9 ms·
Firefox expands fingerprint protections
- tmtvl 11mo agoI'm already using CanvasBlocker, Decentraleyes, and the NoScript Security Suite; but getting more protections will be nice. Even if it may take a while for them to land in Waterfox.
- ravenstine 11mo agoHow is your browsing experience with that stuff? I used to go nuts with anti-tracking measures, but enough of my browsing experience kept breaking that it just didn't feel worth it.
- MathMonkeyMan 11mo agoI use LibreWolf at work, and I exempt most internal sites from aggressive anti-tracking stuff, but otherwise it works fine.
- tmtvl 11mo agoIt's fine. Sometimes I get annoyed by websites which require JavaScript to show static text (apparently HTML is too difficult?) or which block me with a 'please unblock challenges.cloudflare.com to proceed' (that second one seriously pisses me off when I see it on, for example, the website of the Belgian railways), but by and large I'm fine with just saying 'if it breaks I don't need it'. But I handle my e-mail with isync, mu, and mu4e; and as far as I understand e-mail tends to be a sticking point for those who care for their digital rights. I also don't have Xitter or Facebook or any of that nonsense. If there's one thing I don't like its the fact that NoScript doesn't integrate with Multi-Account Containers. It would be neat if instead of having to temporarily allow GitHub JavaScript and re-disable it when I'm done; I could just allow GH JS in a GitHub or Microsoft container and it only being enabled in that container.
- skydhash 11mo agoLibraries documentation that requires javascript to load is the lowest of the bunch in my opinion.
- pmontra 11mo agoMy experience with uMatrix: most sites work right away. Others require fiddling with the matrix of media, script, xhr, frames and the third parties serving them. After a while it's easy to remember which ones must be temporary enabled and which ones don't. Sites with videos are a little more difficult. Sites with payments require care. I whitelist the minimum set of scripts that make the sites I use often work. There are usually many scripts that can be left out. If everything fails and it's a one shot site, I start Chrome.
- hku333 11mo agoYou are actually easier to track using these addons. By installing Canvasblocker, Decentraleyes and NoScript you are providing more entropy to trackers and thus making it easier to track you. Imagine how many people worldwide block specifically Canvas, have weird looking network requests to certain js libs and have JS disabled for some (/all) scripts combined with your general setup (window size, font size, and many other factors that do not even require JS). The Tor project explicitly suggests to not install an adblocker for example because of this.
- tmtvl 11mo agoWithout an ad blocker and JavaScript blocker the average website would be 100GB in size and take several years to load. If I really cared about tracking protection I would just not use the regular internet and stick to Gemini. CanvasBlocker is just because the Tor browser itself has one implemented (source: <https://2019.www.torproject.org/projects/torbrowser/design/#fingerprinting-linkability https://2019.www.torproject.org/projects/torbrowser/design/#...>) so I figured I might as well.
- unethical_ban 11mo agoThere has to be a happy middle between "no protection" and "complete uniqueness" The web without ad blocking is revolting. Browsers building in these features makes them more popular. Aside: Fuck the Washington Post. They have a line in their privacy policy that acknowledges the existence of "Do Not Track" flags in browsers. Their acknowledgement: since there is no industry standard for responding to it, they ignore it.
- evertedsphere 11mo agowow lmao > Do Not Track. Some web browsers may transmit a “do-not-track” signal. Because there currently is no industry standard concerning how to treat such signals, the Services currently do not take action in response to do not track signals. We respond to legally recognized browser-based opt out signals such as the Global Privacy Control signal for California residents. https://www.washingtonpost.com/privacy-policy/ https://www.washingtonpost.com/privacy-policy/
- Dwedit 11mo agoAdding noise to images sounds like a really bad idea. It will mess with any Javascript code which performs processing on images. Try writing a photo editor in Javascript and watch your browser corrupt your images.
- zuhsetaqi 11mo agoLike the articel says those features can be disabled on a per site basis.
- Dwedit 11mo agoYou are able to toggle these specific named categories: * Cookies * Tracking Content * Cryptominers * Known Fingerprinters * Suspected Fingerprinters But there is no separate toggle for the feature that adds noise to the image, or indication of which toggle would affect that.
- tomrittervg 11mo agoIt's 'Suspected Fingerprinters' that controls the Fingerpritning Protection feature described in the blog post. But yes, naming and descriptions is hard and never seems to work. But to disable it on a per-site basis, I would just disable ETP for the entire site. If it's a service or site you use frequently you probably trust them or otherwise have a login to them that makes trying to avoid fingerprinting illogical.
