I wonder if we can come up with a widely adopt(able|ed) fingerprint that we can mask ourselves with, do any of these identifying bits actually make the web more usable for us?
I wonder if we can come up with a widely adopt(able|ed) fingerprint that we can mask ourselves with, do any of these identifying bits actually make the web more usable for us?
One could also introduce confusers -- e.g., setup some "light anonymizing portals" that will add / swap / scramble non-critical cookie data. Done right it should be possible to keep almost all of web functionality intact without introducing a security nightmare, but to work well this also needs a viable business model.
Sure you can disable js, but for the majority the Web would be really broken without js.
As a culture, tracking is everywhere. Disabling js still logs your up, referrer and a bunch of other things.
I do like what uorigin/adblock and other extensions are doing.
I don't want people to track me on the internet, I think the main reason they bother is that they can show me ads that will be more interesting to me and make them more money. I can resist this by not showing the adverts to myself.
I'd like to make it harder for them to track me at all, though this is always an arms war it seems like I'm labeling myself at the moment. I'm not familiar with the technology they use to detect adblockers, does it detect "U-Block Origin (Firefox) Ver 17.3" or does it just detect "I can't seem to see the ad I know should be here, this user is blocking my ads." if it's the latter then my proposal to adopt a blank/universal fingerprint is willing to confess the single bit of information of whether the user has decided to refuse adverts.
In my generation (I'm 28), and even more in my cousins' (early twenties) it looks like the hurd is using an adblocker. And I'm talking about art students, acountants and chefs not IT engineers.
You just can't spend hours on YouTube videos without an adblocker on …
...actually, you can. But those hours won't be filled with the videos you wanted to watch. ;)
Browsing the web with NoScript is far more pleasant, even if I have to sometimes open a menu to enable a couple domains to make a poorly developed website usable. I'd highly recommend it to anyone even remotely technical.
Some websites need more than text or images.
1. Is there anything the site owner can do to turn that off?
2. Is it because they inject some kind of DDoS prevention/tracking thing? This suggests crawlers load JS, which I wouldn't have necessarily assumed.
The complaint isn't with the scripting language, but with the blatantly unnecessary use of it.
One of the principles of human-friendly design is graceful degradation. For instance, you might design a museum for people that can walk. But some visitors might not be able to walk, so for them you install ramps and elevators when the stairs are not usable.
At the very minimum level, where someone is manually typing in HTTP requests, over a direct TCP connection to port 80 of your site, you should be returning something that can be read. Some people (or bots) may be fetching your site with curl or wget or links. Some people may be using screen readers. Some people may need machine assistance with pointer movement or scrolling. Some people may have extremely limited bandwidth, and won't automatically download images or frame contents.
If you can't degrade gracefully, your website is "poorly developed". So if you are utterly reliant on scripting to display anything at all, that certainly qualifies.
For the fourth or fifth time this year, in response to a thread about browser privacy, I am reminded that what I really want is the ability to jail/chroot a browser.
Firing up a full-blown VM for a browser ("banking profile", "twitter profile", "sketchy online store profile") is way too heavyweight and resource intensive. I want a totally, totally clean slate (restored to post-install defaults) to restart certain browsing sessions with (and dispose of when I am done) but a full virtual machine is too expensive in time and resources.
But if I could jail a GUI application ... then there would be almost zero resource overhead and the jail would die quickly when you're done.
jailing a GUI application is not that well developed of a use-case. Further, OSX doesn't even have a jail command.
I wish this was an established use-case - I would really like a totally throwaway browser profile that I could reset and re-use.
No ...
That is, unless I can easily script the destruction and recreation of the guest account, and automated install and configuration of my chrome setup ...
The idea here is that I set up chrome just how I want it and deploy and redeploy that "container" over and over - destroying it and recreating it after each use. Possibly with multiple instances running simultaneously ...
Sounds a bit like local Docker for browsing?
Everyone would download the same Chrome container with the exact same clean config and software rendering so the canvas/WebGL fingerprinting yielded nothing?
