9 ms·
Web fingerprinting is worse than I thought (2023)
- coffeecantcode 1y agoWould be curious how Brave handles fingerprinting, I’ll have to look into that.
- torium 1y ago[dead]
- mitkebes 1y agoBrave has built in fingerprinting protection (https://github.com/brave/brave-browser/wiki/Fingerprinting-Protections https://github.com/brave/brave-browser/wiki/Fingerprinting-P...), that's enabled by default. It seems like it's less aggressive than firefox's though (since firefox's fingerprint protection is disabled by default because it breaks things), and it doesn't seem to be able to block this companies fingerprinting tech. I got the same ID in a regular window and private browsing window. The brave shields setting section also has an option for blocking scripts, which may work. It prevents the demo from being able to show an identifier for the user at all, but I'm not sure if it's preventing identification or just preventing the displaying of the identification.
- nilslindemann 1y agoI tried that site with Brave and it detected me. I was not able to escape fingerprinting with Brave, Firefox, Chrome, hardest settings. Only Tor works :-(
- t_mann 1y agoIsn't fingerprinting covered by GDPR in a similar way to how cookies are? So in theory you should be able to opt out, at least as an EU user.
- bryanrasmussen 1y agosure, if they ask you can we track you and you say no they should not fingerprint.
- apples_oranges 1y agoEU (or whoever) could mandate a switch in the browser, when turned on, all identifying apis are disabled. But the IP is still the same, so..
- troupo 1y agoThe law has been around for almost 10 years now. If browser vendors wanted, they could have come up with such a switch themselves. Guess which company is coincidentally is the world's largest advertiser, largest ad broker, largest data tracker and owns world's most popular browser?
- kennywinker 1y agoNon-hostile websites use identifying apis for functionality. Disabling them globally means a broken browsing experience.
- afiori 1y agoThis falls into the same problem as the DNT header, while being a good technology it will be used by so few people that is might very well increase fingerprinting capabilities in some ways.
- AlexandrB 1y agoHow would you ever find out/enforce this though? With cookies, you can examine the local cookie storage but with fingerprinting everything happens server-side (as I understand).
- Sanzig 1y agoThe fingerprint collection happens mostly using client-side JS (a bit of server side with HTTP headers, but the really high entropy stuff is client side). Conceivably you could develop some sort of heuristic that detects when a script is simultaneously poking at a whole bunch of APIs associated with common fingerprinting techniques (canvas capabilities, WebGL, screen size, installed fonts, etc) and then kill it. But it is certainly much harder than blocking cookies.
- voidUpdate 1y agoHow does web fingerprinting work with things like iPhones, where many people have the same screen, browser, os version, etc?
- fuzzy2 1y agoI think there’s still quite a bit: font size, regional settings (language etc), software versions, browser extensions, adblockers…
- kevindamm 1y agoThe browser version will have some variance because releases are rolled out to clients over time, and users don't restart their browser immediately. I don't know all the signals FingerprintJS use but they obviously depend significantly on the user agent string (which has the precise version) seen by how the author could spoof it with Tor's UA randomizer. BTW, the article is incorrect that Chrome doesn't allow for user agent modification or other fingerprint resistance; you can: https://developer.chrome.com/docs/devtools/device-mode/override-user-agent#override_the_user_agent_string https://developer.chrome.com/docs/devtools/device-mode/overr... and there are extensions for more convenience. The article is also incorrect about third party cookie leakage from ads but it was possible to sniff the session ID in some cases, back a decade ago before everything went cookieless and dropped session identifiers from the protocol entirely. However, it is possible for advertisers to parameterize their campaigns and analytics to such a detail that they can link demographics to their internal user IDs, though it's against policy it is easy to go unnoticed. And things like location exfiltration in too many Android apps, I'm not trying to give Google a complete pass on privacy but it's clear the author made some assumptions based on bias. Back to your question, though, there are other things you can use as part of the fingerprint. The fonts that are installed are a proxy for which applications have been installed. The artifacts at the edge of text rendered onto a canvas can indicate which graphics chip and drivers are installed, sometimes with differences even within the same GPU model and driver version. Touch tracking can tell whether you swipe with your left hand or your right hand. Timing signals can indicate CPU specs and even hint at whether you're in a VM or behind a VPN, etc. There are more, accessible from JS in most cases, and really most of it is more reliable than what's in the user agent string.
