EFF's Panopticlick 2.0 Launches with Tracker Protection Tests
panopticlick.eff.org
panopticlick.eff.org
They’re located in Germany—a big legal plus—and their service uses an international chain of independent servers, but they charge for data rates greater than a few hundred kilobits per second. Thankfully, the browser profile also supports faster Tor proxying while maintaining the same degree of personal privacy. It also supports anything you can configure from your computer’s settings, but if that means something other than Tor or JonDo, it’s probably not redundant (i.e., comprising multiple independent proxy servers) and therefore less reliable. It can be downloaded from https://anonymous-proxy-servers.net/en/software.html; for those who wish to try it, I’ve found it works best with Firefox ESR, which can be downloaded from https://www.mozilla.org/en-US/firefox/organizations/all.
>Does your browser unblock 3rd parties that promise to honor Do Not Track? X no
What, why would I unblock those?
Edit: Thanks HN for deleting the fancy X unicode!
What extensions do you have installed? There's a known and unfixable issue with browsers that both block JS and absolutely block all requests to tracking domains (eg AdAway, which modifies /etc/hosts).
> What, why would I unblock those?
To incentivise better behaviour by web publishers and advertisers!
It's kind of weird for something specifically dedicated to measuring tracking to get so confused by an anti-tracking mechanism.
> To incentivise better behaviour by web publishers and advertisers!
Maybe if it could have some legal teeth to it, otherwise it's too easy to lie to get your tracker unblocked.
I switched off "Do Not Track" in my options since only good-behaving websites listen to it, such as those using Piwik analytics, which respects privacy. Therefore I only would harm good people with Do Not Track on.
Are Cookies Enabled? No
one in x browsers have this value 3.94
...so according to the EFF's data, almost 1 in 4 people also browse with cookies disabled? I thought I was in an extreme minority, and I know I come across a TON of sites that don't work without cookies or localStorage enabled (which is understandable for when you need to log in or if it's a more "app"-y thing, but for just reading content it's a ridiculous requirement).
https://wiki.mozilla.org/Fingerprinting
The Tor project submitted some of their fingerprinting protection patches to Firefox. They can be enabled by setting the "privacy.resistFingerprinting" about:config pref.
https://bugzil.la/418986 - Bug 418986 - Resist fingerprinting by preventing exposure of screen and system info
And the W3C has shared some information about the obligations of W3C specification authors and working groups of new Web platform features:
http://www.w3.org/wiki/images/7/7d/Is_preventing_browser_fin...
Also, does this test check for that and/or give points for that?
Here is the HOSTS file I use to block ads: http://winhelp2002.mvps.org/hosts.txt
http://adaway.org/hosts.txt http://hosts-file.net/ad_servers.txt http://malwaredomains.lehigh.edu/files/justdomains http://pgl.yoyo.org/adservers http://someonewhocares.org/hosts/hosts http://winhelp2002.mvps.org/hosts.txt http://www.malwaredomainlist.com/hostslist/hosts.txt
It's more plausible for a large population of browsers to share a single spoofed user agent; all of the Tor Browsers pretend to be a single specific version of Firefox for Windows.
What's the desktop equivalent?
https://addons.mozilla.org/en-US/firefox/addon/uacontrol/
https://addons.mozilla.org/en-us/firefox/addon/user-agent-js...
String...
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
Update the string every now and then?
https://techblog.willshouse.com/2012/01/03/most-common-user-...
Disable all plugins.
Best I got, sorry.
Is there a way to pretend plugins are disabled when they're on click to play?
Also, being able to toggle the UA and setup lists to dynamically set it is helpful in my usecase.
Of course, you'd actually have to do a bit more work to make it bulletproof (otherwise fingerprinters could use the fact that you modified your default navigator object as a way to uniquely identify you !)
I imagine ultimately it's almost impossible to defeat fingerprinters in JS, as they could do tricky stuff like timing attacks to get you.
Use NoScript if you're concerned.