- pona-a 11mo agoI wish them the best. When I last tested it on fingerprint.com, the hash remained stable even with resistFingerprinting and letterboxing from a VPN, only changing between profiles. When I daily-drove resistFingerprinting (not reduceFingerprinting that permits exceptions like dark mode) in 2021, my hash changed every restart.
- Tmpod 11mo agoPerhaps fingerprint.com has stepped up their detection game and have new heuristics to identify you, thwarting the resistFingerprinting measures. My experience lately has been that fingerprint.com is able to identify my main profile "in bursts", i.e. it will identify me consistently for some days, then it will forget and tell me it's never seen me. Maybe the service they provide on the landing page has a TTL policy? Either way, I've observed this behaviour on both my main profile and my "Firefox Focus"-like profile (a mix of no history + automatic temporary containers). On Mullvad Browser, however, it always seems to group me with random access across the globe.
- xnx 11mo agoThis is a good use of Firefox resources. Unfortunately Firefox is at a natural disadvantage for fingerprinting by virtue of being used by such a small number of users.
- prism56 11mo agoInteresting. So when you try resist fingerprinting. If you dont go all the way you're at risk of making your differentiations smaller?
- kube-system 11mo agoAs an oversimplified example: If a website has 100 visitors, and 99 of them use Chrome, and 1 user uses Firefox, it doesn't matter how good their fingerprinting resistance is, they're always the one using Firefox. https://xkcd.com/1105/ https://xkcd.com/1105/
- Phelinofist 11mo agoBut if another Firefox user comes they are indistinguishable from each other, while every Chrome user is uniquely identifiable, are they not?
- kube-system 11mo ago> if another Firefox user comes they are indistinguishable from each other, Even if every Firefox browser gave off the exact same fingerprint, that wouldn't make the network traffic indistinguishable between Firefox users. There is a lot of entropy that is provided by your network stack of your device, the networks you connect to in order to get to the end website, the behavior of your requests, etc. Now, most websites aren't doing this kind of analysis. But it isn't unheard of or impossible. There are major websites that are known to do TLS fingerprinting.
- godelski 11mo agoFirefox is low on browser count but it's still around 4%[0]. That's enough that there will be lots of collisions. Even a small percent of a very large number is a very large number [0] https://radar.cloudflare.com/reports/browser-market-share-2025-q1 https://radar.cloudflare.com/reports/browser-market-share-20...
- cluckindan 11mo agoIt’s a bit annoying that Firefox by default breaks all sites that use canvas imageData API. There is no permission for that, so no user-friendly way to ask for consent either.
- HackerThemAll 11mo agoSites such as?
- cluckindan 11mo agoOffline friendly image editors for instance.
- y-c-o-m-b 11mo agoI exclusively use private browsing, but I know that doesn't do much in preventing tracking, so it's nice to see this finally starting to roll out. The fact that I have to go to great lengths to browse anonymously - and companies desperately try to circumvent my genuine decision to opt out of their tracking - tells me everything I need to know about those companies. Words like sleezy, shady, and predatory come to mind. I would love to see this taken one step further and have states/countries prevent companies from tracking me altogether if I reject their cookies, but I fear it's more likely those companies will lobby to prevent Firefox from protecting us.
- tgv 11mo agoYou could try to use profiles instead of private browsing. It keeps things separated.
- notafox 11mo agoAlso profiles can be configured and used with CLI, no need for UI (old or new). ./firefox -CreateProfile "profile-name /home/user/.mozilla/firefox/profile-path/" ./firefox -profile "/home/user/.mozilla/firefox/profile-path/" And, you can run it directly, no need to launch default firefox profile: Given that /usr/bin/firefox is just a shell script, you can - create a copy of it, say, /usr/bin/firefox-hn - adjust the relevant line, adding the -profile argument If you use an icon to run firefox (say, /usr/share/applications/firefox.desktop), you'll need to do copy/adjust line for the icon.
- unethical_ban 11mo agoInstead of needing to know scripting for a core feature, it would be nice if I could tell the program to ask me every time I open a new window which profile that window used. Right click would have an option like their containers "opening new profile window" .
- skydhash 11mo agoBetter if they would allow some configuration like toggling js by domain. uBlock is great, but I would like first party support.
- dmix 11mo agoI use FF and I paid for NYTimes. I was logged in, yet NYTimes constantly flagged my browser with a persistent captcha I couldn't bypass for months (across 2 different machines). It thought I was a bot because of the privacy features. So I cancelled my subscription using my phone.
