"Protip: Use Firefox instead of Chrome. We get very little data from Firefox users"
"Protip: Use Firefox instead of Chrome. We get very little data from Firefox users"
https://addons.mozilla.org/en-US/firefox/addon/canvas-finger...
https://addons.mozilla.org/en-US/firefox/addon/webgl-fingerp...
https://addons.mozilla.org/en-US/firefox/addon/font-fingerpr...
https://addons.mozilla.org/en-US/firefox/addon/audioctx-fing...
I would really love to have more addins like this, doing one thing and doing it good. They will kill fingerprinting and as a proof, I was downvoted the next moment i posted the links in another post but I want you to know there is a way out.
It’s very difficult to have a non-unique fingerprint. Your browser would have to be the exactly the same as a bunch of other people. At the moment (AFAIK), this is only possible with Tor (all Tor users have the same browser fingerprint.)
You don’t have to worry about this too much, though. Firefox and uBlock Origin blacklist many fingerprinting scripts.
Some other useful ones for seeing what you're leaking: https://www.bromite.org/detect https://www.doileak.com/ https://www.deviceinfo.me http://fp.virpo.sk/
For things that should always be unique (like a canvas fingerprint), just make sure to randomise it each time.
Basically, you want to appear as mundane as possible (user agent, screen resolution, fonts, platform etc.) and be able to change on demand as much of the remaining entropy (as is feasible) that would normally be expected to be unique.
If you're showing up as unique it's either because:
1. your blockers are randomising each time
2. your blockers aren't blocking everything and what's left is still enough to uniquely fingerprint you against the database of fingerprints they have.
If it's 1 above, that's fine. If it's 2, you may need more (or better) blockers.
Also, it obviously helps from the get go if you're on a bog standard platform like Windows and using FF.
I fail to see how Tor affects your browser fingerprint. Are you talking about a "tor browser" or something?
E.g. I usually use Firefox with NoScript. I frequently exit Firefox; when I do I clear everything using "Clear history when Firefox closes".
When I want to visit a site that requires JavaScript I switch to Safari. I'm just as aggressive in Safari in clearing my history.
Consequently, about the only ads I do see (in Safari) are clothing ads for teenage girls. I have two teenage girls, they have their own computers, so it must be the shared IP address.
So far it hasn't been worth the hassle for me to switch to a new IP address from Comcast more than about once a year. By default my firewall asks for the same IP address and even if it didn't, Comcast will use my firewall's MAC address to give me the same IP address.
Make sure you turn them on though!
Firefox by default doesn't block canvas fingerprinting, that's a setting you need to enable in `about:config` under the `privacy.resistFingerprinting` section.
Ideally I’d like to see fewer captchas. But there’s no good alternative to it really. I mean, requiring phone verification instead is an alternative. But I don’t necessarily want to hand out my phone number to each and every site on the net that I interact with either.
How do they decide which captcha is harder ?
I think that only two things can defeat this madness
1. Legislation
2. Breaking captcha to the point it's not effective anymore
For example, a fingerprinting script might try to measure the viewport height and width, calling on window.height can give it that info, but if Firefox were to fake that info when a friendly script calls for it, the page might try to reflow to the new size, etc. All kinds of desired behavior can use these same values, the challenge is determining whose a bad actor.
That said, it wouldn't hurt to split it out into a different about:config preference. I'd probably disable it since I don't use a vpn so my time zone can be deduced from my IP anyway.
(Or, if you’re just interested in helping advance the anti-tracking ecosystem! In which case you can test resistFingerprinting and file Webcompat issues when you encounter them — but be sure to mention that resistFingerprinting is enabled or your issues will probably be closed “unable to reproduce”.)
The first is, like you said, that resistFingerprinting can be kind of a gateway to Tor in general, since Tor will do everything resistFingerprinting does, and better.
The second is that uplifting Tor features to "normal" browsers and allowing "normal" users to enable them makes it harder for website operators to say, "well, I don't need to worry about this because it's just Tor users and they're all criminals." Right now, enabling these features in Firefox will result in some website breakage, but as more people say, "well, this is a mainstream browser thing", maybe more website operators will start to accommodate the protections.
