I didn't set a cookie. (kuber.studio)
from yogthos@lemmy.ml to privacy@lemmy.ml on 09 Aug 16:11
https://lemmy.ml/post/51166852

#privacy

threaded - newest

Maeve@lemmygrad.ml on 09 Aug 17:36 next collapse

So I tried this in *Privacy Browser, mojeek search engine, with and without .js. Thing is, most websites are designed not to work, without it. I could use some help with settings, if anyone is inclined.

Also, that made my fingerprint much more unique. It almost seems worse.

unitedwithme@lemmy.today on 09 Aug 18:06 next collapse

Having a unique fingerprint I swear is just a way to scare people into compliance. Unique doesn’t always mean known. Sure, it’s unique that they can’t track you so well. Oh no…

I feel if 1 out of 200 people had this unique fingerprint, it’d be hard to distinguish who’s actually who. No distinct way to really differentiate with such little data being allowed to be gathered.

Maeve@lemmygrad.ml on 09 Aug 18:08 next collapse

One out of 119k.

Edit: but yes, I am satisfied. I just need to know how to do settings so .js IS enabled but also not so evil (and I doubt it’s possible), as well as just general functionality with privacy, if that’s even possible.

Carrot@lemmy.today on 09 Aug 18:27 next collapse

I’m 1 in 166 million lol, I think I’m easy to track, however a lot of the data is wrong so not sure how to feel

LincolnsDogFido@lemmy.zip on 09 Aug 18:52 next collapse

The paradox is that your traffic is so unique that it can be compared to traffic captured from other websites you’ve visited and be used to build a profile around your commonly visited websites and current interests.

That fingerprint is then sold to brokers that forward to websites that will serve targeted content to your fingerprint when you do happen to show up. It doesn’t necessarily care what your identity is just that you have an identity.

unitedwithme@lemmy.today on 09 Aug 19:34 collapse

But if you’re not running multiple tabs, or in private tab view, and you’re not allowing most or any cookies, then they’re going to have a harder time following what you do and where you go.

  1. Use a solid VPN
  2. Use Firefox derivative (Waterfox and Libre Wolf, feel free to use multiple to separate tracking)
  3. Use pivate tab mode
  4. Use Privacy Badger (EFF)
  5. Use Port Authority (highly rated port scan blocker to block network port scanning from LexisNexis)
  6. Close unused tabs
  7. Clear cache and cookies on exit
  8. Disable unused network stuff (WiFi and/or data, GPS, BT, NFC, anything that’s not required that could be used for location scanning)
  9. On Android 15+ iirc, disabled mic and/or camera permissions until necessary. Most people don’t talk on the phone anymore so it’s rare you need the mic (unblock for camera)
LincolnsDogFido@lemmy.zip on 09 Aug 19:38 collapse

I shouldn’t need a 9 point checklist to browse the internet. I’d rather there be proper user protections in place.

unitedwithme@lemmy.today on 09 Aug 19:41 collapse

Oh for sure! I agree! But I do the following, mostly automated through settings, to either poison the data or avoid them from getting it at all.

tyler@programming.dev on 09 Aug 18:57 next collapse

For me my fingerprint is unique, but the advertisers list was empty so yeah, it’s pretty pointless when you have Adblock at a dns level. You can be identified by first party sites, but that requires visiting every advertisers site to actually get them to fingerprint you. Otherwise your data won’t and can’t be sold realistically.

partofthevoice@lemmy.zip on 09 Aug 19:00 collapse

Imagine enough data was random that it was always unique. Never duplicate.

Or if that’s some kind of issue, then instead allowing the user to randomize their fingerprints by click of button. Surely there’s some kind of spoofing, virtualization, something that browsers can do to effectively “randomize” the measured fingerprint by third parties.

unitedwithme@lemmy.today on 09 Aug 19:38 collapse

I use Fake Traveler to spoof location sometimes. I sometimes do this while shopping for various travel things that are affected by region… If you catch my drift.

f-droid.org/packages/cl.coders.faketraveler

MonkderVierte@lemmy.zip on 09 Aug 20:25 next collapse

Also, that made my fingerprint much more unique. It almost seems worse.

