[1] https://www.privateinternetaccess.com/blog/2019/07/why-you-n...
[1] https://www.privateinternetaccess.com/blog/2019/07/why-you-n...
Edit: Oh, apparently there's built-in UI now: https://blog.mozilla.org/firefox/how-to-block-fingerprinting...
The matter of virtual graphics drivers cuts both ways, however. Multiple VMs in a host that use the same virtual graphics driver have the same WebGL fingerprint. So if you want multiple fully compartmentalized VMs on a given host, they must use different virtual graphics drivers. That is, Windows vs macOS vs Debian family vs vs Red Hat family vs BSD family etc.
ad nauseum actively poisons the dataset by clicking on every link it is presented. this can be useful when it is combined with other techniques. https://web.archive.org/web/20180714043311/https://iotdarwin...
(sadly) do-not-track also doesn't work - it makes you stick out even more when activating it. best is to try to blend in with aggressive hardware compartmentalization. there are no solutions that can easily be recommended to somebody less tech-savvy which would protect them from bad actors (and GDPR or not - there will always be plenty of them).
The second article CiPHPerCoder linked seems to be more focused on the VPN marketing aspect. A more interactive approach might be https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...
Of course, that makes total sense, because many of the factors that can identify your system have little to do with the browser, but are determined by the underlying system: fonts, display, date/time information, graphics fingerprints, etc.
17.62 Chrome 75.0.x normal (non-incognito)
16.62 Chrome 75.0.x incognito
15.62 FF 68.0.1 (Private doesn't seem to make a diff, I get the same score)
Seems like in Chrome, at least, the most offending (most unique) "characteristic" is HTTP_ACCEPT Headers, which looks something like text/html, */*; q=0.01 gzip, deflate, br en-US,en;q=0.9,fr-FR;q=0.8,f...
If there is a good way to control this (FF does a much better job -- could be tied to plugins and such tho), one could further reduce the number of identifying bits.Chrome seems to do better (less unique) in both Hash of canvas fingerprint and Hash of WebGL fingerprint. I've summarized the main differences I see below, seems like combining the best of Chrome w/ the best of FF would result in even better privacy:
https://i.imgur.com/QQQ6R85.png
Edit: I think Chrome's HTTP_ACCEPT Headers is like that because I've installed/enabled many languages in it for l10n testing. I'm removing them now, which should make Chrome get a better score than FF.
So, the true number is somewhere in-between.
On Panopticlick with Firefox Mobile, with Ghostery plugin active in a normal tab I get 18 bits of info, in a private tab I get 17 bits, but the best is a private tab with Ghostery paused - then I get 16 bits, and equal results on the other parts.
Are privacy plugins really redundant in this day and age? Or is the test too incomplete to reflect their value?
easy. use firefox, open about:config, and set privacy.resistFingerprinting => true.
I tested with my browser and it was unique as well. It seems to be caused by high dpi monitor breaking the window size rounding logic. Retrying with high dpi disabled results in
Within our dataset of several hundred thousand visitors tested in the past 45 days, only one in 5551.36 browsers have the same fingerprint as yours.
Currently, we estimate that your browser has a fingerprint that conveys 12.44 bits of identifying information.
Maybe having resistfingerprinting is a fingerprinting datapoint itself?I installed CanvasBlocker, and one of the things it does is fake results for a handful of API calls. So while Panopticlick reports a unique fingerprint each time, it looks (to me, based on their results) like a different browser each time.
In particular, the two most specific categories they track are canvas and webgl hashes. Those are changing every time, which I believe makes them less useful as tracking information; the next-most-specific thing is a list of fonts, which is almost two orders of magnitude less specific.
> Within our dataset of several hundred thousand visitors tested in the past 45 days, only one in 417.05 browsers have the same fingerprint as yours.
> Currently, we estimate that your browser has a fingerprint that conveys 8.7 bits of identifying information.
So yeah, pretty much all web privacy is broken by Javascript.
However I think those VPN companies that throw around suspicious abouts of cash advertising all ask for credit cards or similar. I would never do business with one of them, it's pointless.
I also hate NordVPN's YouTube advertising campaign in particular, in which they pay YouTube creators to mislead their audience. Suggesting among other things that connections to your bank's website are unencrypted if you aren't using a VPN.
Also ask your girlfriend / boyfriend to tag imgur links with NSFW :)
[0] https://www.wired.co.uk/article/porn-block-uk-wired-explains
[0] https://www.ageverificationfacts.org.uk
Here's the important bit from the article where children will need to bypass:
> From the launch date in July, porn websites will have to show anyone visiting from a UK IP address a landing page that doesn't show any explicit content.
This is so going to result on a ton of teens with credit cards. Just look at what is already happening with mobile games. Sounds like a boom for the porn industry. Sure enough, MindGeek is already on it:
>The most well-known of these is AgeID, designed by MindGeek
Do I care if Google & Facebook track my viewing habits? I'm not sure I understand what the potential harm to me might be.
Countries can change. There are plenty of examples in history.