Panopticlick
panopticlick.eff.org
panopticlick.eff.org
You want to take that with a grain of salt, because I don't think Panopticlick is a perfect tool to measure this stuff. For one thing, I suspect that Panopticlick is highly influenced by the people who visit it -- being posted on HN probably means there are more data points for me to hide in than usual.
For the other thing, there are measurements that Panopticlick doesn't include, and there's no way for Panopticlick to track disinformation and false data. For example, you could still get my screen size without Javascript via just CSS. Are most tracking sites doing that? No, it would be a massive pain to do, and it would force you to ship giant CSS blobs everywhere. But it's still possible.
But, this does still strengthen my conviction that turning off Javascript by default _probably_ helps avoid tracking on most sites, and it's surprisingly feasible to do. A lot of content-sites work without Javascript.
I recommend UMatrix if you want to go down that route, since it lets you create very precise exceptions relatively easily when you need them.
There is also master switch to wholly disable JavaScript on per-site basis in uBlock Origin[1], which I think is a more user-friendly approach for whoever wants to experiment with toggling on/off JavaScript easily.
[1] https://github.com/gorhill/uBlock/wiki/Per-site-switches#no-...
Another thing is "not blocking sites that honor DNT". I am sorry but I dont trust anyone based on fact web users were lied just too many times. Once DNT will be tied to hefty fines, I might reconsider, untill than everything will be blocked.
(And it is highly tasteless that eff is offering links to promote panopticlick on worse web tracking facilities of the internet - fb, google+ and twitter.)
or https://addons.mozilla.org/en-US/firefox/addon/random_user_a...
It's very hard to fake an OS or pretend to be a separate browser. If you're focusing on disinformation, you should probably be focusing on disinformation that's harder to detect.
This can by partially achieved by setting privacy.resistFingerprinting to true in Firefox's about:config. This won't stop Panopticlick from fingerprinting you. If you really want to reduce your fingerprint, try using the ghacks user.js [1]. If you want to make fingerprinting completely impossible, use the TOR browser [2].
Most users don't need to worry about this - uBlock origin blacklists most fingerprinting efforts by default.
Please read: https://www.privacytools.io/browsers/#fingerprint
[1] https://github.com/ghacksuserjs/ghacks-user.js [2] https://www.torproject.org/
More Firefox privacy extensions: https://github.com/ghacksuserjs/ghacks-user.js/wiki/4.1-Exte...
"No" comes with a red X like if it's a bad thing, but... Is it?
I don't like DNT, and I don't like that the EFF pushes for it. Users shouldn't have to ask to not be tracked - websites should respect your privacy by default, and if they don't, users should take control with tools such as uBlock Origin.
Also, privacy means different things to different people. Two of the most privacy advocating websites in existence, eff.org and privacytools.io, think it's OK to collect anonymous stats on site usage. Yet the authors of EasyPrivacy (a filterlist enabled by default in uBlock Origin) make no exceptions and block both of those sites from collecting data.
> DNT Header Enabled? | 0.94 | 1.92 | True
Strange, that they do not make use of the fact that browsers leak your local ip:
https://browserleaks.com/webrtc
This is one of the most glaring privacy holes build right into the browsers.
On the other hand, I am surprised they correctly identify my "platform" as "Linux x86_64". Even though I used a windows user agent. How do they do that?
Also: What does the "Share on Google+" button do? It prompts me to log into Google. What would happen if I do?
probably because your user agent faker only fakes the http header and not the javascript environment.
try printing out the value of navigator.userAgent or navigator.platform in the developer console.
There is even more stuff in navigator, that should not be accessible to the website. For example how much ram my machine has in navigator.deviceMemory, how many cpu cores in navigator.hardwareConcurrency and so on.
>>> navigator.deviceMemory
undefined
>>> navigator.hardwareConcurrency
2If I were running 3rd party javascript in multiple places, I could build a pretty unique personal profile of someone. If I were looking for technical people using Tor, even moreso.
I'm not in ad tech, so am naive to this. The biggest myth on the internet is that nobody actually cares enough to watch what you in particular are doing, when in fact, this changes from nothing to almost total prediction of consumer and political behaviour as soon as someone at a platform company becomes interested.