Unique but useless data.

yogthos@lemmy.ml on 09 Aug 21:44 collapse

yeah turning off js means that you can’t really use most sites

Maeve@lemmygrad.ml on 10 Aug 01:35 collapse

I had to edit the post you answered here, for accuracy. Cloudflare on kbin.earth isn’t having it, for anything. I checked the box to prove I’m human a dozen times, with .js and cookies enabled, and the whole shebang just noped. 😋

yogthos@lemmy.ml on 10 Aug 01:48 collapse

ha

lnxtx@sopuli.xyz on 09 Aug 18:27 next collapse

Needed to enable JS.

sulfidedisburseangledafternoontipper@piefed.blahaj.zone on 09 Aug 19:27 next collapse

Ironfox seems to do its job. Me fingerprint every time. Vanadium as well (though it does disclose more in-depth device data).

communism@lemmy.ml on 09 Aug 19:51 next collapse

A small point but it assumes that your browser’s self-declared timezone is “true” to where you live. My timezone is spoofed to UTC+0; my VPN server is in a different country; and my browser language is set to en-us. I feel like if you see a user whose settings are all of the above then you can assume that none of those three data points actually describe the user, unless they coincidentally are a US English speaker or live in UTC+0, but that’d just be them coincidentally living where anti-fingerprinting browsers report you as.

kungen@feddit.nu on 09 Aug 20:09 collapse

Anti-fingerprinting is a fingerprint too.

MonkderVierte@lemmy.zip on 09 Aug 20:13 next collapse

Only if too few people do it.

communism@lemmy.ml on 09 Aug 20:51 collapse

I know that…? I’m not sure how this relates to the comment you replied to.

hirihit640@sh.itjust.works on 09 Aug 21:16 collapse

they are just warning other readers who might read your comment and think “oh I should spoof timezone and language too”. To those readers: don’t spoof these yourself, find a browser that has fingerprint resistance on by default, like Tor or Mullvad Browser, and don’t change the defaults. The goal is to blend into a crowd of users with the same fingerprint

communism@lemmy.ml on 10 Aug 11:41 collapse

Ah ok, sorry I read that as correcting me and got confused. But yes, you are right, it is a fingerprint, the point is to just share as much of your fingerprint as possible with other users to make it hard to differentiate you.

My comment was about how the OP website has a line that claims that the reported timezone/language is the “truth” rather than my IP address, and I was just pointing out that that wasn’t the case.

FineCoatMummy@sh.itjust.works on 09 Aug 20:41 next collapse

What it got right,

  • My OS. It’s in the user agent header, which I hate.
  • I read the page methodically at a human reading pace.
  • I am using a VPN.

What it got wrong,

  • Location.
  • Screen res.
  • Num of CPU cores.

It’s good for ppl to think about fingeprinting. So demo pages like this are good. But I’m sure the identity resolution industry is MUCH better at it. They have capabilities like TLS fingerprinting, outside the browser. For most ppl, not the privacy crowd so mcuh but normal ppl, they fingerprint resource fetches to diff geographic servers. They can run 100’s of scripts on a single page from every identity broker. They employ the best data scientists, to figure out every possible way.

I’m pretty careful. More than 99.999% will ever do. Can commercial fingerprinters still ID me? IDK. But like Skywalker, I have a bad feeling about it.

GaumBeist@lemmy.ml on 10 Aug 01:14 next collapse

They can run 100’s of scripts on a single page from every identity broker. They employ the best data scientists, to figure out every possible way.

The impact of this is probably greatly reduced by anti-JS measures like NoScript. Some sites probably still bundle fingerprinting code into their own scripts, but the really big players contract that out to companies whose entire purpose is data-harvesting, and that’s easily defeated by denying scripts from outside domains

FineCoatMummy@sh.itjust.works on 10 Aug 14:42 next collapse

the really big players contract that out to companies whose entire purpose is data-harvesting

For sure, blocking those scripts goes a LONG way. But that’ll only work until lots of ppl do it. If it ever catches on big, the Identity Brokers will adapt. They’ll integrate their shit into sites in ways that are hard or impossible to separate this easily without totally breaking the site you were trying to visit.

IDK for sure, but I fear we could be living on borrowed time.

GaumBeist@lemmy.ml on 14 Aug 21:43 collapse

As long as there’s an incentive to violate privacy, it will always be an arms race. The upside is that we’ll get better and keep adapting just as they do.

Daefsdeda@sh.itjust.works on 10 Aug 17:03 collapse

I liked the idea of noscript but, it just wasn’t practical to adjust it to every site which scripts should run and which shouldn’t

GaumBeist@lemmy.ml on 14 Aug 22:19 collapse

Yeah, it definitely makes browsing a lot more hands-on, and the lack of cross-device syncing means that you’re constantly duplicating work. There’s probably a way to export settings and diff/patch and sync the settings files for each device, but I just haven’t bothered; seems like a lot of time investment to automate something that takes me seconds to do manually.

