4 ms·
All fingerprinting is a vulnerability, unless the client opts-in.
by stackghost 5mo ago
All fingerprinting is a vulnerability, unless the client opts-in.
- lmz 5mo agoThe opt in checkbox is labeled "Enable Javascript"
- ranger_danger 5mo agohttps://fingerprint.com/blog/disabling-javascript-wont-stop-fingerprinting/ https://fingerprint.com/blog/disabling-javascript-wont-stop-... https://github.com/jonasstrehle/supercookie https://github.com/jonasstrehle/supercookie
- autoexec 5mo agoWhen I go to https://noscriptfingerprint.com/ https://noscriptfingerprint.com/ all I see is a blank page. My browser is pretty locked down in other ways which probably helps, but I'm still taking that as a good sign.
- ranger_danger 5mo agoThe site seems to have been taken offline, but the code is here: https://github.com/fingerprintjs/blog-nojs-fingerprint-demo/ https://github.com/fingerprintjs/blog-nojs-fingerprint-demo/
- danlitt 5mo agoRidiculous comment. People should not have to choose between functionality and privacy.
- eimrine 5mo agoImplement it then.
- zelphirkalt 5mo agoShould not, true, but in the case of many websites the reality is that allowing JS means you lost your privacy. Just like one cannot allow webgl and canvas by default any longer. Thanks to all the web devs who helped creating this web dystopia.
- danlitt 5mo agoYes, my point is that this does not mean it is an "opt in checkbox". I appreciate that it allows people to be nasty, it just isn't a "please be nasty" toggle.
- ZiiS 5mo agoYou can't go out in public naked and just ask everyone to look away. If you want someone you don't trust to run unvetted general purpose code on your machine you have to accept that you are trading away some privacy. You can sandbox them (wear cloths) but that doesn't give you strict privacy.
- stackghost 5mo agoIt's not a binary situation. Lots of fingerprinting is based on e.g. audio or canvas rendering quirks. Browsers should be obfuscating that shit.
- ZiiS 5mo ago100% we should ensure that Browser's restrict fingerprinting as much as posible. I certainly set my Firefox to have many inconviniencies to reduce the fingerprint. I am just saying this is an engineering compromise and the tradeoff will be different for different people. Wishing we can have our cake and eat it dosn't help; you do have to choose between privacy and functionality.
- danlitt 5mo agoI do wear clothes (all JS code runs in a sandbox). This is a bit like saying "you should lock the door to your house" and therefore refusing to prosecute someone who steals from a house with a broken window frame. I did lock my door, and it's still a crime regardless!
- ZiiS 5mo agoI did not mean to excuse Firefox leaking this identifier or suggest we shouldn't strive to be as secure as possible. I just took issue with the blanket statement "should not have to choose". As well as making the Browser as secure as possible we also have to chose to limit functionality.