I think there's value in continuing to blur the line between Tor and other browsers, if only to push the idea that the kind of privacy protections Tor offers should be available to everyone across multiple browsers. Not to mention that it's nice to be able to take advantage of a few Tor features while still getting stuff like fast video streaming.
But agreed, there's definitely a continuum here, and it might be valuable for some people to explore farther down it.
The issue I had more often is random captcha's for sites I actually need to use not letting me through. (Thanks school).
My solution for this is to keep de-googled Chromium installed, and just use it when I run across these sites.
There are a few ways of looking at the captchas; the optimistic lens is to look at it as a response to people who say that it's impossible to meaningfully reduce fingerprinting. If that was true, Google wouldn't be so mad at me for flipping this setting on.
But it does make some browsing more annoying, especially if you're not technically savy enough to realize what's going on when something unexpected happens. I think it's the right decision for them to have it off by default (at least for right now).
If you have the "restore previous session" option enabled and have grown accustomed to Firefox remembering all the windows you had open before, you may find it annoying that it no longer remembers the size of your windows; it just puts them to the default size. Although now that I think of it, this might possibly be specific to the X11/Linux version, as other window systems might handle window size in such a way that it's not affected by this.
Also, if you like having websites automatically detect if your system uses a dark color scheme and adjust their CSS accordingly, that no longer works. Again, speaking from an X11/Linux perspective here.
https://chrome.google.com/webstore/detail/dont-fingerprint-m...
extension is able to block most of the fingerprinting attempts. If you guys know about better "plug-in" solution, please let me know.
I don't want to sacrifice basic comfort of browsing though, like disabling .js, wiping everything on browser restart or diddling with uMatrix on every website.
I use uMatrix with strict defaults for privacy. I agree diddling is annoying. I find diddling with sites more annoying.
"Dont FingerPrint Me (DFPM) is a browser devtools extension for detecting browser fingerprinting."
Here are some of mine in my privacy browser:
BP Privacy Block all Font and Glyph Detection
Canvas Blocker
Clear URLS
Cockiebro
Decentraleyes
I don't care about cockies
NoScrupt
Privacy Settings
Privacy Oriented Origin Policy
Startpage
ublock origin
WebTRC Control
HTTPS Everywhere
And as a bonus, not really related: Bypass Paywalls Clean
Also use a host file manager. I use host flash
Most important thing: use many many browser. I have chrome for Facebook, Banking sites and Booking travel tickets (Trust me, you don't wat to do this with you privacy broswer).
I have chromium for gmail
I use firefox with all the plug-ins for webbrowsing
opera with build in VPN for some other stuff (carefull, owned by Chinese)
Vivaldi
There is also blue moon. There are many browser out there. Another option would be to use virtual machines with seperate VPNs.
Why are you reinventing the Tor browser?
Without an adblocker the internet is such a slow heap of trash that I'd never go back to not using one. This is also one of the main reasons I use my iPhone so little, since it doesn't really have any way to adblock.
Is adblocking not common? Every tech literate person I know uses an ad blocker. I'd say about 30-40% of millennials I know use them, most using ADB or uBlock Origin.
Every time I see someone using a browser with ads I forget what a nightmare the internet is.
But I just can't bring myself to indiscriminately block all ads, knowing how important they are as a funding source for the websites I use.
There's only one thing that destroys privacy even more thoroughly than ad targeting: payment.
Can you expand? Because I disagree. I would rather a company have my name, payment info, and email address than all those things plus other personally identifying information. I feel like a payment model decentralizes the issue and that I would not be tracked around the web. I don't need the WaPo to know the other sites I've been on, what my political affiliations are, my age, gender, etc. This is because I don't see the issue as companies know who I am, but rather that I don't like that companies have intimate details of who I am, or maybe more simply put "who I am vs what I am." To me the latter (tracking) is invasive, the former (payment) is consensual. As one might say "just shut up and take my money."
But I am open and interested to differing opinions.
I don't know many subscription based content publishers that promise not to monetise what they know about me in all sorts of other ways. I do have a newspaper subscription. That doesn't stop them from showing me ads or using ad networks and trackers. Payment networks and banks monetise my payment data as well.
Even if a particular publisher is willing make such promises, I wouldn't have much confidence in their ability to keep my data safe.
