6 ms·
On Google’s Policy Change Towards Fingerprinting
- jqpabc123 2y agoThe simplest, readily available solution ---use Brave or LibreWolf. These can't prevent all fingerprinting but they can make it less reliable and more difficult and costly for a fingerprint to be relayed back to the mother ship. Personalized advertising is one of the dumbest ideas of the 21st century. Studies show it is less effective than context sensitive ads and it costs more. Participants in ad auctions are essentially flying blind with little reliable, verifiable insight into the process.
- dewey 2y agoSimplest solution is Firefox or Safari, not another Chromium browser or niche Firefox Fork.
- tholdem 2y agoIf security is not that important, Firefox or Safari. If you care about security, Chromium.
- dewey 2y agoAny widespread recent security issues that were only affecting Safari and Firefox? That sounds like scaremongering to me.
- timtom123 2y agoYes, there was a big one for FF in Oct https://nvd.nist.gov/vuln/detail/CVE-2024-9680 https://nvd.nist.gov/vuln/detail/CVE-2024-9680
- dewey 2y agoAnd Chrome had one with severity "High" just three days ago, browsers will always have security issues that seem to be patched reasonably fast in the big three. Might as well pick one that's not part of the monoculture by a big advertising company, depending on your threat model of course. https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/01/stable-channel...
- tholdem 2y agoYes all software will have security issues, but Chromium is much harder target to exploit than Firefox.
- fsflover 2y agoUsing Firefox on Qubes OS. Show me any good attack vector affecting me.
- tholdem 2y agoQubesOS is great if you need to do work and personal stuff on the same computer. I do most of my stuff in the browser and have a separate computer for work. I am mostly interested in making initial access as expensive and difficult as possible. You are still just as vulnerable or more vulnerable to malware stealing browser sessions, passwords, and everything you have on the AppVM the browser is running on than you are on a regular Fedora Workstation. Unless you only use disposable VMs, which you probably don't. If QubesOS had hardened templates, I would use it. When I used it, SELinux was not enforced, and I believe it still has passwordless sudo. Not sure what other mitigations are disabled in the default templates compared to regular, non-QubesOS Fedora Workstation.
- fsflover 2y ago> QubesOS is great if you need to do work and personal stuff on the same computer This is significantly underestimating the benefits of Qubes. Are you using your online banking in the same browser that you use for random web surfing? I do it in separate VMs with hardware isolation. Same compartmentalization with all other things. > You are still just as vulnerable or more vulnerable to malware stealing browser sessions, passwords, and everything you have on the AppVM the browser is running on than you are on a regular Fedora Workstation This is not true. I'm not using the same VM for everything but dedicated VMs for bank, email, HN, instant messaging and so on. A malware on a random website would only get the access to an empty VM, nothing more. Passwords can be securely saved in the related single-purpose browsers and in a plain text file (in an offline VM). > If QubesOS had hardened templates, I would use it. You misinterpret the Qubes' approach to security. If your VM is compromised, no hardening will save your data (https://xkcd.com/1200/ https://xkcd.com/1200/). On Qubes, you should compartmentalize your digital live into security domains, such that you never run anything untrusted in trusted ones and never have anything valuable in untrusted ones. With such approach, hardening is irrelevant. More examples: https://www.qubes-os.org/news/2022/10/28/how-to-organize-your-qubes/ https://www.qubes-os.org/news/2022/10/28/how-to-organize-you... > Unless you only use disposable VMs, which you probably don't. I don't understand why one wouldn't use them for everything not requiring saving the data. Of course I do use them and wrote this comment from one. More benefits: https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15 https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15
- bobajeff 2y agoSimplest solution is to not use computers anymore. Move to a cabin in the woods, away from civilization, and live off the fat of the land.
- fsflover 2y agohttps://news.ycombinator.com/item?id=27897975 https://news.ycombinator.com/item?id=27897975
- iLoveOncall 2y agoAh yes, Brave, the browser that highjacks websites to inject their own referral code, that's the right browser to use for privacy conscious people.
- LightBug1 2y agoWhat's your suggestion? Genuine question. I'm on Firefox.
- SlimyHog 2y agoFirefox.
- jqpabc123 2y agoAhh, yes. The browser that tags every install with a unique identifier.
- NemoNobody 2y agoFF is too slow. Brave is where it's at. I do wish I paid for Brave but again - I don't see ads online so I don't what they do with my information anyways. I don't wonder about Google or Microsoft.
- i_love_retros 2y agoGot any more info on this?
- jqpabc123 2y agohttps://www.ghacks.net/2022/03/17/each-firefox-download-has-a-unique-identifier/ https://www.ghacks.net/2022/03/17/each-firefox-download-has-... This data will allow us to correlate telemetry IDs with download tokens and Google Analytics IDs.
- NemoNobody 2y ago
- nine_zeros 2y agoUse Firefox. Consumers need to wean away from spam companies.
- Hizonner 2y agoNo browser is immune to fingerprinting, or even a little bit hard to fingerprint.
- xnx 2y agoWouldn't Safari on iOS put your browser in a crowd with millions of other people?
- jqpabc123 2y agoNo --- because fingerprinting techniques can detect subtle manufacturing differences in the underlying hardware. Even identical models of iPhone have minor variations in hardware and configuration and will produce different fingerprints.