- 1y ago
- 1a527dd5 1y agoAdding the other side; we use ja3/ja4 * for rate limiting and it works a treat, especially when we set our rate limits to much higher than normal traffic. I've pushed back any attempts for any kind of tracking for business purposes (e.g. fancy charts). * ja3 seems to be slightly better, ja4 sometimes groups too many "people". Edit* Title also needs (2023).
- apples_oranges 1y agoUsing the same IP address, isn't he?
- apples_oranges 1y agoI tried with phone, switch from wifi to cellular and I get a new fingerprint. (private browser, always on)
- 0points 1y agoMany of us are. It's not a unique identifier.
- Sanzig 1y agoBrowser fingerprinting is one of those things that should be outright illegal - it is far more of a threat than tracking cookies ever were. But it hasn't permeated the public consciousness like cookies have, so regulators seem to ignore it.
- chpatrick 1y agoSeems almost impossible to police though.
- tonyedgecombe 1y agoYes, it’s probably worse to have unenforced regulations than no regulations.
- Sanzig 1y agoSince fingerprinting is mostly client side, it should be detectable. If you serve a web page with a fingerprinting script, that should be an automatic big fine.
- MontyCarloHall 1y agoSites would then avoid running purpose-built fingerprint scripts and collect fingerprint metrics as a side-effect of necessary activities. Lots of sites need to know window/screen size, DPI, installed fonts, timezone/locale, etc. as a matter of being able to function properly. It would be impossible to know whether a site is also using this information to fingerprint users. The unsolvable problem is that modern websites are not simply documents but rather full-blown software with web browsers their runtime environments, and you simply cannot enable that amount of power without also enabling the power to fingerprint that runtime environment and thus fingerprint the user.
- deleted 1y ago[deleted]
- amelius 1y agoWe need regulators with more balls. And more brains. This privacy theater is becoming very painful to watch.
- anonymousDan 1y agoIt's a little unclear to me - does Brave prevent it or not? Edit: some interesting background on what they do here: https://github.com/brave/brave-browser/wiki/Fingerprinting-Protections https://github.com/brave/brave-browser/wiki/Fingerprinting-P...
- thesuitonym 1y agoDoes it matter? Brave is adware, so even if they prevent fingerprinting, you're just trading one vendor for another.
- oldandboring 1y agoI just turn off all the news, ads, crypto wallet, etc. stuff in Brave and it honestly feels just like Chrome but with really good ad-blocking. I'm just a little disappointed to see that it isn't as good at blocking fingerprinting as they claim to be.
- yjftsjthsd-h 1y agoIt depends exactly what they do and what you're trying to prevent. If Brave shows you ads but does it without tracking you, then that might be better than them not showing ads and letting you be tracked. So the question is: Are they tracking you?
- homebrewer 1y agohttps://privacytests.org https://privacytests.org Maintained by a Brave employee, though the site is fully open in all senses of the word, as far as I'm aware.
- anonymousDan 1y agoOh wow, supercool! Seems to do pretty well on desktop private mode at least.
- nuker 1y agoSafari in Private mode checks a lot of boxes! Great find!
- specproc 1y agoI just tried this with the Firefox setting recommended in the article, with and without a VPN, and it still recognised me. Any other tips?
- nicman23 1y agoipv6?
- thesuitonym 1y agoDid you restart Firefox after enabling the setting?
- specproc 1y agoActually, no. Good shout. AFK right now, but will try later.
- jabjq 1y agoYep, doesn't work at all. This post is two years old and the methods they use have been updated.
- Jeremy1026 1y agoI didn't get the same ID when using Safari in a "regular" window, then visiting again in a Private Browsing window. So that's good I guess? https://imgur.com/a/OBoaTdy https://imgur.com/a/OBoaTdy
- matthewdgreen 1y agoThis isn't exactly browser fingerprinting (though it may involve browser fingerprinting.) But the biggest open question I have right now is: what is Meta doing to get around Apple's iOS privacy protections? A couple of years ago, Apple launched App Tracking Transparency as a way to reduce tracking across their iOS app ecosystem. People predicted that this would be devastating for companies like Meta and Snap, and it was -- briefly, for Meta. But Meta seems to have rebounded very quickly, maybe Snap not so quickly. The rumor I've heard is that Meta threw every brain they had against the problem of finding new ways to track app users, which presumably involves some similar type of fingerprinting. The revenue success strongly indicates were successful. But if this is true, nobody has much written about it.