On the other hand, there were two big shifts for me after I started using it. One was when I got the sites I use frequently all set up after a few weeks, it became a lot smoother sailing after that. The other was when I finally took the minute to find the setting to default (temporarily) allow, but only for the current domain (after like a year or two on default deny everything).

It’s now rare that I visit sites where I feel like I’m missing out without the added scripts. The only times that has really changed is when everything started implementing anti-scraper measures, and sites along the high seas that have trouble streaming videos from other servers.

iglou@programming.dev on 10 Aug 13:59 collapse

It doesn’t really matter if they got it right or wrong, as long as it’s consistent. The goal isn’t to know your location, screen res, or cpu core count, it’s to track you across websites.

FineCoatMummy@sh.itjust.works on 10 Aug 14:23 collapse

Yah. I agree. Which is why I think, it is often better to randomize the fingerprint every time, than TBB’s approach. Tor is still good for the onion routing, ofc. But I’d like a semi random return on screen res, timezones, and w/e.

sculptor0725@sh.itjust.works on 09 Aug 21:00 next collapse

Interesting. The only thing that really surprised me was the time zone thing. Can I hide that somehow?

aim4harmony@lemmy.world on 10 Aug 00:14 next collapse

Yes, the time zone can be spoofed via browser settings or with an ad-on.

irotsoma@piefed.blahaj.zone on 10 Aug 04:10 collapse

I know IronFox and some other forks have a setting to change your timezone to UTC-0. But you’ll have to live with remembering to convert time on most websites unless you log in and your profile sets the timezone. Not a huge deal, but it trips me up more than I’d like to admit. Especially since I avoid sites that require logins. I have heard that you can get a browser plugin to change the time locally, but you’d have to trust the plugin since it will need access to all content on all sites.

olafurp@lemmy.world on 09 Aug 21:50 next collapse

“Remember me on this device”

Maeve@kbin.earth on 10 Aug 17:00 collapse

Even without that, they track you, if you're not taking proper precautions, from a social media button to a pixel (meta's infamous wtfery, for example.

olafurp@lemmy.world on 10 Aug 20:28 collapse

Yeah, it was intended as a joke, as in they already remember whether you check the box or not based on just the browser fingerprint.

irotsoma@piefed.blahaj.zone on 10 Aug 02:09 next collapse

I mean “1 in 122.7 million browsers look like” mine meaning it got me down to one out of about 2% of all internet users globally. I’d say it’s still pretty difficult to target anything at that many people and have it be relevant. Just knowing my location and that it’s a weekend basically gets down to that many or maybe fewer people on it’s own since fewer than that live in my city permanently, and adding tourists/visitors and people who work on weekends, that might be about right for how many devices are online in my city right now. And that was browsing with my less locked down browser on my phone.

Actually, looking with ironfox, though, actually reduced that to about 112m. I think part of that is that ironfox apparently still seems to enable the “do not track flag” even though it was removed from Firefox because it actually made people more easy to track and no sites who track are ethical so they are not going to obey something like that. So now it’s rare and makes for a really good tracking point. Need to figure out how to remove it from ironfox I guess.

pineapple@lemmy.ml on 10 Aug 12:15 collapse

Your math is not mathing, 100/122,700,000=0.000000814995925% not 2%

Also this seems to be a vibe coded website and probably doesn’t use the most advanced fingerprinting techniques. Most likely your browser is actually unique if you go to https://amiunique.org/ you might get a more accurate answer.

irotsoma@piefed.blahaj.zone on 13 Aug 03:18 collapse

I was doing a little more complex math than just the 1 in 122.7m. That seems to be unique browsers not unique human users. I added some calculations based on how many browsers are used by humans vs bots and various other nonhuman users. It’s extreme rough with a lot of guesstimation and rounding based on some googling. But that’s beside the point.

I was trying to figure out the difference between fingerprinting a Mozilla Firefox browser from the play store and the IronFox browser from Fdroid. I had expected it to be significantly reduced accuracy since it’s explicitly set up to be more resistant to fingerprinting than vanilla Firefox.

