4 ms·
This would be the only problem it solves, then, since blocking 3rd party cookies does almost nothing to stop tracking.
by thirsteh 12y ago
This would be the only problem it solves, then, since blocking 3rd party cookies does almost nothing to stop tracking.
- millstone 12y agoWhy is that?
- taf2 12y agoWhen you remove the obvious way to track the resulting solutions are much much harder to prevent or even be aware of e.g. Fingerprinting, cache headers and others
- thirsteh 12y agoTake a look at the results on http://www.areweprivateyet.com/ http://www.areweprivateyet.com/ The methodology is described here: https://cyberlaw.stanford.edu/blog/2011/09/tracking-trackers-self-help-tools https://cyberlaw.stanford.edu/blog/2011/09/tracking-trackers... Even the DNT header, which is widely recognized as a failure since it relies on the perpetrators to regulate themselves, protects you better against tracking than blocking third-party cookies. It's just too easy to track people by other means, and the companies that aren't already doing it will certainly start if a meaningful number of people suddenly block third-party cookies. The only pragmatic and effective way to avoid being tracked today is to use something like uBlock (more efficient ABP + noscript) with the third-party script and frame blocking features enabled (whitelisting third-party scripts/frames only on those sites that break something you want to see at the cost of possibly being tracked by something the block lists don't catch.)
- erglkjahlkh 12y agoThank you for good links. What is also somewhat scary is font enumeration. It is somewhat uncommon to find two computer with the exactly same set of installed fonts. I have noticed that especially on Windows platform many applications bundle their own fonts, and the resulting sets are very good for fingerprinting systems.
- thirsteh 12y agoIndeed. Some interesting research is being done on this: https://github.com/ghostwords/chameleon https://github.com/ghostwords/chameleon
- gsnedders 12y agoAlso, it's worthwhile noting the DNT header just provides another piece of input to the fingerprinting matrix.
- pdkl95 12y agoI doubt anybody really expected the DNT header to actually stop anything. Sometimes there is value in stating your position clearly, and the DNT header provides a standard, unambiguous way of doing that. It is a lot harder to claim that your users wanted tracking as a "feature" (or that asking their opinion was to difficult or impossible) when lots of of the HTTP requests have a header that explicitly states users' opinion.
- thirsteh 12y ago...and it's completely pointless when your browser enables DNT by default, putting us back to square one.
- wtallis 12y agouBlock can block scripts, but that doesn't make it a replacement for NoScript, which has quite a few features beyond simple script blocking.
- revscat 12y agoETag manipulation + HTTP headers, zero-width images combined with browser fingerprints, HTML local storage. I'm sure there are others.
- hrjet 12y agoEven the HSTS header can be used for tracking: https://bugzilla.mozilla.org/show_bug.cgi?id=930638 https://bugzilla.mozilla.org/show_bug.cgi?id=930638
- kvbr 12y agoNot just HTTP, there is plenty of information in lower layers too. For example, this page will show your exact computer uptime, down to the millisecond, using the tcp/ip timestamp feature (OS dependent, works on linux kernels 3.12+ and some Windows and Mac versions): http://lcamtuf.coredump.cx/p0f3/ http://lcamtuf.coredump.cx/p0f3/ 10-20 bits of entropy right there (you need 33 bits of entropy to uniquely identify 1 of 6.6 billion people on earth). ...or traceroute of the user's routers, done within the confines of an existing TCP/IP connection, bypassing every stateful firewall and address translation (exhibit 3 in page): http://lcamtuf.coredump.cx/mobp/ http://lcamtuf.coredump.cx/mobp/
- deathanatos 12y agoI get some odd results: HTTP client = Opera 15.x-18.x (User-Agent string is fake) I'm on Chrome, and not faking a User-Agent. Uptime = 9 days 17 hrs 17 min (modulo 49 days) This is just wrong. Everything else was correct, but everything else is available in HTTP headers, so isn't really that interesting. > 10-20 bits of entropy right there (you need 33 bits of entropy to uniquely identify 1 of 6.6 billion people on earth). This reminds me of this[1]. [1]: https://panopticlick.eff.org/ https://panopticlick.eff.org/
- kvbr 12y agoYou may be behind a transparent proxy, or have a user-agent string not in P0f tool database. Vardump: notice that you get almost the same uptime for your Mac and your Windows PC: 19 days 18 hrs 10 min. It appears your router (NAT) is handling / modifying the tcp/ip timestamp. Btw, even if the timestamp is wrong, it can provide some entropy (=measure of uniqueness compared to other users).