So the upshot is that I simply don't want my real name irrefutably and permanently linked to everything I read, write or watch.
What ad neworks know about me is extremly patchy. Every time I see what they think about me I wonder who on earth would ever consider paying them for that rubbish. But that's not what it's about. All they need to be able to do is make predictions that are slightly better than random guesses.
I disagree with this. Maybe you can elaborate?
If I am paying for a service then there is no incentive to mine my personal data for revenue. It's a mutually beneficial transaction. And there are plenty of ways to hide your personal information (even your name) when paying for something (e.g. using a service like privacy.com).
I doubt that there will ever be a widespread, convenient way to make anonymous electronic payments. The authorities would never allow that to happen (for understandable reasons I have to say).
Incentives are not working at all. Lots of services I pay for go to great lengths to squeeze even more out of that customer relationship. And how could I possibly trust a large number of small companies I know very little about?
I try to minimize ad problems by using containers and profiles. I have a Facebook-only container and Google-only container and never login to either in any other container. So far this approach seems to work for me.
Also important: start asking websites that need to take payment to provide a cryptocurrency alternative. Something based on Ethereum blockchain preferably, given that is possible to easily get stable-tokens (meaning, no volatity risk) and that is on its way to get rid of Proof-of-Work.
The ad-based economy needs to die and we already have the tools to kill it. All we need now is to stop with the excuses and take action.
I don't believe cryptocurrencies will work. As soon as they become widespread they will be banned or regulated just like other forms of electronic payment, including know your customer rules.
For the moment, I don't see that we really have the tools to replace ads, much as I would like that.
No. The biggest claim of Brave is that all of the information for ad matching is in the browser. So they can not control it. The only thing that Brave can control at the moment is the on-boarding ramps - i.e, if you want to take your BAT out of their wallet and to your own, you need to go through KYC via Uphold.com. But you can pay and contribute BAT to other people even if you haven't done KYC.
Even in this case, the KYC that needs to be done is only with Uphold. After you take out your tokens you are free to spend them however you want and no one will ask you anything.
> I don't believe cryptocurrencies will work
They already do.
> regulated just like other forms of electronic payment, including know your customer rules.
Even in this libertarian nightmare that you are imagining, crypto would more likely help you to keep your data away from businesses and third-parties. If every transaction needs to be authorized and monitored by the government or central authority, then there is no need for the business to collect any information from you - all they would need is to ensure that you are sending your payment from a government-validated address.
Governments don't do that today due to the sheer costs of trying to run such an operation. But tracking things on the blockchain is reasonably easy, so there would be no need for banks and third-parties to do the dirty work for them.
In any case, it seems like you are just looking for a way to rationalize your current behavior. I only mentioned Brave because it is the first strong offering for an alternative to the ad-based economy. If for whatever reason Brave stops being a valid alternative, there is nothing holding you to it. Why not try it for yourself?
Not in the least. I find ads annoying and I don‘t have any skin in the game when it comes to advertising. But it‘s not a matter of simply trying Brave. I want to understand how it works for users and also for publishers. And I want to understand how it is not a proprietary system with a gatekeeper role as a structural feature.
Hell, a competitor could even decide to have an advertisement network that also operates with the BAT supply that has been taken out of the exchanges. If for some reason the company starts doing anything user-hostile, they will lose the business to someone else.
The only important thing is that anything is better than the status quo. If you are weary of Brave, you can go for something like flattr, or you can start looking into crypto as a way to pay directly for those you want to support (and still keep your privacy). Whatever you decide, just please realize that "I don't like ads, but I don't see any good alternative" is not a valid statement anymore.
Does Brave support a way for other ad networks to integrate into their BAT system? If not, any competitor would first have to popularise their own web browser.
BAT is just a token like any other on the Ethereum chain. The "easiest" way to acquire at the moment is by using the Browser and setting up the wallet, but if you don't want to that you can just go any exchange and trade it. Or you can have a website and accept it as payment.
I am sorry if I made you on focus on the specifics of Brave when the point of my original post was to say that there are alternatives nowadays for ads. Alternatives that may not be perfect, but that do work and are better than the status quo.
In any case, I think that the best way for you to understand how things work and make sense of what I am saying is if you try it yourself. You can start by using Brave on your phone to replace Chrome or Safari and get a feel of things, see how the rewards system work, etc.