- dec0dedab0de 1y agoprobably just ignored them. Aren't those privacy protections basically you saying "pretty please don't track me?"
- willis936 1y agoIf we're exploring the space of "they're lying" isn't a simpler explanation be that they're lying about their revenue?
- pc86 1y agoThe consequences for lying about revenue as a public company are many orders of magnitude worse than lying about compliance with some private contract or TOS.
- PenguinCoder 1y agoMess with someone's personal privacy, non-issue. Mess with investors money, instant problem.. Money is more important than people, to these groups.
- 1y ago
- bellajbadr 1y agoPeople who are recommending Tor/torBrowser the last versions are enabling system spoofing which helps to fingerprints you. Also Javascript can just help to fingerprint you easily even if the browser doesn't
- NooneAtAll3 1y agohow does system spoofing fingerprint you, if it spoofs same way for all tor users?
- _lvbh 1y agoMust be a typo. They are disabling user agent spoofing for operating systems (but not versions) Not a great move imo
- Oras 1y agotitle should mention this is from March 2023
- Vinnl 1y agoSo, one thing I don't quite get about fingerprinting: > For example, websites can see web browser version, number of CPUs on your device, screen size, number of touchpoints, video/audio codecs, operating system and many other details If, for example, I upgrade my web browser in two weeks (i.e. I get a new version number), doesn't that mean that the site has lost me? Sites like https://coveryourtracks.eff.org https://coveryourtracks.eff.org seem to focus on how unique your fingerprint is, but doesn't it also matter how stable it is over time?
- rinz 1y agoThat is why they probably don't put features that can be easily changed into the final fingerprint hash.
- Vinnl 1y agoBut how many features then remain? For example, I've seen people discuss font size, version numbers, viewport size, etc. Do the remaining features still make a unique identifier?
- corford 1y agoIn most cases yes. If you upgrade your browser, the only thing that changes is the user agent data. The underlying device remains the same and it is this that leaks a lot of fingerprinting attributes (screen, gfx card, fonts, timezone, language, operating system, battery status, audio setup, bluetooth, installed video codecs, TCP data, IP address if static etc.). To get a feeling for this, try: https://abrahamjuliot.github.io/creepjs/ https://abrahamjuliot.github.io/creepjs/ ; https://bot.incolumitas.com/ https://bot.incolumitas.com/ and https://amiunique.org/fingerprint https://amiunique.org/fingerprint Combined with super cookies (https://blog.mozilla.org/en/internet-culture/mozilla-explains-cookies-and-supercookies/ https://blog.mozilla.org/en/internet-culture/mozilla-explain...), that's a lot of data points to stitch together a high confidence fingerprint. Although not perfect, FF is much better out of the box at limiting the leaks than chrome.
- dehrmann 1y ago
- mysterypie 1y ago> go to about:config and setting privacy.resistFingerprinting = true in your Firefox browser Two questions jump to mind: Why isn't this the default in Firefox? What is the downside? I.e., what can break by enabling this parameter?
- rinz 1y agoSome websites prefilled username to allow quicker re-login - this kind of features. Worst case scenario, you will get a first-time visit experience all over again
- JohnFen 1y agoIt's isn't the default because the countermeasures cause a lot of side-effects. If it were on by default, new users would probably think the browser is broken or buggy. Here's what the settings do and what sort of side-effects you might experience: https://support.mozilla.org/en-US/kb/resist-fingerprinting https://support.mozilla.org/en-US/kb/resist-fingerprinting
- Yeul 1y agoYeah I have it on but I use a second browser for banking and government business.
- micromacrofoot 1y agoIt's actually part of the privacy preferences in the normal settings, and they supply this warning > This setting may cause some websites to not display content or work correctly. If a site seems broken, you may want to turn off tracking protection for that site to load all content. Some sites use light fingerprinting to provide features
- jeroenhd 1y agoresistFingerprinting is stricter (and has worse side effects) than the standard "strict" privacy protection.
- 1y ago
- ezfe 1y agoThis doesn’t work on my iPhone in Safari
- jordanb 1y agoI'm considering it a good thing at this point that I'm getting captcha-walled with increasing frequency. It means that my setup and behavior looks more like the billions of anonymous bots flooding the web rather than a lucrative mark.