Also maybe sad to point out something far worse if someone chose to track you specifically, if one were to get bid stream data (or even a 1% sample), they would see virtually every website you visit. Sure your cookie/ip/geo/ua etc are less entropy than JS fingerprint (though 1st party google cookie surely knows who most are). this exposes the very core of who you are, what porn you watch and everything.
EDIT: Whoops, I had it blocked in /etc/hosts:
# [EFF Tracker Detection]
0.0.0.0 trackersimulator.org
0.0.0.0 eviltracker.net
0.0.0.0 do-not-tracker.org
(still, I had to allow scripts for eff.org to see the results)Take an iPhone10 in California and visit the site. They'll tell you you're in a million in 1 or one in 500k people.
All iPhone10s have exactly the same signature. They only differences at most are region settings and time zone. If you're in california those are likely the same for 95%? 90%? 80%? I doesn't matter to my point.
How many iPhones10s are there in that time zone? I think there are like 55million people in that time zone (Seattle + Portland + Bay Area + Los Angeles + San Diego). How many of those own an iPhhone10? Let's be what I think is conservative and pick 1 million. Now compare that number to the number you go from panopticlick and you'll see their stats are off by several orders of magnitude.
Their excuse is they don't get that many visitors but it's only useful to track you on popular sites with lots of visitors. If you go to a site with few visitors then you're already unique. Any sight with lots of visitors will have lots of iPhone10 users in the same time zone with the same region settings and so tracking you is much harder.
Of course I'm not saying you shouldn't be worried about tracking and if you're on Windows/Linux/Mac/Android your device is likely much more unique. My only point is that it exaggerates given that there is popular hardware that has the same signature it should be reporting different numbers for those devices.
Not quite, this varies depending on the browser app used, zoom level set, language set, other accessibility settings, etc. etc.
Most users either use safari or chrome. Maybe 2 bits of entropy at best.
>zoom level set [...] other accessibility settings, etc. etc.
95% (random guess) of users don't have these changed from the default because they don't have vision problems or other accessibility needs.
>language set
The parent post said it was in California, so en-US is a pretty safe assumption.
My point was panopticlick says some iPhone10 in the PST time zone set to en-US running Safari is one in 500k. If there are 55million people the PST timezone then panopticlick is basically saying there are only 110 iPhone10s set to en-US in all of the PST time zone. That's clearly false.
But it is a very useful way to get us all to think about tracking. The kind of techies who discover the problem by reading about it on HN might very well be the kind of techies to make the next stride in defeating it.
Well, apparently I leap-frogged to Chrome 78, which even fewer people are on. Now my user agent is shared by just 1 in 1400 users, and my fingerprint went from nearly-unique to unique. Go figure. :P
I also don't think Google needs that info, there's a million things to criticize them for but this is a bit silly.
I wonder what the most common user agent is.
Temporal and spatial; when you’re browsing, where you’re browsing, and how you’re browsing. We can predict future non-unique (unknown) browsing behavior by training on your past unique, known, behavior. It is a common misconception, by those that are not in adtech (e.g. your typical software dev), that a fairly non-unique rating on sites like these will correlate with being difficult to track (not saying this is necessarily you).
I naively thought it might be buried in Google Takeout somewhere, their facility for downloading all your data from Google.
I didn’t see it. Perhaps (1) it doesn’t legally belong to me; or (2) the fuzziness of the fingerprint allows for sufficient deniability that the adtracking data is actually tied to my Google account?
But I’ve certainly browsed other sites while having a Google cookie which is pretty unambiguously identifying me, so maybe they don’t literally just don’t have a log of which sites I’ve visited?
What adtech tracking data about me can I see?
Other bits of entropy are relevant though (such as canvas fingerprints etc.)
I'm running openwrt with the adblock service on my router.
So I need to stop reading the internet in my native spoken language to hide from evil tracking and only consume things in english.
That doesn't seem like progress.
I am disappointed :(
privacy.resistfingerprinting.letterboxing=true on firefox
I still think panopticlick is an excellent title choice. Isn't it (behavioral modification because of tracking) the real hack at work here, not just how many bits are leaked by your browser?