If you like, you can uncheck the "Use the selected profile without asking at startup" checkbox to have the window show up every time you start Firefox (which is defined as loading Firefox when there's no Firefox window already open). Doing this has the additional side benefit that if an application tries to open Firefox and load a new URL when you don't have any Firefox windows open, you'll be alerted to it by the Choose User Profile box - very useful if your normal profile takes a long time to load!
If you want, you can add the "-no-remote" switch to tell a new Firefox process not to connect with any existing one, which will allow you to open a new profile in a different browser window while you've still got the original running in other windows. However, those windows will share the same taskbar grouping, so I'd recommend you apply a different theme to the new profile to allow you to distinguish the two.
(Note: You should not use "-no-remote" by default, as a browser profile can only be open by one process at a time and you won't be able to open new windows through your shortcut icon.)
Of course, none of this will defeat the multiple-browser fingerprinting techniques mentioned in the article, but it's still incredibly useful.
I'm not sure if there's an equivalent in Chrome, or at least one that goes as far as Firefox does.
https://anonymous-proxy-servers.net/en/jondofox.html
JonDofox with JS turned off and uBlock origin installed. There's actually a small pool of users with this config but it needs to be bigger. As you said, as soon as we get consensus on what config to use, we can all switch to it en-masse.
If a site shows me nothing but a blank screen when I load it up with scripts disabled, I am very reluctant to enable 14 different script domains just to see a paged article, or worse, a slide show.
Allowing scripts to run only from whitelisted domains makes the web a better place.
Running unknown programs from random hosts on the internet - even in a limited environment - is a bad idea. Fortunately, documents (including images, audio, video, etc.) do not need Turing completeness. A lot of people will react strongly against the idea of not using JS, often because their income depends on tricking users into running spyware/malware,
Curious. This goes completely against the sentiment in all of the discussions around modern SPA frameworks and JS libraries I've seen on this very website. It seems that for most fronted devs today JS is a natural prerequisite for using their product. Progressive enhancement is often sneered at[1] as impractical and unnecessary. This leads me to believe that there are two mostly disjoint groups of people commenting on this issue in different threads.
---
[1] - Good example: https://www.viget.com/articles/the-case-against-progressive-...
I don't know which world JS devs are dragging us in, but it certainly looks shitty and ignoring every single thing software engineers have learned in the past thirty years.
If a site requires JavaScript, it already doesn't work. If a site requires JavaScript, its owner clearly doesn't care about either your security or your privacy.
Why use a site which requires JavaScript?
JavaScript delenda est.
It might be more practical to work towards browsers that do not have access to data that is not relevant to the web experience. I do need to know the size of your browser window. I do not need to know anything more about your video capabilities. In an ideal world, I wouldn't even need to know your browser, I would just need to know its capabilities. Your browser needs to know which fonts it can display, but my web server doesn't need to know that.
Isn't that info still enough for finger printing the browser, if they have enough different capabilities?
Have a look at the parameters that bring the highest amount of fingerprinting bits in your config https://panopticlick.eff.org/ then see if it possible to disable them. I think it's just plain hard.
> If you intend to test for leaks using other third-party sites, I recommend using Tor browser, because it's been hardened to block WebGL fingerprinting, and otherwise to report the same fingerprints for all users. But you obviously don't want to use Tor while testing your VPN. First, download Tor browser for your OS. Do that with your VPN connected, so your ISP doesn't see. After extracting, start Tor browser. You can probably accept all defaults. Go to advanced network settings, and select "No proxy". Browse about:config, and toggle both "extensions.torlauncher.starttor" and "network.proxy.socksremote_dns" to "false". Then browse check.torproject.org. You should see "Sorry. You are not using Tor." and your VPN exit IP address.
0) https://www.ivpn.net/privacy-guides/how-to-perform-a-vpn-lea...
https://addons.mozilla.org/en-US/firefox/addon/random-agent-...
https://addons.mozilla.org/en-US/firefox/addon/trackmenot/
https://addons.mozilla.org/en-US/firefox/addon/adnauseam/ (doesn't work well for me, though, YMMV)