- Esophagus4 11mo agoHa - I thought you were gonna say you switched browsers.
- dmix 11mo agoI just found a way to bypass the paywall on a web browser when I want to read an article. Which I figured was a easier solution than emailing customer service over a technical matter (never fun).
- deltoidmaximus 11mo agoIs there a reason to force all these bot checks on logged in accounts that are paying you money other than insanity? Surely you could just have a max monthly bandwidth limit per account and just stop worrying about this?
- rpdillon 11mo agoThe New York Times is like a microcosm of the publishing industry. They seem to spend the majority of their effort on protecting their intellectual property. I'd rather they use those resources to improve their reporting, particularly about technical topics, but alas.
- kvirani 11mo agoWe just down know from the outside how much revenue they would lose by redirecting that effort though.
- 11mo ago
- shevy-java 11mo agoI tested firefox recently. It had some AI summary button or something that was new. I instantly wanted to eliminate this from the UI but I don't know how to do that. I guess it is possible? But it probably requires some time and research; the thing I don't need or want this, it just takes away space. Then I remembered why I no longer use firefox. I believe we, as users, need to take back the open web. The days of some random developers ruining the UI should really be over, be it firefox, or Google chrome killing ublock origin. We need to fight back.
- cowpig 11mo agoI use Firefox because it is better than Chrome, which is the only alternative I see. Do you use something else?
- rpdillon 11mo agoLibreWolf, Iron Fox, and Brave are all worth a look, I think.
- messe 11mo agoNot the commenter you're replying to, but I've been using LibreWolf for the last few months. It's a bit more privacy focused, so may need some tweaking to your liking (by default it won't persist history, zoom levels, cookies, etc.)
- SoftTalker 11mo agoAlmost all "alternative" browsers are Chromium based or Gecko/Firefox based. If there are any that are truly scratch-built other than the text-based browsers such as lynx or w3m I'd be interested to hear about them. I'd guess they are extremely limited in features.
- II2II 11mo agoThe graphical alternatives that I am aware of are extremely limited, such as NetSurf.
- 11mo ago
- deleted 11mo ago[deleted]
- charcircuit 11mo ago>Having a unique fingerprint means fingerprinters can continuously identify you invisibly This is not right. If you have a unique fingerprint every time someone tries to fingerprint you, then they have to do extra work to try and figure out which are the same. If you make it always be the same you've made the fingerprinter's job much easier.
- cjkaminski 11mo agoAgreed. And this technique becomes more effective as the number of people using it increases. It's easy to match up randomized fingerprints if only one person is doing it, but quite hard when thousands or millions are doing it.
- rolph 11mo agodont use randomized fingerprints, spoof actual fingerprints, randomly.
- kube-system 11mo agoA good fingerprint algorithm incorporates features and functionality that can't be spoofed because it is necessary for the browser to work correctly. You can't just make your browser's APIs give erroneous outputs and still expect the browser's APIs to work.
- wiredpancake 11mo ago[dead]
- tomrittervg 11mo agoIn this context "a unique fingerprint" means that your fingerprint does not match any other user's. When you visit Site A and B you give a fingerprint X that is the same on A and B but no one else on the internet has ever sent. In contrast a randomized fingerprint mean when you visit A you have a fingerprint X' and on B you have a fingerprint Y' and no one else on the internet has X' or Y' but A and B can't correlate you. The protections we've put in place first try to do API normalization to make it so more people have a fingerprint X, and it isn't unique. And then they do API randomization so you use X' and Y'. If a fingerprint goes to extra effort of detecting a randomized fingerprint, and ignore (or remove) the randomization, they will get the X fingerprint which - hopefully - matches many more users.
- nalekberov 11mo agoFingerprinting is nearly impossible to resist these days anyways, no matter which technics Firefox uses to reduce it, and sometimes it actually makes the browser appear more unique. Last time I tried everything I could to prevent Firefox from calling home, it was still requesting Mozilla servers. Though I haven’t given up, my plan is disabling it at source code level and build my own release.
- vablings 11mo agoI think this is a nihilistic view. The browser ultimately sends only what the webpage requests. If we gut the ability for websites to request large swathes of information such as every supported TLS Cipher suite and also better protections such as GDPR to make it illegal for browsers to track this information unless a user signs up and also not gating information behind said sign-ups
- nalekberov 11mo agoI couldn't quite catch what you meant, but > The browser ultimately sends only what the webpage requests. You should do research before making such claims.