- fsflover 1y agoDid you have a look at this test? https://www.eff.org/pages/cover-your-tracks https://www.eff.org/pages/cover-your-tracks
- daneel_w 1y agoYou should share details on your setup.
- jordanb 1y agoNothing special just Firefox and the normal privacy plugins.
- PunchTunnel 1y agoIt also might be (as it proved in my case) that your address block (including the whole neighborhood from an ISP perspective) includes a compromised device. I discovered one of my neighbors has a compromised device that's sending a couple million spam emails per month, and it tainted the reputation of the entire network address block.
- jordanb 1y agoWell it happens on both my laptop and my phone, both of which are firefox with a lot of the fingerprinting stuff like useragent knocked out, as well as adblock, etc.
- bo1024 1y ago(Different commenter, same experience) Firefox, VPN, UBlock Origin, Privacy Badger, and UMatrix plugin to block cookies and javascript by default. (You can easily whitelist first and/or third-party cookies and/or JS on sites of your choice.) Actually, usually librewolf instead of firefox, but not a big difference I suspect.
- torium 1y ago[dead]
- lucraft 1y agoI tried the demo, fingerprint.com, in: - Safari - Safari private mode - Chrome private mode and it was not able to identify me across those. I then tried - Chrome (normal, non-private mode) and it did identify that as a repeat Chrome visit. Does Safari have better privacy than Chrome?
- rogerkirkness 1y agoYes by a lot.
- piker 1y agoThis comes with some downside because to protect privacy Safari blocks some useful APIs. For example, you can't tell if the user is running Apple silicon or Intel. That means you have to ask them whether they want the Intel or Apple silicon version of a download. This is a non-trivial question for a lot of Mac users. And, sure, you can always publish through the App store but that comes with its own drawbacks.
- 9dev 1y agoA price I’ll gladly pay in favor of increased privacy, and I haven’t heard of too many people stumped by the question. In the worst case, you can just try it out.
- piker 1y agoYeah for folks who are viewing this site it's obvious, but my target audience doesn't have a clue for example.
- deleted 1y ago[deleted]
- dangus 1y agohttps://developer.apple.com/documentation/apple-silicon/building-a-universal-macos-binary https://developer.apple.com/documentation/apple-silicon/buil...
- Roguelazer 1y agoIt's really "cool" when you get vendors like 6sense that combine browser fingerprinting with semi-licit data brokers to do full deanonymization of visitor traffic. Why bother doing marketing when you can just get a report of the name, email address, mailing address, and creditworthiness of every person who's visited your website? I've seen people argue with a straight face that these tools and their reports don't run afoul of GDPR/CCPA because they don't involve information that a user gave you on purpose, so it's not protected. Ghouls, all of them.
- Zak 1y agoI turned on resistfingerprinting and started getting sites in light mode. The horror! This doesn't look to be among the available toggles, and I hope that changes. I realize the light/dark setting is a data point for fingerprinting, but it's also something I have a genuine strong preference about.
- nelblu 1y agoThis really saddens me. The fingerprinting even works when using Mullvad browser with VPN. I am so tired of this new internet, I hope someone is working on figuring out an alternative to this type of fingerprinting. I understand it is a cat and mouse game, but whatever, this is absolutely shitty. I was wondering why can't browsers just fake the hardware (assuming that is what it is using to recognize)? I understand sometimes these javascripts run some type of algorithm to detect how fast it was processed to fingerprint, but even those could potentially be faked by the browser. Is anyone working on such stuff?
- u8_ 1y agoFrom my experience, fingerprint.com isn't really the best at fingerprinting. The scariest one to me is creepjs https://abrahamjuliot.github.io/creepjs/ https://abrahamjuliot.github.io/creepjs/
- anthk 1y agoDillo and Links are prefect against that crap.
