4 ms·
I question why websites can even access all this info without asking or notifying the user. Why don't browsers make it like phones where the server (app) has t
by SirMaster 6mo ago
I question why websites can even access all this info without asking or notifying the user.
Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff?
- t-3 6mo agoThe most popular browser is made by an ad company. They also provide the majority of funding for their biggest competitor. Why would you expect anything different?
- john_strinlai 6mo agomost people would expect something different from tor, surely.
- briansmith 6mo agoThe purpose of a system is what it does.
- triceratops 6mo agoThis phrase is practically https://en.wikipedia.org/wiki/Thought-terminating_clich%C3%A9 https://en.wikipedia.org/wiki/Thought-terminating_clich%C3%A... now
- octoberfranklin 6mo agoThe funding for tor project is nowhere near what is needed to develop an entire browser. Mainly because the web has become such a bloatfest, not because of any wrongdoing by tor.
- Barbing 6mo ago>Why don't browsers make it like phones where the server (app) has to be granted permission to access stuff? Like Android phones perhaps? Unfortunate Apple gives very little granular control.
- Joe_Cool 6mo agoMost stock android phones don't either. You usually get to control precise location, notifications, some background activity, SMS, Calls, Mic, Camera, SD Card, etc. But most ROMs don't allow controls for WiFi, Cell data, Phone ID, Phone number, User ID, local storage, etc...
- kelvinjps10 6mo agoall these permission you have to accept?
- chneu 6mo agoYes. A few apps have been caught doing nefarious stuff using advertising sdks, like meta, but on android most apps are well sandboxed and can only access what you approve.
- Joe_Cool 6mo agoFor those things you can't control it doesn't ask. You can see those under "other permissions" (or similar). But once you look there it's too late if you care about this data and forgot to turn on airplane mode.
- kingstnap 6mo agoI mean Google ain't paying for Chromium development just for the fun of it...
- subscribed 6mo agoHah. It's still better than apps. Apps have access to inconceivable amounts of identifiers and device characteristics, even on the well protected systems without Google Play services.
- troupo 6mo agoIt's a fine line between making the web usable, fingerprinting, and peppering the user with dozens or hundreds of permissions. And since browsers rival OSes for complexity (they are basically OSes in their own right already), any part of the system can be inadvertently exposed and exploited.
- deleted 6mo ago[deleted]
- michaelt 6mo agoBrowser fingerprinting is an unintended side-effect of things it's sorta-kinda reasonable for browsers to provide. A user agent that says the browser's version? Reasonable enough. Being able to ask for fonts, if the system has them? Difficult to have font support without that. Getting the user's timezone, language and keyboard layout? Reasonable. The size of the screen, and the size of the browser window? Difficult to lay things out without that. Of course a video or audio player needs to know which video formats your browser supports - how else to provide the right video? Obviously javascript can get the time, and it's trivial to figure out the system's clock error by comparing that to the time on a server. Before you know it, almost every browser is uniquely identifiable.
- sandworm101 6mo agoThe tor project seeks this bypass this by keeping such things standardized across users, even down to reported screen size. And there is nothing stopping the browser from fibbing as most settings dong matter all that much (ie UK v Canadian v American English).
- autoexec 6mo agoThis is a bad idea though, because any newly discovered means to get even a single data point results in being able to ID every tor user. I'd be better to have every tor browser always generate a random fingerprint so that even if the unexpected happens people will never get anything but random results.
- rendx 6mo ago> to have every tor browser always generate a random fingerprint Browsers do not "generate" fingerprints. They expose data that can be used to fingerprint users. You cannot "randomize" this; even if you were to return random values for, say, user screen size, with various visual side effects, it would just be another signal to fingerprint: "Oh, your browser is returning random values? Must be a Tor browser user".
- snowwrestler 6mo agoAnd yet this sort of endless (fingerprintable) browser feature list is what people cite when they claim that mobile Safari is somehow way behind Chrome, and how it’s a travesty that Chrome can’t natively implement all these (again, highly fingerprintable) features on the iPhone.