4 ms·
Let's face reality: as soon as you browse the internet, you will be tracked and identified. Here are just a few data points used for fingerprinting: IP address
by randomtoast 1y ago
Let's face reality: as soon as you browse the internet, you will be tracked and identified. Here are just a few data points used for fingerprinting:
IP address, User-Agent string, Referrer URL, Requested URL, Language, Locale, Screen resolution, Time zone, System time, Installed fonts, Installed plugins, Cookie data, Browser fingerprint, Canvas fingerprint, WebGL fingerprint, AudioContext fingerprint, Mouse movements, Click paths, Keyboard input timing, History sniffing, DNS queries, Destination IP addresses, HTTP traffic content, HTTPS metadata (host, SNI, timing), MAC address, Query parameters, Session ID, Login status, User account info, Geolocation (via IP), Geolocation (via browser API), Page interaction data, Time on page, Scroll behavior, Clicks, Form submissions, Browser type, OS type, Network provider, Client ID (\_ga cookie), Session ID, Timestamp, Pages visited, UTM parameters, Interaction events, Google Ad ID, DoubleClick cookie (IDE), Cross-site behavior, Cross-device behavior, Inferred demographics, Mouse tracking, Scroll depth, Video interactions, Audio interactions, Session replay, Keystroke logging, Facebook login status, Pixel events (Meta, LinkedIn, etc)
If you want to avoid that, you need to make a real effort (not just using DuckDuckGo). The Tails operating system might be a good place to start.
- edoceo 1y agoHow is the MAC collected?
- Arnt 1y agoThe WLAN AP collects that. They really track you (they being the AP and Google). You may assume that they collude, or not.
- 2716057 1y agoDepending on your network configuration I could imagine abuse of EDNS(0). This is used for example by NextDNS to identify which device (MAC) on your local network sent the request in order to apply specific filters and log the request. A not-so-friendly DNS could sell such information.
- johnisgood 1y agoI use dnscrypt with a supposedly secure configuration, is that not enough to counteract this?
- IAmBroom 1y agoAsk your friendly local CIA agent, not us. We don't have access to that intel.
- johnisgood 1y agoHow do you know? Someone might!
- blueflow 1y agoIt isn't, parent is making stuff up. Browsers do not offer an interface that is exposing that information. And remote servers are outside of your local network and thus cannot see these values, either.
- randomtoast 1y agoThat's true for browsers, but Google controls both the Android OS and Google Play Services, giving them access to hardware identifiers on Android smartphones. Given the broad adoption of Android devices and the potential to correlate data, this is not a case of "making stuff up." Even if your MAC address is spoofed/randomized, the remaining data points are still sufficient to track you.
- blueflow 1y agoDoesn't make sense to track and correlate the mutable MAC address when you have access to the burnt-in device serial number and IMEI.
- poisonborz 1y agoMAC is easily spoofed, most smartphones do it already by default - although only per session
- fn-mote 1y agoTo me just posting this long list is spreading FUD. It mixes voluntary user actions, like submitting forms and “query parameters”, with things like “WebGL fingerprint” which we agree is evil sneaky fingerprinting. I agree tracking is a serious problem, but this list isn’t contributing to any discussion.
- blitzar 1y agoPeople complain about google logging their search queries when they are in "incognito mode" and logged into their google account - we need a lot more education.
- johnisgood 1y agoWhat I would like is effective solutions against most fingerprinting.
- fsflover 1y agoTor Browser?
- johnisgood 1y agoBesides that? I want more (if they exist). :P
- fsflover 1y agoWhonix (which still relies on Tor Browser).
- sfebreiro 1y agoTails and Qube OS, for example
- deleted 1y ago[deleted]
- 1y ago
- mvieira38 1y agoThis list manages to be mostly correct while still spreading FUD. These can all be tracked, but the threat actors are very much uncoordinated in exploiting this info, and much of it (especially things like keystroke and mouse fingerprinting) is expensive to track en masse. Just using Firefox with uBlock, no history, and privacy settings on max, through a somewhat trustworthy VPN like Mullvad will make your data mostly useless. Yeah, "they" could still catch you in a million ways, but if your threat model revolves mostly around surveillance capitalism you'll just be too much of a hassle to matter