Browser Fingerprinting: An Introduction and the Challenges Ahead
blog.torproject.org
blog.torproject.org
On almost any other distro you're just going to see "Linux" for the platform. The reason "Fedora" is in this particular one is that there are packages that are installed by default on both Firefox and Chrome that add it to the useragent string for no reason.
I know this because, for a few glorious days, there was a bug in the Chrome plugin that meant that there was another "Fedora; " added for every redirect in a redirect chain (i.e. "Fedora; " to "Fedora; Fedora; " etc.), which broke a whole bunch of whitelists and fingerprinting bot detection scripts.
There's absolutely no reason for it, there's no benefit to having there, but everytime someone files a bug about it the maintainers don't see what the problem is and WontFix the bug. [1]
Sadly maintaining exceptions for broken sites that demand them is too much for one person.
Using the list of measurement points on https://amiunique.org as guide most of the things that are constant about my computer like platform, browser, or requested language are not really unique to me and are shared by a large percentage of the other users who have come to the site.
On the other hand, most of the data points that are unique to my machine change semi-frequently. User agent and version change on browser updates, timezone changes when I travel, screen size and resolution change when I plug into my external monitor, new fonts will slowly be installed over time, and even things like how the canvases are rendered can change slightly depending on how much strain my GPU is under at the time I get fingerprinted.
Just plugging in to my external monitor was enough to get amiunique to treat me as a different user. (if you want to try, be sure to clear your local storage and cookies in between visits as the site saves a uuid there and will serve you your previous results if it finds it).
I'm sure there's some magic formula that gives different weights to different data points that can give a decent guess at who you are, but I doubt it can say with 100% accuracy that you are who it thinks you are.
It seems to me all it would take to defeat fingerprinting is a browser extension that modifies the browser apis to randomly slightly alter the requested data (add a random font to the list, add some nonsense to the user agent, etc). Sure, the fingerprint would still be unique, but it would be unique on every visit which would defeat the ability to track a user across visits.
*I'm not an expert on this subject at all, so if I got something wrong, please correct me
If I get a fingerprint that contains some super unique font and is requesting the site in Mongolian then yeah, that can probably be mapped to a single record.
If I get a fingerprint in which the only data points that match anything in my database are that the user is on a Mac using Chrome 76 and has cookies and local storage enabled, I don't see how that can be used to track a user.
My point was that the data points that seem most unique to a user also seem like the ones that change the most frequently. If you're only changing one at a time like they would during normal use, then yeah, it's probably still trackable, but if you wrote something to change all of them on every page load, I don't see how you would be able to connect one partial match to another.
It’s possible to be anonymous if you only log into websites with proper privacy policies, delete cookies & cache every day, and hide behind carrier NAT.
Adding a random font shouldn’t stop fingerprinting, people install new applications all the time. You make a lot of points, but ad tech can get around it.
Ideally ad corporations would be forced to delete records on people after 30 days.
I'm browsing everywhere in Safari's Private mode by default, 3 years no problems.
You are giving out a unique identifier that tracks you across devices.
Many of the test seem to look for the presence of specific APIs, or test various features of the JS environment. Which I'd expect to not give more information than the user agent, but of course is not as easy to fake as the user agent it.
I'm not sure this script is entirely about fingerprinting, but I really can't see any other reason for it. Though the minification of course makes it a bit harder to see exactly what it does.
The script in question is the following:
If one hates all ads and tracking, of course, then none of this will matter, but just thought I'd point out the "why" for the fingerprinting in this case.
Interesting discussion from six months back: https://news.ycombinator.com/item?id=19323032
But I am a part of this battle.
I don't want to start a fight about Javascript; that's a complicated issue. I just want to point out that the "we" you refer to in the privacy battle may be a fair amount larger and more diverse than the "we" was in the Javascript battle.
BTW, your argument about being able to inspect local code still seems moot in light of the fact that if you interact with the server, you still have to trust it. 90% of the code might be local, but you still have to worry about that 10% that is opaque to you. And there's no practical difference between 10% of code being opaque and 90% being opaque. The "bad stuff" could happen in that 10%.
Surf makes it easy: https://news.ycombinator.com/item?id=20806638
Currently using chrome for HN, but that also creates a completely unique print. I highly doubt it will ever be a focus of this browser to change that issue. And everyone should buy more widescreen monitors, they are awesome.
I wonder if users of standard devices like iPhones fare much better. Not that I would want to use one...
Curiously, Firefox gives me WebGL Vendor = not supported, which isn't true at all, while chrome gives the full driver name, which in my case is very uncommon (using an intel nuc).
I am unique purely based on my content language: "en-AU,en,en-US"
While we like to think we're special in Australia, I'm not THAT special.
Wouldn't it be better to impersonate at random a different combination of fingerprints for each page? Otherwise any browser with this fingerprint would be risking being blocked for being part of the Tor network.
I browse with JS disabled, but when I hit a site which doesn't work properly (and which I want to use still), I can allow only the domains which it needs to work.
It's quite surprising how quickly many sites now load!
I'd love for fingerprinting-resistant browsers to either lie, or scroll a viewport.
Additionally one needs to disallow all third party javascript sources by default.
Both strategies are possible with a good content blocker.
These strategies protect against all known and almost all unknown fingerprinting scripts. The only scenario where it doesn't work is unknown first-party scripts, but cross-site tracking is impossible.
Note that for some time now TBB on Linux identifies as Linux in both the platform string and the useragent.
Edit: the platform string is mentioned later in the article.
1: https://gitlab.com/edneville/newuserbrowser