- philipallstar 11mo ago> and also not gating information behind said sign-ups "People should do work for free" isn't very workable.
- wtallis 11mo agoI don't think there's anything in GDPR or similar laws about disallowing paying for a subscription with money. It's merely about killing the practice of paying with your privacy for something otherwise labeled as "free".
- philipallstar 11mo agoThe quote I gave was the context, not GDPR.
- Bender 11mo agoOn the topic of Firefox fingerprinting, how does one edit the NetworkID in about:networking#networkid without creating new profiles or user accounts?
- instagib 11mo agoOne thing I found that broke tracking algorithms was the ‘every tab is a new random profile’ extension. I can’t remember the name as I haven’t used it in a while and it broke a lot of logins. They could not build a profile on you and it would break their system of tracking user login per device.
- DavideNL 11mo agoYou probably mean Temporary Containers…? https://addons.mozilla.org/en-US/firefox/addon/temporary-containers/ https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
- adamc 11mo agoThanks to both of you. That seems valuable.
- rogueparitybit 11mo agoI've recently switched from Containerise + Temporary Containers to Auto Containers. Brand new addon, but the dev is responsive and IMO it works much better for creating new containers on the fly as you browse. https://addons.mozilla.org/en-GB/firefox/addon/auto-containers/ https://addons.mozilla.org/en-GB/firefox/addon/auto-containe... https://github.com/Shajirr/FF-Auto-Containers https://github.com/Shajirr/FF-Auto-Containers
- godelski 11mo agoThat's really handy! I like that it handles domains automatically Edit: Seems to break ad blocking and there's some issues with login. Such as adding a container for YouTube requires also doing *.google.com since that's how the login is handled. Interesting and I'll keep playing around with it
- baranul 11mo agoUsually, with most browsers, you can't separate YouTube from Google in order to watch their videos. People can get around this using NewPipe and various forks, that are mostly for Android. There is also FreeTube for the desktop, that doesn't allow ads, but does connect to Google.
- Fokamul 11mo agoI dev my private fork of browser fingerprinting bypass and I can tell, this is like 1% of what commercial tracking companies use for fingerprinting. Unless they tackle all the hidden things, all artifacts, canvas rendering and many more. These companies will be actually happy after this change, because even users with ublock and other plugins, will think they're not tracked. Yeah, nope. And it's not that hard to see how they fingerprint your browser, reverse any JS tracking script yourself and see.
- yborg 11mo agoIn my case the single largest contributor to my fingerprint is ... canvas size. I run full screen with a custom Firefox setup that basically makes my canvas size unique :/ The "protection" Firefox uses for this is to always open a new window at a default size, which does nothing in my case since my toolbar config still makes the canvas size unique. It would be really useful to have something that dithers the reported canvas size by 5 or 10 pixels in different containers to add noise there.
- HackerThemAll 11mo agoNow I understand why I'm getting paywall limits even in private browsing :) I use Tree Style Tab, so my canvas is also of unusual size and ratio. I guess I can try making it more narrow or wider to combat that :)
- Liquix 11mo agoto defeat canvas size fingerprinting in firefox: about:config -> set privacy.resistFingerprinting to true about:config -> create new boolean key privacy.resistFingerprinting.letterboxing set to true this will set your canvas to a common size which fits in the viewport and display a grey "letterbox" border in the surrounding space.
- yborg 11mo agoDoesn't seem to work... reported canvas size is still some odd value (2200x1283x24). I think it uses a fixed size for the letterbox, which is useless. Right general idea though.
- nicce 11mo agoUnfortunately, Cloudflare and other protections will keep working even less than they used to. I have started to not use Cloudflare protected websites because they don’t work with Firefox. But that is a fight I am going to lose.
- Spunkie 11mo agoI run exclusively Firefox over known mullvad VPN endpoints and I never have any issues with cloudflare or its captcha.
- nicce 11mo agoI guess you don’t have fingerprint resist on: https://news.ycombinator.com/item?id=35742606 https://news.ycombinator.com/item?id=35742606
- harshreality 11mo agoSymptoms? Is it limited to when a site has Cloudflare's more aggressive protection turned on? I haven't noticed any problems I've attributed to Cloudflare, and I use Firefox exclusively.