- Hizonner 2y agoNo. Not unless every other aspect of browser, many aspects of the computer, and many ways you can configure them were identical with every other user. In fact, Safari narrows you way down all by itself.
- jqpabc123 2y agoTrue --- but incomplete. Browsers can block known sources of advertising and fingerprinting code. It's hard to produce a fingerprint when the browser won't load the code.
- hilbert42 2y agoPerhaps so, but with JS disabled, Chrome uninstalled and all Google apps disabled and or removed together with a myriad of other tweaks including phone rooting, regular rebooting of routers to change IP address as well as using multiple different IP providers seems to minimize the problem. Can't remember when I last saw an ad (except for some static one within the page), and the last time I actually clicked on an ad was about 20 years ago. Oh and BTW, I use a dumb/feature phone for telephone, my smartphones have no SIMs and they connect to the net via a WiFi router (usually a pocket type), and no email is sent from smartphones. Nor do I use any social media (perhaps one if by some stretch HN could be classified as one). And Gibson Research's ShieldsUP can't find anything of note. Finally, without JS the web runs like a grayhound. Sites that break without it are not worth visiting anyway (and they're usually the worst privacy offenders). I've no need of them, as they say, there are pleanty more fish in the sea. All this nonsense is only a problem if you expect something for nothing and or like the trinkets and pretty baubles Google pretends to offer for free. PS: and I don't send or receive email from those who've gmail addresses. Boycotting those with gmail addresses sends a message that one is actually serious about privacy.
- fidotron 2y agoHe may or may not want the attention, but https://ladybird.org/ https://ladybird.org/ is coming along surprisingly well. In the meantime Safari/Firefox as appropriate. It's a shame really, because as a piece of software engineering Chrome is incredible.
- 2OEH8eoCRo0 2y agoIs it though? Or is it a monolithic rube Goldberg machine of lock-in?
- gr4vityWall 2y agoV8 is amazing.
- 2OEH8eoCRo0 2y agoYeah but I should be able to swap in any JavaScript engine I desire or use one provided by the system. Browsers are far too bloated.
- Dalewyn 2y agoPlaying Devil's Advocate, maybe browsers are still too incomplete. Once browsers are the operating system, everyone can simply speak Chrome and be done with it. The success of Electron strongly suggests both devs and users want to singularize on Chrome, so why not take it to the logical conclusion? Chrome is the abstraction layer to WindowsMacOSiOSLinuxAndroidBSDx86ARMRISC-Vspaghettisoup.
- 2OEH8eoCRo0 2y agoElectron is only successful because it saves development time compared to native applications, not because it's good for users.
- NemoNobody 2y agoBrave is better.
- Hizonner 2y agoI guess it'd make a difference if anybody'd been following the policy or Google'd been doing anything effective to enforce it. I find this, um, improbable.
- xnx 2y agoThis seems like nothing. Had Google ever enforced or even inspected its ad partners for use of fingerprinting? My assumption is that every site that knows how to do fingerprinting is doing fingerprinting and probably deanonymizing against a shared signature database.
- NemoNobody 2y agoExactly. There is not anon browsing bc of a browser - you have to do a lot more than a browser to be anon online these days.
- fsflover 2y agoHow about the Tor Browser?
- Hizonner 2y agoVery hard to link with your name or other elements of your "real identity" (unless you ever give them out over Tor). Probably only slightly hard to link all the things you do using a given installation of the browser to each other. They do at least try, but it's still basically Firefox, and it's not clear that it's even possible to make an unfingerprintable browser.
- deleted 2y ago[deleted]
- gr4vityWall 2y agoMy guess is that the way aggressive captchas and similar tools work these days is fundamentally incompatible with the original wording in Google's policy. Doesn't make it any less sad, though. The web is very hostile to the end user these days.
- deleted 2y ago[deleted]
- Hizonner 2y agoWhat is with everybody suggesting this or that browser? They're all going to be fingerprintable. Using a less common browser just makes that easier... not that it will ever be hard. You might get some relief from some tracking, including via fingerprinting, by using comprehensive ad and tracking blockers. Or you might not, since CDNs are still probably going to track you.
- fidotron 2y agoIt is because Google want a situation where they have a monopoly over being able to track web users, and Chrome is a major part of that. Because that is so blatantly anti competitive the adtech industry manipulates it into a sort of war of opaque identifiers (“user resettable device identifiers”) , attached to things like Roku, smart TV and phones, which then can be passed along with bid requests for ads and later used to effectively target people even on other devices in the same household, conveniently only by some players in the adtech world who then charge more. Breaking the Chrome monoculture will not solve this problem by itself, but it is a necessary step in getting there.
- Hizonner 2y agoYou're not going to even improve the problem without completely shutting down the entire "personalized" advertising industry. Which I'm totally on board for, mind you.
- fidotron 2y agoThat is true, and part of that would have to be enabling people to make money from web type content without shoving ads in it (or it being an ad for something else). My personal, controversial, conception of the future is to return to the notion of the Internet as a network of other networks, and then enable devs and content creators to sell apps and experiences which operate privately within those networks.
- Hizonner 2y ago