- yodon 1y agoThere's a company offering a service to explicitly unmask and name the formerly anonymous visitors to your website, posted on HN today. [0]https://news.ycombinator.com/item?id=44670308 https://news.ycombinator.com/item?id=44670308
- mystraline 1y agoBigger question: why isn't Firefox and Tor Browser modifying the JavaScript reporting calls to lie? All machines would have 16 cores and 32GB ram, running windows 10, and 1 point-touch or mouse. And the resolution would also be fixed as reporting, and only on client would change. The user-agent should be acting on our behalf. So, why isn't it (Firefox, TBB) utterly lying and acting in our interest? We know why Chrome wouldn't. Tor also gave up this web fingerprinting fight without even really trying. Editing the JavaScript calls to consistently lie the same way was "too hard". https://m.youtube.com/watch?v=3wlNemFwbwE https://m.youtube.com/watch?v=3wlNemFwbwE
- rsync 1y agoGoing further: why does Firefox allow site operators to dictate common user interface restrictions? Infantile developer behaviors like disabling paste in the password field? Or bona fide on page text that cannot be selected in the browser window? There is no reason for Firefox to enable or honor these requests.
- fortran77 1y agoI cleared my cookies, went to private mode (on Edge) and fingerprint.com knew it was me. Now I wonder how much was a good guess from IP address and things that are other than browser-supplied information.
- bugsMarathon88 1y agoTor Browser is the only last remaining bastion for a semblance of privacy online, both through the network and hardened Firefox. Any other attempts, through VPN or otherwise, are frankly futile and only increase attack surface.
- kyle-rb 1y agoThere's a company, currently called Tie (meettie.com), formerly known as Revenue Roll, who promises to "de-anonymize your highest value web traffic", which in practice means that they give you an email address for retargeting, for a user who visited your site without ever explicitly providing any identifying info. The old site had a blog post [0] where they explicitly said they were using fingerprinting, and even called it "privacy-compliant". I'm sure they're not unique in the service they provide, but that was the first time I'd seen someone brag about browser fingerprinting. [0] https://web.archive.org/web/20240527125312/https://www.revenueroll.com/blog-posts/how-the-cookiepocalypse-will-affect-your-e-comm-store https://web.archive.org/web/20240527125312/https://www.reven...
- gausswho 1y agoI notice they have an Opt-Out form here: https://app.termly.io/dsar/ee5088c4-5eb2-475c-a9ea-9376f1b70eb6 https://app.termly.io/dsar/ee5088c4-5eb2-475c-a9ea-9376f1b70... It's pretty hilarious legalese and tells you nothing about what it even achieves. Maybe makes you a Very Important Marketing Target. One thing that struck me was the 'Under penalty of perjury, I declare all the above information to be true and accurate'. Shame they seem to require validating request by email. It'd be fun to take a PII breach and throw all the emails you find at 'em.
- kurtoid 1y agotried the form for shits and giggles - 6 days ago and no response yet
- amelius 1y agoWhy aren't privacy orgs trying these services.
- 71202114 1y agoFound This: https://www.youtube.com/shorts/Du1W8k6Y_kc https://www.youtube.com/shorts/Du1W8k6Y_kc
- deleted 1y ago[deleted]
- owenthejumper 1y agoThere are legitimate use cases of fingerprinting, like bot management. Unfortunately too many people abuse the system
- soruly 1y agoYes. As a site owner who keep fighting with bots and malicious traffic, I wish web browsers provide me a way to identify real users from bot traffic. Otherwise I'll have to put everything behind account registration.
- luxuryballs 1y agowhat if I just have a script that browses random websites when I’m away and now they id my machine but the data isn’t a true reflection of anything
- DavideNL 1y agoFyi, interesting info about Firefox Fingerprinting Protection mode/settings : https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo...
- dingody 1y agoEvery now and then, news like this pops up and sparks some discussion. But in reality, I believe any internet-based business—every single app to some extent—tracks users in this way. It’s just the nature of the internet.
- nilslindemann 1y agoI have just tried this with a fresh Firefox and `privacy.resistFingerprinting` set to True, still this site detects me, and coveryourtracks.eff.org tells me "Your browser has a unique fingerprint". Speak, I can not reproduce the results of this article. Can you? Edit: Have also set all other `fingerprinting` bools to False. uBlock, uMatrix, Privacy Badger installed. Under Settings → Privacy and security: Enhanced Tracking Protection = strict. Tell websites not to sell or share my data. Delete cookies and site data when Firefox is closed. Enable HTTPS-Only Mode in all windows. Enable DNS over HTTPS using: Max Protection – I still can be detected. Edit 2: Just tried with Brave, strictest settings. No effect, I am detected. Edit 3: Tor works.