5 ms·
Browser fingerprinting is one of those things that should be outright illegal - it is far more of a threat than tracking cookies ever were. But it hasn't permea
by Sanzig 1y ago
Browser fingerprinting is one of those things that should be outright illegal - it is far more of a threat than tracking cookies ever were. But it hasn't permeated the public consciousness like cookies have, so regulators seem to ignore it.
- chpatrick 1y agoSeems almost impossible to police though.
- tonyedgecombe 1y agoYes, it’s probably worse to have unenforced regulations than no regulations.
- Sanzig 1y agoSince fingerprinting is mostly client side, it should be detectable. If you serve a web page with a fingerprinting script, that should be an automatic big fine.
- MontyCarloHall 1y agoSites would then avoid running purpose-built fingerprint scripts and collect fingerprint metrics as a side-effect of necessary activities. Lots of sites need to know window/screen size, DPI, installed fonts, timezone/locale, etc. as a matter of being able to function properly. It would be impossible to know whether a site is also using this information to fingerprint users. The unsolvable problem is that modern websites are not simply documents but rather full-blown software with web browsers their runtime environments, and you simply cannot enable that amount of power without also enabling the power to fingerprint that runtime environment and thus fingerprint the user.
- deleted 1y ago[deleted]
- amelius 1y agoWe need regulators with more balls. And more brains. This privacy theater is becoming very painful to watch.
- Lord-Jobo 1y agoThe core issue is that politically you gain nearly no votes and definitely no money by running with regulation as a pillar of your campaign. In fact, doing so will often times end up bringing donations from relevant industries directly to your opponent. Now, this system of perverse incentive and legal bribery should be fixed at the constitutional level but thats a gigantic can of worms. In the current system there are two methods that can circumvent the issue. The first is one deployed by the likes of Elizabeth Warren; run your campaign on a broad array of "fighting for your constituents" and don't get specific until you see already elected and drafting a bill. The second path is underutilized and should be done more: lie out your ass to the moneyed interests. Take their money, make them promises, eat at their fancy dinners, befriend them, laugh at their awful jokes. Then just fucking dunk on them in the legislature, as quietly as possible. Make a big show of being forced to, keep the charade going as long as possible. The inverse of this has been done a lot recently, with Sinema, with Fetterman. But the good version is quite rare, and a good opportunity to make our country a better place. Key notes: tough to do in bigger positions because they're rarely the first public office seats people hold, so track records build. Tough to do in many districts because voters can be rubes who actively agree with the corporations stomping on their nards. Tough to do if you make too large of a profile(not really a concern).
- jancsika 1y ago> The core issue is that politically you gain nearly no votes and definitely no money by running with regulation as a pillar of your campaign. Proof of Domain Expertise: Name the famous presidential campaign which focused directly on combating "this system of perverse incentive and legal bribery" as its core campaign message. Edit: Hint: primary, lots of votes, lots of money MD5 of answer: 1c02462874398d776ff28aeed2d056b1
- OhioMan2943 1y ago
- troupo 1y agoOr... You could read GDPR and realize that "cookie dialogs" were never about cookies: https://news.ycombinator.com/item?id=44670345 https://news.ycombinator.com/item?id=44670345
- Sanzig 1y agoTIL, thanks! The usual convention of calling them "cookie dialogues" sure obfuscates that.
- dylnuge 1y agoWhich is a very intentional (and successful) marketing ploy by companies to get users to not care about them. It sounds like a boring technical thing instead of "we need your permission to let massive advertising networks track you around the internet" (consent isn't needed for site functionality; you can use cookies and never mention it if you don't use them for tracking). Unfortunately this is a challenge with regulation; companies find a way to break the spirit of it as much as possible while following the letter. It's better that companies need consent to track us than not, but consent managers are dark patterns designed to deeply annoy us at the prospect of saying no.
- aniviacat 1y agoSo does that mean that fingerprint.com, which records your fingerprint without asking for your consent, is operating illegally?
- troupo 1y agoGood question :) I think if it's all client-side, not logged or retained, and is not transmitted to third parties, it should be fine. IANAL
- 9dev 1y agoYes, almost certainly so. You did not consent, they have no legitimate interest to track you, and you were never informed about the what and why in plain language. The GDPR isn’t the complex legislation monster people make it out to be, but for the most part common sense about handling sensitive data.
- patrickmay 1y agoThis is a technical problem, not a legal one. The solution is for browsers to provide users with the ability to limit the information being sent. There's no need for the vast majority of websites to know my OS, number of CPUs, screen or window size, or most of the other fingerprinting metrics.
- Sanzig 1y agoI think it's both. It wasn't a problem when browsers were simple content display engines, but now that they are full VMs for application software, they need some of that capability just to function. FWIW, I think this was a mistake, but the genie is out of the bottle. I suppose one technical mitigation might be a permissions dialog when a script requests access to a high-risk API like canvas or WebGL. But that's unfortunately something that won't work for most users, who will just click through the dialog.
- istjohn 1y agoI'm loathe to suggest it, but perhaps LLM's could help here? Once local LLMs are a couple orders of magnitude better and resource efficient, a user agent LLM could decide what features are actually needed for each page.
- codingminds 1y agoUntil the LLM learned that Cloudflare and friends will bomb you with Captchas until you allow all features again.
- kennywinker 1y agoMaking it a technical problem means it’s an arms race forever. Making it a regulation problem, if done right, can simply end the arms race. Not to mention the big players on the users’ team in the technical arms race (google, ms, apple) are also advertising companies. By all means let’s solve it from the technical side - but also lets regulate privacy so everyone gets it not just people paranoid/technical enough to use the latest/best privacy respecting tools.
- bee_rider 1y agoIt should be illegal, but we also need technical prevention of it, because the internet is global and goes through too many jurisdictions to really regulate. Plus, fingerprinting tech would get developed for criminal organizations or intelligence agencies anyway.
- Szpadel 1y agothere are some more or less legit causes for fingerprinting. like bot protection or to identifying scammers that just create another account when previous is banned. whether this is justified is of course subjective
- ryandrake 1y agoSomewhat off topic, but I think calling something "more or less legit" is a form of justifying it.
- grishka 1y agoIt can't be made entirely illegal so IMO a better way would be to remove or restrict the APIs that fingerprinting scripts abuse. Make browsers hypertext viewers again!
- thrance 1y agoWhy can't it be made illegal? And from the article, a very succinct explanation as to why browsers will never be fingerprint-resilient: > Chromium (Chrome) is built by Google, an advertisement company which tracks its users for showing relevant ads. So naturally it doesn’t have any inbuilt protection against fingerprinting.
- quantas 1y agoEven if they make it illegal, it won't stop bad actors especially from foreign countries to abuse stuff like this. It's better to build better systems that fix this issue instead of relying on government laws. You could compare it to the concept of security by obscurity which is obviously bad.
- fsflover 1y agoIt's already illegal in Europe: https://news.ycombinator.com/item?id=44670345 https://news.ycombinator.com/item?id=44670345
- bugsMarathon88 1y agoThe Internet is a war zone: demanding made up rules for behavior online is as ineffectual as pleading for peace with the enemy during battle. Strap on a helmet if you're shell-shocked.