What I mean is Brave‘s specific Browser integration that creates a compensation scheme for publishers. I would only support such a system if it doesn‘t put Brave a privileged gatekeeper position.
I’m not sure which other alternatives you‘re talking about specifically, but I have explained many times elsewhere in this debate why I see subscription based services as an additional loss of privacy and why I don‘t believe that there can ever be a widely used general purpose system of anonymous electronic payments.
But I do believe that a Brave style system could work if it can be structured in away that does not allow one company to impose content restrictions.
There is nothing stopping other browsers to adopt it. There is nothing stopping other companies to create a similar alternative. There is nothing stopping a publisher to get an advertisement deal and place an ad on their website; as long as it does not use third-party cookies or tracks you in any way, it won't be blocked.
> subscription based services (...) loss of privacy (...) there can ever be a widely used general purpose system of anonymous electronic payments.
Look, I am not trying to sell you anything ok? I don't work at Brave and I am not interested in doing shilling for any specific cryptotoken. It's okay if you want to say "I don't want to pay for content that I am now getting for free. It's also okay to say "I don't mind having my data exploited in exchange of a few dollars that can go to content producers and publishers".
The only things that you are saying that are total BS is that (1) ad-tech is less of threat to privacy than a digital economy based on crypto and (2) that no alternative currently exist.
Your argument against usage of cryptocurrency for payments is just concern trolling. You are presenting a very, very unlikely hypothetical (companies might be required to collect user data to accept payments) in order to justify the status quo. Likewise, you are making these near-impossible demands from a company that has a fraction of the market share on a trillion dollar industry while having no qualms with all of the ethical violations from the dominant oligarchy. Again, concern trolling.
I'm not accusing you of anything either. I wasn't thinking for a moment that you were trying to sell me something or that you were shilling.
It's a simple disagreement. I'm unconvinced by the case you're making for specific alternatives. That doesn't mean I'm happy with the status quo.
You have said absolutely nothing to show that Brave would not be in a position to impose content restrictions if their system turned out to be successful.
My concerns about cryptocurrencies are anything but hypothetical. The authorities are extremely jumpy about cryptocurrencies. Regulation is already well under way. There have been crackdowns on crypto exchanges all over the world. Banks are suspending accounts left and right. I was personally invited by the local tax authorities to take part in a consultation on the subject.
And have you not noticed what happened when Facebook threatened to introduce a payment system that only so much as mentioned the word cryptocurrency? It was absolutely crushed before it even got off the ground. Granted, a lot of the concerns were related to Facebook's oligopolist status. But there were also huge concerns about the possibility of widespread money laundering, tax evasion and funding of terrorism.
What we need is a system that inherently limits the size of any financial transactions that a single party can initiate. That is very difficult to do while guaranteeing anonymity.
Let's not accuse each other of bad faith when what we're talking about is simply a difficult problem that many have tried to solve with very limited success.
> The authorities are extremely jumpy about cryptocurrencies. Regulation is already well under way.
Regulation already exists. It is due to the regulation, for instance, that Brave requires you to do KYC if you want to get the money out of their wallet and into your own. It is due to regulation that exchanges that do not comply with the law are getting crackdowns.
This is not an argument. This is FUD.
> Let's not accuse each other of bad faith when what we're talking about is simply a difficult problem that many have tried to solve with very limited success.
If the status quo was not harmful for society as it is, I wouldn't be nagging you about it. But this whole thread started with you claiming that accepting ad-tech's destruction of privacy is less of a problem than any alternative proposed so far. This is not a "simple disagreement"; it's plain wrong.
In my view, the status quo of ad funding is very annoying and somewhat harmful, but it is far less harmful than the app store model, which is pure oppression.
That's why I tend to be sceptical of any new scheme that once again puts someone in a gatekeeper role.
With regard to any widespread rollout of cryptocurrencies for anonymous payments you're going to have to accept that I'm pessimistic. You can call it FUD all day long. That's just aggressive rhetoric that adds nothing to the debate.
It's not that hard to make the argument that the moment that it became normal for websites to rely solely on ads for its revenue was the moment that we subverted a lot of our cultural institutions.
