Privacy Badger – Block spying ads and invisible trackers
eff.org
eff.org
Another fantastic extension from the EFF team with collaboration from The Tor Project, is HTTPS Everywhere, get it here https://www.eff.org/https-everywhere
[0] https://github.com/samyk/evercookie/
[1] http://www.theregister.co.uk/2015/01/30/verizon_uidh_super_c...
Good starting places for the current heuristics:
https://github.com/EFForg/privacybadgerchrome/blob/stable/sr...
https://github.com/EFForg/privacybadgerchrome/blob/master/sr... https://github.com/EFForg/privacybadgerchrome/blob/stable/sr...
A good example of this is many of the webcomics I read. Many of the adds on those sites are for other webcomics, I've found a couple of good new webcomics that way.
And if you like a site you can enable it.
Go ahead, call me crazy like most people do.
Rough config for surf: https://gist.github.com/jakeogh/b23aac080c5c74310c88
Security/privacy doesn't have to be all-or-nothing.
The Internet Explorer security model has 4 levels (Internet, Local Intranet, Trusted Sites, Restricted Sites) and you can choose a preset security settings package, or build your own, for each level.
Maybe Chrome/FF/Safari need something more similar to that, where we can specify different groups or levels, and then assign those to websites we visit.
The biggest problem with the IE method is that the UI is more tedious to add a site to a zone in IE11, than to add a site to the JS whitelist on Mobile Chrome.
The navigator.plugins array is now sorted alphabetically [2] to avoid an issue documented in Jonathan Mayer's thesis [3]. Gecko and WebKit sorted the navigator.plugins array by the plugins' "last modified" time. Users with the same plugins installed can still have unique fingerprints because it is unlikely that they installed their plugins in the same order.
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1169945
- There is no such thing as "minor" reduction in fingerprinting nowadays. This is a war, every little bit is important.
- I much prefer to have a thousand sites broken and a little bit more of privacy (or the feeling I'm doing all I can).
- A lot of people (me included) do not use Flash anyway.
Thank you for your work!
That said, I find it difficult to agree with the decision to remove features like this. So what if it can break websites? Isn't that what the "This might void your warranty!" warning is for? It seems far better to give users the option of viewing the web the way they want to view it, rather than protecting them from some broken websites at the expense of their privacy.
By the way, Panopticlick is outdated (is it even maintained anymore?). You should use https://browserleaks.com
Of course, this doesn't say anything about stopping those invasive noisy ads or ads that block content, so I may still have to keep using uBlock. Maybe in some future ideal world, advertisers will learn that if they want me to see their ads, at all, they have to respect my privacy, my time, and my attention.
Maybe someone needs to make a "show only ads from people who aren't assholes" plugin.
Maybe there's something to be said for that...put your money where your browser is and support the web you want. You could also just donate to the EFF, I guess.
ABP also considers ads that track people (such as Google's) to be acceptable and whitelists them by default.
https://adblockplus.org/en/acceptable-ads#criteria
If you make a modern-looking long-scrolling article that has an ad somewhere in the middle, it's not "acceptable". If you get a crappy CMS that splits every article into 9 pages with an ad at top and bottom, then it is.
The main weird thing is that 3rd-party tracking is "acceptable" (!)
(I recently added some details on the problem to the Aloodo tracking test, because users have started to assume that ad blockers fix everything. http://blog.aloodo.org/posts/adblockers-myths-facts/ )
[1] http://www.businessinsider.com/google-microsoft-amazon-taboo...
Isn't that the whole point of an ad?
- uBlock Origin
- Self-Destructing Cookies
- BetterPrivacy
- HTTPS-Everywhere
- Privacy Badgerhttps://addons.mozilla.org/en-US/firefox/addon/random-agent-...
because of this:
There might exist some other fingerprints that can lead to the knowledge of what browser you're using (the existence or non-existence of some feature, etc). If your User-Agent contradicts those others fingerprints, you become very easy to identify. It's really difficult to consistently pretend having a given configuration unless you are, well, actually running this configuration.
