the audio subsystem?) despite there being no legitimate purpose for that.
- popcalc 2y agoIs it really a surprise it gets implemented when all browser development outside of Webkit is financed by Google Ads revenue?
- deleted 2y ago[deleted]
- mistrial9 2y ago
- southernplaces7 2y ago> but remember that your digital fingerprints follow you EVERYWHERE. You can't turn them off or disable them on your side like cookies. I'm honestly curious, if you don't mind clarifying a bit more. How do your digital fingerprints follow you everywhere without your being able to erase them? This thread goes into device fingerprinting, but if one rigorously changes devices and certain use/account practices, how can they still be tracked so totally?
- dwattttt 2y ago> if one rigorously changes devices and certain use/account practices Your account practices will need to include only using an account on one device. Every time you use an account that identifies you on a device, that device can be associated to you; at that point its fingerprint is your fingerprint. Rotating devices faster just adds more devices to your identity.
- treprinum 2y agoTor browser asks you if you want to allow fingerprinting or not when a site attempts to query your HW info. Not sure why other browsers can't do the same.
- rrr_oh_man 2y agoThe problem with Tor browser: You’re that guy with the Tor browser. https://xkcd.com/1105/ https://xkcd.com/1105/
- Macha 2y agoThis isn't new. Most advertising companies have had some sort of "Cross device targeting" or "household targeting" solution for going on almost a decade now. It's also why the suggestion of "repeal GDPR, just use cookie blockers" is so misguided.
- skybrian 2y agoThis article doesn’t explain what change Google is supposed to be making and they don’t link to anything that explains it either. (There is a link to what seems to be to a policy change for the ads platform.) Does anyone know what they’re talking about?
- hedora 2y agoRead it more carefully (it is easy to miss). They’re going to start using and allowing third party device fingerprinting throughout their ad ecosystem. This is obviously illegal in Europe, the UK and California (no consent), and an unnnamed regulator warns that it intends to take action.
- skybrian 2y agoSince it’s a policy that Google’s advertisers have to agree to, it seems like it’s silent on whatever Google might do themselves? (Yes, that’s contrary to the headline. That’s why I find it confusing.)
- esskay 2y agoI assume it just won’t roll out to those locations. The EU would take Google to the cleaners (again) if they knowingly ignored EU law.
- ghostwords 2y agoCurrent "Platforms program policies": https://support.google.com/platformspolicy/answer/3013851 https://support.google.com/platformspolicy/answer/3013851 >You must not use device fingerprints... Compare to the update: https://support.google.com/platformspolicy/answer/15738904 https://support.google.com/platformspolicy/answer/15738904 [no mention of device fingerprints] >The changes... [are] less prescriptive with partners in how they target and measure ads.
- hedora 2y agoSo, if I use a device that doesn’t support tracking, and they track it anyway, how do they get it to present the “do not sell my personal information” button? Also, are there any decent plugins that block all of google instead of just the ads? I imagine they’d need to MITM static font assets, etc. I also wonder if / when this means Google will start fingerprinting and tracking tenants’ customers on GCP.
- TheBozzCL 2y agoPersonally, I went the nuclear route with a Pihole. My devices can’t talk to Google.
- timbit42 2y agoWhat if they use IPs instead of domain names?
- TheBozzCL 2y agoThen you write router-level firewall rules for the IPs you know are safe to fully block. You can do that selectively so you don’t break other devices. I already do this for local DNS circumvention, which is probably a lot more common than hardcoded IPs.
- timbit42 2y agoRight, but Pi-Hole can't help with this.
- chgs 2y agoPresumably you set your router to intercept all UDP/53 traffic, but remember the whole point of DoH is to prevent that and ensure nothing gets between the advertising surface and the advert source.
- TheBozzCL 2y agoThat’s why I also block all known DoH IPs. It’s a pretty long list, like 130 IPs. I have an allowlist for devices I don’t want to mess with, like my Pihole or guest devices. It’s definitely not perfect, but it does de job for now.
- unethical_ban 2y agoWe are cattle at the farm for Google. Not humans. Sources of a profitable product they can broker: attention and purchasing power.