It's not that hard to make the argument that the rise of populism and extremist politics is rooted in this "eyeballs is all that matter" mentality for publishers.
It's not that hard to make the argument that ad-tech is making so many people addicted to our tech gadgets that its damage to the general public health is going to make Tobacco companies look innocent by comparison.
If that is not enough for you, take the amount of fraud and the amount of money that goes from advertisers to the pockets of the big ad companies and I hope you realize how ineffective it is.
> That's why I tend to be skeptical of any new scheme that once again puts someone in a gatekeeper role.
We are going in circles now. Again, there is nothing about Brave and its ad network that can not be replicated by any one that decides to compete with them. It's not like an "app store". The ads are optional, you joining the rewards program is optional. If for some reason someone else decides to create a competing ad network, it could run either as a fork or an extension. I fail to see what is so potentially evil that they can do that is worse than the evil that is currently done by the status quo.
Populism and fascism have been a problem for far longer than we have had ad-targeting. That said, I'm not opposed to putting restrictions on what ad networks are allowed to do.
>Again, there is nothing about Brave and its ad network that can not be replicated by any one that decides to compete with them.
Of course not. Others can build search engines and social networks and app stores as well. All of it can be replicated - theoretically. That doesn't change the fact that Google and Facebook and Apple are in an all powerful position to dictate content restrictions and access.
So in order for me to support a any new system, there would have to be an element of deliberate design to prevent that sort of power imbalance. I don't see that Brave has that, but I'm going to look into it more closely as I could easily be wrong.
I didn't say that it is the sole reason, but it certainly is one of the reasons and it is something that I have a way to control my input into the system.
> I'm not opposed to putting restrictions on what ad networks are allowed to do.
The problem is not "ad networks". The problem is in ad-funded business models and in PPC/PPP. When the business have the consumers just as a vehicle for delivering eye-balls, business only important metric is "how many eye-balls can we get?" and this is where everything went to shit.
> So in order for me to support a any new system, there would have an element of deliberate design to prevent that sort of power imbalance.
On one side you have an incumbent that is light-years away from having any kind of dominant hand and that you can hedge against an eventual abuse from their side. On the other you have giants that "are in an all powerful position to dictate content restrictions and access" but your only response is "it is annoying and somewhat harmful" and shrug it away? "Oh, I am pessimistic about every alternative that came so far, so let's just keep the existing abusers?"
I don't get this logic at all. It is either a display of apathy or dishonesty.
News, community, educational, etc? Is it a small group of sites, or a wide variety?
It's also got me really close to paying for YouTube red, which is the other option,and o e I wouldn't consider without the annoyance of ads.
Essentially, it's the great variety of what's available on the open Web that I don't want to lose. I don't want everything to become one big app store with all its suffocating narrow-mindedness and oppressive control freakery.
Would be way too hard to solve something like that with subscriptions.
Maybe one day, concepts like Brave Rewards or Google Contributor[0] will actually work... No idea what it'd take for those to reach critical mass, maybe government intervention.
If a site wants to use adds that will work despite, I have no issues seeing them. The extensions block pretty much any I would find unethical.
There must be a better way!
More than a handful choose that browser for privacy, including keeping stuff private from Mozilla.
Also those that disable telemetry after starting Firefox still sent telemetry. Mozilla only promises to delete it after 30 days not that they don't generate a number that says what % new installs in the last month disabled telemetry (though they don't publicly report this to my knowledge).
So that leaves those with whitelist only firewalling or similar measures that I (hope?) we can all agree isn't going to swing these numbers at any interesting digit position.
So number of (uBO + ABP users)/ Firefox users is probably 33%. So that might be where it is coming from
"Has addon" metric. uBO + ABP is far less than 33%.
https://www.businessinsider.com/30-of-all-internet-users-wil...
At my company people are either don't know about them, or actually fundamentally disagree with their purpose. (No, it's not an AdTech company, before anyone asks)
I don't think most people minds ads, such as on TV, but everyone hates the ad that is 10x the volume of the show and that's how the internet feels to me currently.
Is that true? I despise ads and the entire advertising industry. I would wear special glasses that would block billboards from my vision if they existed. I pay extra for the ad-free version of Hulu. When I'm at someone's house and they have cable and the TV is on, I find ad breaks incredibly jarring.