More generally, the more you use technologies to protect your privacy, the more you increase your fingerprint entropy, that is, the more it's easy to identify you.[1]
I wouldn't advice those "spoofing" tools, but rather to use the browsers' settings at the maximum of their capabilities (disable third-part cookies, delete cookies when closing the session, set Flash to 'Ask to activate', etc) and just the minimum extensions set to block third-part requests in a first-place (Disconnect, etc).
https://www.torproject.org/projects/torbrowser/design/#finge...
Maybe just make their User-Agent the standard?
I'll add to the list: Uninstall Flash completely. For much of the crowd here, that's probably a no-brainer after the recent spate of Flash zero-days, but still.
Many of the sites that I use the most load very little unneeded resources and I tend to leave lots of tabs open while working.
Granted, I am not a "normal" web user, but so far all of the responses to my question have brushed it off as unimportant. My suspicion is then that they don't know the answer, which makes the brush off unconvincing.
Yes, that's obviously true. But for my part, whatever overhead these tools do add is low enough that, even for no-crap sites like HN, if I can notice it at all it's within the page-load-latency noise threshold. Moveover, the increased browser stability, laptop battery life, etc. is an overwhelming win.
FWIW, I just fired up Chrome on HN and messed around with the dev tools a bit to see if there was any obvious overhead. Without taking the time for anything like rigorous analysis, loading HN with all extensions disabled vs. uBlock Origin and Privacy Badger had no immediately obvious effect on page load+render times. The superficial results agreed with my intuition: I'd have to collect data and run an analysis to uncover any added page load latency.
I rarely run into situations where I need to fiddle with both to unblock a script or embedded video, but for the most part the combination is pretty reliable.
I also like seeing the long lists of adware Ghostery is blocking as the page is loading. You'd never know some pages have 50-60 scripts getting loaded to track what you do. It was an eye opener the first month I was using it.
Why do you use both, though? Aren't they pretty much perfectly overlapping?
Plus with Privacy Badger, it gets better the longer you use it:
The salient difference between Privacy Badger and the other extensions is that Privacy Badger’s blacklist is generated through heuristic blocking, which means it gets better the longer it is used. Out of the box, Privacy Badger won’t block nearly as many third-party requests as the commercial options, but as you use it more, it will learn more and more hosts to block
https://gigaom.com/2014/05/11/not-all-ad-blockers-are-the-sa...
Privacy Related:
- NoScript
- Random Agent Spoofer
Generally Useful: - RefControl
- The Addon Bar (restored)
- UnloadtabPerhaps when Privacy Badger does more for detection of first party stuff, then I'll add it back again.
[0]: https://addons.mozilla.org/en-US/firefox/addon/umatrix/Obviously wireshark would get you 50% of the way there - to add to that then, a pretty UI focussed on scaring users with what information is being leaked - hostnames for SSL sites they're visiting for example.
There are also tensions between trying to identify leaks to a network eavesdropper and trying to identify leaks to a remote site (or ad network). In many people's analysis, the network eavesdropper is worse because you didn't mean to communicate with them at all, so any information they derive whatsoever is a pure loss of communications security. But for projects like Tor Browser and Privacy Badger, it counts as a loss of privacy if different sites can recognize you as the same user, even if you intentionally communicated with those sites.
Using HTTPS will prevent a sniffer from recognizing that some tracking cookies or identifiers are being sent, so you simultaneously get a true improvement against the network adversary and a false negative measuring privacy against the ad networks.
You're right about false-negatives with sniffers. If you read the source on pages you visit, you'll see https analytics data mining, so don't assume that every outgoing https connection is okay. (and some browsers don't use your normal DNS / hosts settings, so sites you think are blocked may not be)
Surely there's already something to do this aside from a full sniffer?
- Tell me whenever something that looks like an email address is sent in the clear
- Tell me whenever my name/postcode/other user-specifiable text is sent in the clear
- Tell me when I'm connect to an SSL site but the hostname is leaked
- Keep a list of DNS entries that I'm leaking
The real challenge will not be to capture everything, it'll be trying to show up items of interest.
This makes me sad. They should have based it on uBlock. ABP is very bloated, and really caused issues for my browsing experience. Not sure if I want to try it after reading that.