- bdangubic 2y agojust google? :)
- mdaniel 2y agohttps://archive.ph/6TmKa https://archive.ph/6TmKa I wish HN would support creating snapshots on some sites by default
- mindslight 2y agoEvery browser information leak that can contribute to fingerprinting needs to be plainly considered a security vulnerability in need of fixing/mitigation, period. This class of vulnerabilities has continued to get a huge pass, only being taken seriously by projects like TOR browser and then still only the convenient fixes getting backported. I do realize this is a tall ask, as many of these vulnerabilities arise from standards promulgated by the surveillance industry itself (chiefly Google, of course), and so are not easily mitigated. For example font lists and ask-to-use-microphone are straightforward to fix for general web browsing, whereas the fix for browser viewport size requires some kind of thoughtful design that subsumes the old model. In general I'd say that browsers (or at least their operating modes) need to start differentiating into different things for the open [season] web versus app runtimes, so that vulnerability mitigations can be stronger for the open [season] web and sidestep complaints that it disrupts legitimate apps. Of course the two modes need to be indistinguishable by websites, lest every two-bit xitter-summarizing "news" site insists that it's some special snowflake needing app functionality to run its surveillance code. Also since I'm apparently writing my Christmas list, we desperately need widespread privacy laws in the US. If you want a "value add" feature of your product to be shoving ads in people's faces, fine - people at least get immediate and actionable feedback from that. But persistent tracking supported by pervasive surveillance is completely at odds with individual liberty. And taking away the largest consumer surveillance market would mean much less being invested in new ways to attack users.
- tatersolid 2y agoThe Accept-Language header predates Google by many years, see https://www.rfc-editor.org/rfc/rfc1945#appendix-D.2.4 https://www.rfc-editor.org/rfc/rfc1945#appendix-D.2.4
- mindslight 2y agoI certainly did not mean to imply that every browser fingerprinting vulnerability is due to Google née Doubleclick. What did I say to make you think so? And from a technical perspective, Accept-language doesn't seem terribly hard to mitigate - exactly one language at a time, and UI that allows a user to easily change to another, as if it's part of the logical URL. It's all the javascript APIs, especially the graphics ones with their loads of weakly-defined behavior, that are especially pernicious.
- anythingelsenow 2y agoI have a script which runs a random browser in incognito mode with a random user agent and a random search website every time I click a shortcut. Then another script changes the DOH dns setting for my connection every hour. Next up I will set a socks proxy setting on each browser via command line params to a ssh connection located in Europe. Oh and I also change my computer name on every logon and have random hw address enabled.
- smitelli 2y agoAnd I use Firefox with uBlock Origin and really nothing else. I suspect everybody’s threat models and risk tolerance is a little different.
- GuestFAUniverse 2y agoTime to break them up.
- compootr 2y agobreaking up chrome would be a blunder though, because of their massive funding to mozilla, it could kill FF
- duskwuff 2y agoI believe Mozilla's funding comes from the search team at Google, not the browser team. (It's nominally compensation for including Google as the default search engine.) If anything, I'd be more concerned about Chrome, since it might be difficult for Google Search to fund Google Chrome to its current levels without raising arm's-length concerns (i.e. "is this a bona fide payment for services rendered?").
- em-bee 2y agogood, as long as chrome has such an overwhelming marketshare, reducing its funding sounds like a good idea. the companies that build on chrome can contribute to the funding to keep chrome alive.
- tomsel 2y agoit could most certainly kill Mozilla, but it will surely not kill Firefox
- xg15 2y agoGoogle's philosophy seems to be that intrusive tracking and behavioral advertising are OK as long as they only happen on the user's device. The result is a worst-of-both-worlds: To an end user, it will still feel as if you're being tracked, with ads following you around, etc, but no worries, your privacy is safe because the advertiser doesn't have access to the data...
- hedora 2y agoTo be clear, Google has the data, and despite acting like they allow opting out from tracking, they do not.
- datavirtue 2y agoYes, Google is positioning themselves to be the regulator.
- hyperman1 2y agoA few weeks ago, I was using my mothers PC. Google was erroneously in French, and no language chooser available. So I checked. Firefox sent a HTTP header with a Dutch preference. She was logged in with her Google account, which had a Dutch language preference. Some geolocation providers put her in Dutch speaking cities of Belgium. Still, the Google Algorithm had decided she would speak French. Plenty of other sites make similar errors, especially the biggest ones So I wonder: Why are we sending out all this info. Fingerprinting is the only actual use. The number of sites using it as it should is minimal. Lets just stop giving it. They don't need a list of audio or video devices. They don't need my installed fonts. They don't believe my language settings when I whack them over the head with it. Let's just fill in defaults everywhere. Maybe provide a whitelist for legitimate sites.
