Preventing Tracking Prevention Tracking
webkit.org
webkit.org
It's not perfect because the IP blocks make it obvious that it comes from DigitalOcean, AWS, etc, but it's sure better than loading untrusted PDFs or JS locally. Still vulnerable to a network attack, though.
>I generally do not connect to web sites from my own machine, aside from a few sites I have some special relationship with. I usually fetch web pages from other sites by sending mail to a program (see https://git.savannah.gnu.org/git/womb/hacks.git) that fetches them, much like wget, and then mails them back to me. Then I look at them using a web browser, unless it is easy to see the text in the HTML page directly. I usually try lynx first, then a graphical browser if the page needs it
Or, just don't use the website if they do this.
I also anticipate someone will do smart diffing on target websites to better auto nuke ads, trackers, etc.
I just don't know. I've stopped using VPNs for this very reason.
Very few websites will vary the response if there is no Referer. Sending it really offers little benefit to the user.
Setting up a "headless" browser also seems like overkill. Firefox 57 and later has a -screenshot command line option which saves a PNG. No need to launch X11 for this to work.
No need to send one when using the web for recreation.
# Only send the origin cross-domain.
network.http.referer.XOriginTrimmingPolicy = 2
This alone is a pretty liberal policy. People in this crowd probably want even more which can be found here: https://wiki.mozilla.org/Security/Referrer1. https://gitlab.com/smart-referer/smart-referer/blob/gh-pages...
2. https://gitlab.com/smart-referer/smart-referer/issues?scope=...
I can remember my Dad getting a mail from someone he linked to that was about to move his website and politely contacted his neighbors on the internet to allow them to update their links.
Very useful at that time.
Granted, this is probably rare enough that it's safe to disable the header for the vast majority of websites, but it's something to keep in mind.
Judging solely by the UI, I actually kinda like Atlassian's tools, but they're a huge pain in the ass to get working with privacy extensions installed (uMatrix, uBlock, etc.). They make cross-site requests all over the place (to weird servers like "some-huge-name-that-obscures-the-host-name.atl-pass.net", and even some third party servers!), tons of Javascript and css for basic features, etc. Using dubious features like referer headers seems right up their alley.
It's one of the main reasons I only use them at work, and won't use them for my personal projects. I'd rather pay for GitHub and Sourcehut so I don't feel like I'm opening my browser up to a bunch of security problems.
In the past they've also made some really brain dead (IMO) decisions like going out of the way to break middle-click paste on Linux.
If you like this, you should try Microsoft. They combine this crap with endless redirects. Usually, I give up after 5 minutes whitelisting + redirects.
I recently got the Pyramid Python framework to make it possible to disable Referer-checking for the built-in CSRF protection, but they're still going to keep requiring the header by default: https://github.com/Pylons/pyramid/issues/3508
More discussion about it in these pull requests too:
https://github.com/Pylons/pyramid/pull/3512
https://github.com/Pylons/pyramid/pull/3518
The new version with it being optional hasn't been released yet, so as of right now almost everyone using Pyramid will still require users to send a Referer header to get past any CSRF checks.
The problem was that chrome cached www as the default for anyone who'd visited the old site, and had started hiding www from the address bar.
I used Caddy to redirect all requests to the subdomain free site unless the request came with a referrer from that site, fixing the caching and allowing for free navigation between and within both the old and new site.
This is going to break a lot of things. Things that probably should be broken, but it will cause headaches nonetheless.
The css value `100vh` meant the height of the viewport of the browser, until it didn't.
Huh, what's it mean now? Is there some subtle difference, like it doesn't include the horizonal scroll bar or something?
How so? Tracking scripts are often included by a script tag that points at a website. Can’t the code be updated, “deployed” to websites immediately, and take advantage of the relatively slower release cycle of Safari?
Sometimes the publisher only embeds an image form the tracker (the famed "tracking pixel"). Getting lots of sites to change that to script is a pain. Sometimes they need to deploy new server-side tech for a workaround. For the recent CNAME cloaking trick, they have to get sites to modify their DNS and change what URL they embed script from.
It has got to the point where any time someone posts something that seems to too clearly show a brand name or speaks too highly of a product I suspect its the PR people at work and I downvote it.
The new way: making sure that 95% of the snowboarding videos you see are subliminally designed to sell you a snowboard (the guy riding the competitors snowboard goes slower and crashes... the guy riding your company’s snowboard wins the race and his girlfriend looks like a supermodel)
I think eventually we will pine for the old way. Already you can’t get useful reviews anymore because all of the “comparison” searches are run by manufacturer mouthpieces.
Absolutely. A lot of reviews these days from google results read like someone who has only ever read the feature list from the marketing page. There is a bit of a search engine hack where you just put "reddit" after any search and it brings up fairly real results for now.
If the third category can be used to construct a narrative about something that is a deal-breaker, then that's the information I'm looking for. Of course, it has to be taken in context of the competitors.
My expectation is that the best products have some type (I) and type (II) bad reviews, but no type (III). Almost as good is something with type (III) that are about something that either doesn't matter to me or is actually a positive from my perspective.
Handle them the same way as websites with a cookie or gdpr warning that blocks everything else, vote with your valet by leaving the site and find another site instead
What is meant by cross-site here? Does it mean a different eTLD+1, or a different origin (as used by CORS)?
Specifically, if I make a request from https://www.example.com/path?query to https://api.example.com will the referer header contain the "/path?query"? or will that get blocked as well?
Honestly, this shit gets confusing, can someone please ML us out of it? Or maybe we just design a sane and understandable First-Party only policy?
What's the hard problem here that prevents major browsers from having an option like this?
More details in this ghacks article:
https://www.ghacks.net/2018/03/01/a-history-of-fingerprintin...
Currently canvas fingerprinting [1] is a popular option, but there's quite a lot of options for that next thing you can use. Even generic code execution time could be used to an extent. Realistically there is hope at the end of the tunnel, but it's a very long way to go given just how complex of a corner we've painted ourselves into with modern web standards.
While it wouldn't stop purely malicious actors, I personally think it might be easier to address the whole situation on the legislation side rather than with technology. Imagine GDPR, except tracking would be illegal altogether: there will always be actors who will work to bypass it, but the majority would do their best to conform, lest they want to go bust with fines.
Its interesting that Google being an ad-tech company is doing something against their own interest.
How should anyone believe these actions are for privacy? And not against competition? Against the Internet?
Have you seen any consideration how it will impact website owners? I didn't. It seems they really don't care. And it is very dangerous.
It looks like the path to break the Internet.