I hope you consider things like blocking loading of webpage icons, and something to deal with data being appended to redirects or even CSS calls when cookies are disabled. I'd read about detecting caching of slightly different colored versions of icons and beacons. Sneaky offsite https accesses (analytics etc) are commonly bundled in a pages JS and NoScript doesn't alert to that. Also, some browsers seem to make accesses to a number of sites on startup, before even going to open a page.
Widening the view from "advertisers" to data-mining contractors that even do drive-bys, it might also be worthwhile to study what could block local data broadcasts by code designed to modulate r.f. noise leaking from our machines. Tune across the A.M. broadcast band on a nearby battery operated radio. I've noted that sometimes there's much more pulsed/bursty noise that doesn't seem to be tied to any obviously more demanding content.
Some of the insideous Ad-Choices content seems to go beyond Flash for hiding data. From the plugin being called when there wasn't any visible content needing it, I think even Quicktime is being used to cache data. It would really help if scripts from one tab could not be accessed by another, and were killed on closing the parent tab. I guess the litterboxing would best be done by a trusted browser? Bring on the worming tablets!
Could you clarify this point? I may well simply be misunderstanding, but a quick check of a hosts-blocked site using Safari, in El Capitan, does indeed not resolve (or rather, resolves to localhost, as specified).
The bigger question today is whether Privacy Badger has value in light of uBlock… I don't know… anyone?
Personally I use uBlock and Privacy Badger. I'm not sure if it's entirely redundant, but I have not had any bad experiences with using both.
Blocking ads and using reusable water bottles are socially responsible, positive behaviors. Anyone encouraging ads or encouraging bottled water (or worst: encouraging bottled water ads) should be ashamed of the harm they're doing to the world.
This is mostly with an earlier version; I just upgraded to 1.0 today.
That's exactly what I thought. Interesting that they're so hostile to non-JS people.
There's another trick that works on many sites, including this one. Keep JS disabled but do View/Page Style/No Style. IMO the site looks better that way than with JS enabled.
Edit: one other trick I use frequently in Firefox for sites with poor contrast. Preferences/Content/Colors/Override the colors .../Always. Kind of a hassle to traverse so many menus. I'm sure there are ways to make that easier to do, but I'm a muggle when it comes to this stuff.
This extension is slowing down Google Chrome. You should disable it to restore Google Chrome's performance.
Any other users with this issue?
What's the downside to doing this?
"It's self learning! Things above the that divider are things that are reading or writing cookie, html5 local storage, or canvas data. Below are third parties that are not. You can manually change any of them, and if one of those domains is blacklisted via another site it will appear above that divider in the future."
Does Privacy Badger itself track me?
I know I could read through the source-code, but it would be quicker for myself (and others) to know if any tracking is done by EFF itself.
"Nope! Privacy badger does not send any information about your browsing to the EFF. The only way EFF will get information from you is if you choose to report a broken site, in which case it will only send information about the site you're reporting on, and that information is governed by the standard EFF privacy policy."
Privacy Badger is governed by EFF's Privacy Policy for Software.
In the privacy policy you have this:
Software Downloads: If you download and install software from EFF's web site, we may collect information about your visit to our site. Once installed, our software may also connect automatically to our site to attempt to determine if updated versions are available. As a result, our site may log information related to the software downloads, such as your computer's IP address. Our collection, anonymization, and use of that data is described our web site privacy policy.
Web site privacy policy has this to say about the collected information:
Disclosure of Your Information
While EFF endeavors to provide the highest level of protection for your information, we may disclose personally identifiable information about you to third parties in limited circumstances, including: (1) with your consent; or (2) when we have a good faith belief it is required by law, such as pursuant to a subpoena or other judicial or administrative order.
So as a start you might want to disable automatic updates
Is Privacy Badger the functional equivalent of that Safari feature?
Some of the entries seem suspect, e.g. YouTube.com - why do they think that Google won't track you through pages with YouTube embedded items?
https://github.com/EFForg/privacybadgerfirefox/blob/master/y...
If you don't want something to be on the list, you can also override it in your own copy of Privacy Badger.