- CWuestefeld 11mo agoThis matches my experience as well. As a FF user, I very occasionally encounter problems, but these don't seem to be correlated to their using CF protections. Much more often I find sites broken that rely on cloud domains with bad reputations, which my DNS filters block. I was actually wondering if the stuff that Mozilla's talking about here will be used by bad bot people to try to circumvent CF's abuse protections. As I recall from when I was working with them, CF's service relies in part on being able to identify botnet attacks by doing its own fingerprinting.
- nicce 11mo agoThe only symptom is that captcha never completes. I have more restrictive protections on. If you use just loose settings, it completes, but advanced fingerprint protection, for example, breaks captcha completion. This is very known issue. https://news.ycombinator.com/item?id=35742606 https://news.ycombinator.com/item?id=35742606
- mixmastamyk 11mo agoI'm still unhappy with the user-agent header. I tried removing information but it breaks a number of sites. Would like to leave Linux in there (if feasible so it gets counted) but remove/spoof everything else.
- deleted 11mo ago[deleted]
- kube-system 11mo agoBreaking websites is about the only thing you're going to accomplish by messing with the UA string. It's a small amount of entropy and anyone who really wants to track you, doesn't need it.
- 1vuio0pswjnm7 11mo agoThe question that I have not see answered in the many, many forum threads on "browser fingerprinting", is specifically why a user seeks to avoid it Is it (a) to avoid internet marketing, (b) some other reason or (c) both. What is the "threat model" If the answer is (c) then is there a belief that a fingerprint collected for marketing purposes may be used for other purposes I do not use a browser to make HTTP requests, I only send two headers, Host and Connection, unless I need to send more, e.g., User Agent, Cookie, Accept, etc. The vast majority of websites I access work with only two headers. The list of ones that require more is short and the local forward proxy adds them automatically for those sites For me, the "threat model" is (a) internet marketing I do not see any ads because (1) the computers I use cannot access ad or tracking servers^FN1 and (2) I use a text-only browser to read HTML. There is no Javascript interpreter, no way to auto-load resources, no way to display images, no way to store cookies, etc. I have no issue with this information that I'm a text-only web user being revealed to any internet marketer. (More likely I am mistaken for a "bot" as a result of crude heuristics) On the other hand, if I were using a popular browser to make HTTP requests, one that sends a "common" fingerprint to internet marketers, then this would signal a more viable target for ads and tracking. Popular browsers have default settings that enable Javascript, cookies, images, auto-loading resources, etc. tl;dr The reasons a computer user has for avoiding fingerprinting may be different. For example, one user might want to "blend in" and "hide", i.e., avoid being "identified", whereas another user might want to "be left alone", i.e., avoid being the target of internet marketers FN1. Markerters always seem to require access to DNS
- someothherguyy 11mo agoIt would be nice to see Firefox implement a few features browsers like brave have, like being able to automatically clear cookies for a site when leaving it, and to make containers available when in private browsing, ah well.
- godelski 11mo agoThis is pretty handy and I've been using it for years[0]. I like the idea of Brave but we have a bigger fight that requires us to have no chromium. Chromium winning is Google winning, allowing them to control the Internet. I don't want that power in any single entity's hands. So I do ask that more people switch to Firefox or Safari as those are the best options to fight back and have decent market shares (even if small). If we lose the internet we'll lose our privacy too [0] https://addons.mozilla.org/en-US/firefox/addon/cookie-autodelete/ https://addons.mozilla.org/en-US/firefox/addon/cookie-autode...
- charcircuit 11mo agoThe real power is in who owns the product. Since chromium is open source. A fork can be made at anytime. For the web there is a lot of common code that is useful to share between browsers.
- godelski 11mo agoYour take is quite naïve. The problem is that Google is controlling all the protocols. We're already in a situation where chrome, and consequently chromium, is "the most up to date browser" because Google has a heavy influence in dictating what those standards are. This is, of course, why people fork chromium in the first place, because it gives them a leg up not needing to build everything from scratch and allows them to pull in security updates and new protocols as Google releases them. But that last part is the problem. So in a way you're right. But the owner is Google as long as you are forking chromium. Because they control to protocols. Maybe they don't own the roads, but does that matter if they get to dictate how all the roads get used and how all the maps are made? You don't need to own the roads to control them
- jrochkind1 11mo agoThis seem sto be the actual list of things it's protecting? https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting#w_how-does-each-protection-work https://support.mozilla.org/en-US/kb/firefox-protection-agai... They are... surprising to me. And as a developer, some of them seem kind of horrible. Altering canvas data, really?
- hmry 11mo agoIt's a real "can't have nice things" situation.
- trizuz 11mo ago[dead]