- Zak 2y agoSites preferring geolocation over Accept-Language as a means of picking the language is one of my pet peeves. Preferring geolocation over a logged in user's stored setting is beyond absurd.
- f1shy 2y agoWhen you think that 90% of browsing devices are phones or laptops… beyond any possible comprehension
- buildbot 2y agoWith weirdly sticky behavior too once you’ve left that area. My google sign in prompt was in Italian for over a decade after logging in there once on a family vacation. Only with the latest login revamp did that setting finally get purged. Everything else was always english, profile set to english etc.
- anal_reactor 2y ago[flagged]
- ElCapitanMarkla 2y ago
- neonate 2y agohttps://archive.ph/6TmKa https://archive.ph/6TmKa
- red_admiral 2y agoAdblocking google's ad ecosystem so the third-party scripts don't load in the first place should still fix this, if I read it right?
- rpastuszak 2y agoThis is getting trickier: - nowadays (iirc) you can serve/proxy those scripts via your own domain (to circumvent ad blocker blocklists) - there are limitations re the number of blocking rules in Manifest V3 It’s cat and mouse at this stage, we’re getting to the point where blocking ads will be as hard/annoying as, say, installing 3rd party apps on your iPhone. Too much of a hassle even for fairly techie users
- Macha 2y ago> there are limitations re the number of blocking rules in Manifest V3 Use Firefox. uBlock Origin on Firefox also gets around CNAME cloaking to make advertiser domains appear as first party, which Chrome does not give sufficient access to do that. It doesn't get around actually serving these endpoints mixed directly in with first party endpoints, but these are a hard sell on the advertising side too, from the technical effort from the publisher to implement it to the advertisers reluctance to trust the stats when the publisher gets to be the man in the middle.
- int_19h 2y agoI wonder if at this point an AI-based ad blocker that would actually look at the DOM, or maybe even the image, would be viable. Obviously, this requires significantly more resources. But it feels like a more productive use of the hardware power that we already have, compared to the most recent Electron monstrosity.
- rpastuszak 2y agoHehe, so I made a (semi) serious project in a similar vein some time ago actually: Https://butter.sonnet.io (Because you deserve butter.)
- Animats 2y agoDoes blocking Google Tag Manager help? The site you're talking to can still read your data, but most third party sites can be cut off. Privacy Badger will let you block Google Tag Manager, and while it warns you that some sites will break, few do.
- mukti 2y agoIts not clear to me how much this will help; but based on how tags work, it seems like it should help at least somewhat. I use Privacy Badger on both Firefox on PC and Android and haven't run into any sites that break, other than maybe something like Ticketmaster? I'm sure it makes less of a difference on an Android device, where Google has other hooks to track me, but any little bit helps.
- _heimdall 2y agoI don't think there's a universal answer there, it would depend on how accurately they can fingerprint you without GTM. Blocking it does remove an identifier that would make it easier, but blocking it is also a piece of data that could feed into the fingerprinting algorithm. It would be interesting to purposely feed a bogus GTM cookie though. It might actually throw their tracking and fingerprinting off if somehow you were able to send random GTM tags on every request.
- jocoda 2y agoWe have kernel level anti cheat systems for games. So how about kernel level anti tracking? Browsers use system calls to provide the information used for fingerprinting the device, so why not intercept these calls and lie. Have all users present an identical fingerprints and we're back to pre google times. Yes, we lose some important functionality, but maybe it's a price worth paying? Never mind the other elephants in the room that do worse than track your browsing habits...
- wibbily 2y agoI see this going in the opposite direction first - TPM-backed kernel level fingerprinting. Surely you have nothing to hide…
- 3eb7988a1663 2y agoThis is my conspiracy theory as to why Win11 made TPMs mandatory hardware.
- hsbauauvhabzb 2y agoThis page only works on digitally signed supported operating systems. Please consider migrating to a supported system by Microsoft, Apple or an Android device officially supported by Google.
- surajrmal 2y agoFingerprinting or attestation?
- RGamma 2y agoAttestation of working fingerprinting.
