5 ms·
PSA Don't use chrome.
by scrollop 11mo ago
PSA Don't use chrome.
- SV_BubbleTime 11mo agoDefinitely a good STEP1, but it’s not like Firefox and Safari are finger printing secure.
- capitainenemo 11mo agoFirefox does pretty damn well though, especially with privacy.resistFingerprinting set to true
- wizzwizz4 11mo agoprivacy.resistFingerprinting has potentially-unwanted side-effects, like wiping out most of your browser history (instead of the more sensible approach of just disabling purple links). I also recall something about it getting removed or nerfed, though I'm not sure whether that was a mere proposal.
- noisem4ker 11mo agoIt also does (or at least used to) mess with dates, due to it attempting to hide what time zone you're in.
- godshatter 11mo agoThe browser should reasonably know what time zone you're in and what time zone you're reporting to the website and translate between them automatically.
- noisem4ker 10mo agoYeah, "should". Too bad it's unfeasible. As soon as you e.g. print the current date as part of a paragraph somewhere, the browser loses track of it, and the website can just read the element's content and parse it back.
- capitainenemo 11mo agoIt does not wipe your browser history. I can definitely attest to that since my generic JS active + resistFingerprinting profile has a history going back years. It does set your timezone to UTC in JS on websites. I've mostly encountered that when playing Wordle ;)
- jijijijij 11mo agoEvery time I manually touched the "fingerprinting" about:config settings, my entropy went up. I used the EFF site to test: https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ AFAIK some of these options are there to be used by the Tor browser, which comes with strict configuration assumptions, and it doesn't translate well to normal Firefox usage. Especially if you change the window size on a non-standardized device. Mind you, the goal is not to block fingerprinting, but to not stand out. Safari on a macbook is probably harder to fingerprint than Firefox on your soldering iron. However, judging by the fact that every data hungry website seemingly has a huge problem with VPN usage, I'd presume they are pretty effective and fingerprinting is not.
- capitainenemo 11mo agoI've had good success with tracking tool tests and resistFingerprinting. Granted, I usually use it with uMatrix/NoScript most of the time which cuts down on the available data a lot and maybe makes it an unfair test. One issue, I expect, is simply not enough people using resist fingerprinting to add variation to the mix. Since it's off by default, and only a small % of users use Firefox and an even tinier percentage use resistFingerprinting, unlike your example of Tor where probably most people on the tor network use the tor browser, it's likely that simply blocking things is a fingerprint all on its own. The solution there would be to get more people using it :) I will say one downside to using it is far more bot detection websites freaking out over generic information being returned to them, causing some sites to break (some of their settings breaking webgl games too due to low values). Using a different profile avoids this, or explicitly whitelisting certain sites in privacy.resistFingerprinting.exemptedDomains - obviously if a site is using a generic tracking service for bot detection, that kills a fair amount of the benefit of the flag, so a separate profile might be best. I wish firefox had a container option for this. ... and. not too sure what you mean by changing window size on a non-standardised device. They do try to ensure the window sizes are at standard intervals, as if they were fullscreened at typical widths to reduce fingerprinting, but surely that applies to using Tor too? I mean, people don't use Tor on dedicated monitors at standard sizes.
- capitainenemo 10mo ago
- fsflover 11mo agoTor Browser (based on Firefox) is.
- Alive-in-2025 11mo agowhat about duck duck go? We need a simple chart: 1. What browsers are good at resisting finger printing 2. tell for each browser, does it work on android ad ios and apple and windows and linux 3. what setting are needed to achieve this for bonus points, is there no way to strip all headers on chrome on control it better?
- mark_l_watson 11mo agoThis is my question also. I tend to not use apps, use DuckDuckGo browser. I sometimes do use Safari which is a more convenient browser - it would be ironic if DDG browser is less private than Safari.
- 8fingerlouie 11mo agoModern Safari is pretty damned good at randomizing fingerprints with Intelligent Tracking Prevention. With IOS 26 and MacOS 26, it's enabled in both private and non private browser windows (used to be only in private mode). All "fingerprint" tests I've run have returned good results.
- SV_BubbleTime 11mo agoI haven’t tried 26, but I remember it didn’t used to be so great.
- drnick1 11mo agoUnfortunately, it's closed source and only available on Apple devices.
- datavirtue 11mo agoI only use it when I want to be tracked.
- FridayoLeary 11mo agoThat will just make you stand out more.
- 1718627440 11mo agoYou can change the reported UA header independently of the UA you use.
- michaelt 11mo agoIf I was a fingerprinting company, I'd be cross-referencing signals between browsers for sure. If the browser header says windows but the fonts available says linux, that's a very distinctive signal. And if the UA says Chrome but some other signal says not-chrome, that's very distinctive as well.
- nativeit 11mo agoYou said it better than I did.
- biztos 11mo agoSurely this is true, but if you’re a fingerprinting company aren’t you making so much money violating the privacy of the masses that it’s not worth your time going after the tiny set of Freedom Nerds trying to evade you?
- weird-eye-issue 11mo agoThey aren't specifically going after you... they just try to create a unique hash from everything they can and by doing weird things to your system you are making a truly unique hash easier
- jijijijij 11mo agoYeah, and my passwords are so obvious and stupid, nobody's gonna guess them! I think, you are falling for a technical fallacy. It's not costing them any more time.
- nikcub 11mo agodon't use the same browser regardless - the key is to compartmentalise.
- faidit 11mo agoTranslating pages is literally the only thing I use Chrome for. The built-in translation works way better than other browsers, even though they also use Google Translate.
- geocar 11mo agoI don’t think safari uses google translate
- gagik_co 11mo agoThe new built-in translation in Firefox works pretty well! I never need to fallback to others, although forcing it to translate has weird UX.
- seba_dos1 11mo agoFirefox does not use Google Translate and performs the translation locally, which works great for the most common languages out there. For the less common ones you still have to go to Google Translate, but IME it's definitely not worth changing the browser to Chrome over.
- robertlagrant 11mo agoYeah I really like the Firefox translate. A rare win for recent Firefox.
- echelon 11mo agoDitching Chrome is something we need to teach everyone. The DOJ is totally spineless and refuses to squash Google's absurd monopoly on the internet. We are literally the last line of defense, even though we really don't amount to much. Perhaps we could start a grassroots movement.
- IgorPartola 11mo agoYou don’t need a grassroots movement when other movements doing this exact thing already exist. In fact it is likely counterproductive. Mozilla Foundation is the organization you want to support, or EFF.
- unethical_ban 11mo agoPSA only use Mullvad or Tails which are set up to be as bland and uniform as possible
- h33t-l4x0r 11mo agoExcept I don't want to be flagged as a bot when I'm just visiting some website in my browser. (I also don't want to be flagged as a bot when I'm scraping some website with a bot).
- autoexec 11mo agoAs uniform as possible is exactly the wrong way to go. It only takes one data point overlooked or newly discovered to make every person trying to look identical distinct. New fingerprinting techniques are being implemented all the time, so what's the point in taking chances when it's far easier to randomly change a browsers fingerprint for each site/connection making it much harder to track any one browser over time.