3 ms·
How? How would a browser "know" what classifies as finger printing? Literally every piece of the engine is used for finger printing. It can be mitigated, a bit
by miki_oomiri 1mo ago
How? How would a browser "know" what classifies as finger printing? Literally every piece of the engine is used for finger printing.
It can be mitigated, a bit, but I don't see how browsers can win that battle.
Finger printing is a lost battle in my opinion, unless we drastically reduce what a web engine can do (like Tor does).
- lxgr 1mo agoI feel like there are two levels of fingerprinting here, and a lot of the confusion is downstream of not properly distinguishing them: There's the kind that tries to find out what browser vendor, OS, and sometimes hardware you use, and the kind that tries to identify you across visits, unrelated origins etc. I agree that the former is probably inherently impossible to avoid to a large extent, but the latter is both a bigger privacy issue and at least in theory possible to prevent.
- Bjartr 1mo agoI've only encountered the latter described as fingerprinting. Which makes sense side, like fingerprints, the information is being used to uniquely identify an individual. The former is traditional analytics and is not enough to uniquely identify an individual. Not all analytics are as privacy invasive as fingerprinting.
- john_strinlai 1mo ago>The former is traditional analytics and is not enough to uniquely identify an individual shockingly little information is required to uniquely identify someone. "traditional analytics" (lets just say os + browser + some hardware info) is likely to be uniquely identifying when combined with just one other sparse dataset. >Not all analytics are as privacy invasive as fingerprinting. fingerprinting isn't a separate category of analytics. every data point can be (and often is) used for fingerprinting.
- bigbuppo 1mo agoJust assume any site using javascript is using it for nefarious purposes.
- pajko 1mo agoFingerprinting cannot be resisted. There are a zillion techniques to get bits of information which can provide a unique-ish identifier when combined. The only protection is to mix in some random data in all these bits to get a very unique combination that changes on each request. But this only works if at the same time cookie and local storage access is disabled for all sites and whitelisted per site:target combination.