- surajrmal 2y agoIf you're running your workload on someone else's hardware (eg in the cloud) being able to attest it's not being modified is critical. From a companies perspective, when they run their software in the context of a customers hardware, it makes sense that they may similarly wish to ensure the software is running unmodified. This is how games are able to ensure there is no cheating occuring and banks can ensure malware is not tampering with the bank software unbeknownst to their customer. There are obviously ways for this to be use this for more distasteful mechanisms like fingerprinting, but that's not necessarily enough reason to abandon the technology. There are ways to achieve attestation without compromising privacy, but it does require widespread rollout of the attestation mechanism.
- 1vuio0pswjnm7 2y agoSource: https://web.archive.org/web/20241220192229/https://support.google.com/platformspolicy/answer/15738904 https://web.archive.org/web/20241220192229/https://support.g...
- Delmolokolo 2y ago[dead]
- 486sx33 2y agoHow do we disable?
- exabrial 2y ago>“also giving people the privacy protections they expect.” My expectation is you don't fucking store any data about me to be used for advertisements/AI/etc and everything is opt-in, period. Where is that option?
- K0HAX 2y ago"We will tell you what to expect, and you will like it."
- jokoon 2y agoI hope they catch terrorists and criminals with this
- timnetworks 2y agolollllllllllllllll here's $2.49 off a thing you're maybe likely to buy tho
- wobfan 2y agoOT but anyone else finds it ironic that we had multiple articles telling us how Forbes publishes AI generated articles way outside their expertise and still we're seeing Forbes articles regularly on HN? Like, I know that apparently this one is a personal blog, but why does anyone even set up a blog at Forbes. Sometimes I wonder about this. And actually, even when knowing it's a personal blog and me a serious, I cannot really take it serious anymore when seeing the Forbes URL. I am more inclined to skip chapters, to look for AI slop, and to not take the views of the author as independent. Not consciously, but subconsciously.
- ziml77 2y agoI don't even bother clicking on Forbes links anymore. Opinion pieces are fine but it seems like Forbes is entirely being used for the legacy of its name to make random blogs sound authoritative and respectable.
- EVa5I7bHFq9mnYK 2y agoSo what to do? Buy a Huawei device? Does Firefox's anti-fingerprinting help?
- Havoc 2y agoCombined with other news story [0] it sure feels like google is switching from trying to comply with regulation & instead doing what they want with a "Well what are you going to do about it?" attitude. Regulators really need to cut them down to size. Was bad enough during anti-trust era in the US...now we're dealing with multinational entities the size of countries. Can't let that get out of hand or we'll end up living under corporations not governments. [0] https://news.ycombinator.com/item?id=42482509 https://news.ycombinator.com/item?id=42482509
- datavirtue 2y agoCongress creates, empowers and funds regulatory bodies based on the demands of the people (voters, lobbyists). You either grant licenses to operate within a framework or you have to follow people around scooping up shit and work through the legal system as enforcement mechanisms. Big tech or big business very much prefers the scoop shit and fight it out in court method as it gives them a huge advantage.
- Andrex 2y ago> it sure feels like google is switching from trying to comply with regulation & instead doing what they want with a "Well what are you going to do about it?" attitude. I got one link for ya buddy. https://x.com/sundarpichai/status/1854207788290850888 https://x.com/sundarpichai/status/1854207788290850888
- dartos 2y agoThey weren’t before?
- datavirtue 2y agoSo Google's value proposition is to be the central tracking authority that knows who you are and enforces compliance on the advertising industry by keeping your name secret but letting advertisers know that: person x did this and then did that? How convenient.
- endoftheline 2y ago[dead]
- wkat4242 2y agoI'm so done with the advertising industry. They will keep trying to follow us. Not even because it works, but because it's Google's the other companies' moat. Only with their pervasive tracking networks can they sell tracked ads. If there was no tracking, anonymous content sensitive ads would be more popular and thus valuable. Unfortunately even Mozilla is now trying to appease advertisers with their PPA initiative. I don't want purchases to be attributed. I will continue blocking all ads forever and circumventing them in other ways possible (like pirating content and using paywall blockers). I'm done trying to fix the system.
- lakomen 2y agoI'm tired of the constant attacks on our privacy and sovereignty. Be it technical or political
- RGamma 2y agoAnd when shit really hits the fan, non- and "wrong"-usage of this stuff will make you a suspect. The Uighurs are a testing ground for total surveillance on- and offline already. Bad times...
- hxii 2y agoTime to tighten those PiHole lists. Then again, my workplace is using Google. Is there any relatively easy way of routing Google traffic via an intermediary, say a vps?