When I did some digging and looking at other sites. The biggest factor seems to be the combination of it reporting Firefox as the agent and having the DNT flag and the global privacy flag or whatever it is called. Since only Germany has been able to enforce those legally and only in a single case against LinkedIn, but no cases against the bigger tracking companies that aren’t user facing and thus wouldn’t even care about legal stuff since proving standing with that many layers would be difficult, Mozilla decides to remove those a couple of years ago as many people weren’t setting them and so it made people who were setting them more susceptible to fingerprinting since they were more unique. IronFox has argued that the settings should stay on because it’s legally enforceable in Germany and maybe some day will be I’m other places. But IMHO that doesn’t help people getting fingerprinted now or for the next many years. And now since IronFox is basically the only one doing it, the combination of Firefox agent and that header flag means it narrows you down to IronFox users almost exclusively other than maybe some people using really old versions of Firefox, but you could add some criteria that gibe you the version, too, and how many of those are there in the world. A very small percentage of all internet users. And combine that with UTC offset and if you live somewhere like UTC-1 I bet you’re the only user. LOL.

But even in other less tech savvy areas of the world it would be pretty small and a few more data points could easily get you a unique user. People in places like UTC+2 or mainland US, probably there are a lot more privacy thinking folks using IronFox or any other.

Anyway, I changed those settings manually in about:config based on feedback from the IronFox dev that it was set on purpose. But I haven’t had a chance to see how much less unique it made me yet.

melroy@kbin.melroy.org on 10 Aug 02:26 next collapse

Today all websites that have anti bot protection using pow (proof of work) already use cookies. Which is before they "ask you if you want to agree with cookies" haha. Dammit eu rules.

bountygiver@lemmy.ml on 10 Aug 03:25 next collapse

ya the cookie law is outdated and short sighted, the law should instead extend to ability to consent to send any identifying information instead. (Easier to investigate and potentially punish websites that do not respect the setting)

melroy@kbin.melroy.org on 10 Aug 16:25 collapse

The browser can disable cookies if you want since 1996. So this law was from the beginning outdated. Xd

Rather then removing it. They are extending this law with additional rules and design ideas. 😭😰

Maeve@kbin.earth on 10 Aug 16:56 collapse

❤️

iglou@programming.dev on 10 Aug 14:03 next collapse

A website doesn’t need to ask you for consent if the cookie is “strictly necessary”. I’m not sure how those anti bot protections work, but I bet they made it fit the definition of a “strictly necessary” cookie.

melroy@kbin.melroy.org on 10 Aug 16:22 collapse

I know. I don't want those stupid cookie banners. Hence my "dammit eu rules".

I created my own anti bot protection see https://angieguardian.org. So basically all of them use cookies after you completed a pow or captcha. So next time you load the page it doesn't ask you again. Those cookies may expire within several hours until 1 week depending how the server/anti bot software configure them.

Jako302@feddit.org on 10 Aug 16:24 collapse

That are technically required cookies, they require explicit consent

Hadriscus@jlai.lu on 10 Aug 10:30 next collapse

Amazing and terrifying. Thanks for the link. I am not very technical when it comes to the web so this was eye opening.

I used to have a small Firefox extension that would stagger my key presses to muddy the waters, but it made typing impractical, so I eventually removed it.

I wonder what else I can do on my end. And most importantly, what browsers can do for all their users, technical and not, by default.

RodgeGrabTheCat@sh.itjust.works on 10 Aug 12:38 next collapse

On my Android, Brave gave a different fingerprint both times I visited.

The site thinks both times was my first visit.

The site believes I have either a 4 core or 2 core cpu. I have an Octa-core.

Also, it shows a different display size both times.

Nearly all sites like this can do nothing without javascript turned on.

I’m curious to see how Librewolf is, but that will wait until after work.

Edit: Librewolf does indeed produce a different fingerprint each time. It also didn’t give up my location like Brave did on my GrapheneOS phone.

I have since changed the timezone on my phone to a country to the South within the same timezone so the clock remains accurate.

graynk@discuss.tchncs.de on 10 Aug 12:57 collapse

Visited it with LibreWolf (javascript turned on). The only thing that it got right was that I am on Linux, that I have an x86 processor and that I have LaTeX fonts installed.

I refreshed the page, the data shown was the same, but the fingerprint was different.

RodgeGrabTheCat@sh.itjust.works on 10 Aug 17:02 collapse

Same. Cores, screen resolution are off. Fingerprint is different for both visits.

Shindo66@lemmy.world on 10 Aug 12:57 next collapse

Does it know i like watching girls lick each others vaginas?

Goodlucksil@lemmy.dbzer0.com on 10 Aug 16:57 collapse

Now everyone on the internet knows (Sorry, couldn’t resist)

AstroLightz@lemmy.world on 10 Aug 17:55 collapse

Cool site, but breaks when you disable JavaScript. I wonder if you could trick it into thinking you’re a bot.

yogthos@lemmy.ml on 10 Aug 18:33 collapse

Most modern web breaks without Js though.