Am I just an extreme outlier? It would make me sad for humanity if that was the case. Not minding blatant emotional manipulation in your face all day seems... not great.
if you spend a significant time travelling through rather diverse countries, one of the first thing that hits you is different laws and norms around what can be advertised and where. moving through dictatorships and seeing elections is eye opening in its "weirdness". as a non American, visiting America and seeing laws, flags, billboards and medicine advertising is weird.
anyway, my point is, if you haven't been brought up with it, you see it for what it is, and normal becomes what you experience every day. one you spend a few years ad free, it's incredibly hard to go back, it's really jarring, and you see advertising the same way you see plastered images of the dictator in absolutely random locations when you visit other countries (and there's a good reason for that, because they're fundamentally the same thing).
And I do like to pay for services to bypass ads even though I use ad blockers that mitigate them anyways.
No. You are not alone. MOST people don't realize that there is an alternative.
Also depends on the financial model, if it's primarily ad based then the group of users you don't have good ad data for isn't something you should care about either.
Also to note the above % for FF share isn't just from 3rd party analytics anyways, places like Wikimedia report similar numbers. Different services different amounts but again, target demographic usually and not by much unless it's extremely tech niche or something.
10M Brazil
13M China
12M France
20M Germany
12M India
9M Indonesia
6M Italy
7M Poland
7M Russia
30M United States
It's honestly a bit frustrating how even on HN everyone thinks they know who around the world uses something more than the actual public data on it. On one hand you have people insisting the data is missing huge swaths of people and on the other you have people insisting a region has over half the users when that would be less than half the users according to the very data the other person is trying to say is missing lots of people!
It seems amazing how clueless people on hn are yet they post their middle class thoughts.
25% is indeed greater density than 10% and bicycles have two wheels but neither has anything to do with making "50% of global FF users are based in DACH " anywhere near an accurate statement.
DACH is not just Germany neither is it just Germany, Austria and Switzerland it's the German speaking world (and that isn't just DE, CH, AT, LU and LI either) Those reach nearly 30-40% of worldwide users go look it up yourself.
>25% is indeed greater density than 10% and bicycles have two wheels
Someone seems mad his useless comment got debunked. You tried to "well actually" while not understanding the irony of your own post.
>HN isn't the kind of place for your closing comment. Also you replied to yourself by accident.
That should be a reply of mine to you seeing you are literally just posting for the sake of posting after realizing your argument is beyond useless. Your post could literally have been "I LIKE SPAGHETTI" and it would have contained the same amount of valuable information as it does now.
You can block ads in Safari iOS with a Content Blocker. 1Blocker is pretty robust: https://1blocker.com/
Firefox for iOS also has Tracking Protection built in, which blocks most ads.
It'll definitely help with the web if your goal is just to speed things up and make things look better, but if you're worried about privacy, iOS's browser is going to be less thorough than other platforms. It doesn't even support page-source rewrites, let alone protecting against more advanced anti-adblock techniques like CNAME cloaking.
Funnily enough, this has come up a few times in the context of Chrome's manifest V3 changes, where people have asked why it matters since Safari already works pretty similarly to what Google is proposing. Ironically, the answer is that the similarity is exactly why we know it's a bad idea for Chrome to go in the same direction. Safari has less effective adblocking compared to where the rest of the industry is at.
It's always going to be easier to bypass what is effectively a declarative DNS blocklist than it is to bypass a system that can run blocking logic per-request.
- ios does not let you see the traffic
- ios diverts all traffic anyway, and allows apps on the phone to have visibility into web traffic (deep linking)
Focus is designed to be a short use browser that deliberately minimises tracking, akin to fast access private browsing.
That said you only need to get the app to turn on their tracking protection which blocks ads on Safari.
https://www.bleepingcomputer.com/news/software/mozilla-is-ad...
You can use wireguard to tunnel to it when you are outside of your home network
Not much setup or configuration needed.
1. Content blockers for safari are sold in the App Store. Not bad.
2. A private Pinole instance on a vps. Just set your phone to connect to it. There are turnkey docker installs of this now.
Neither are perfect / have quirks. I def recommend pinhole. I thought it would be a pain to set up, it wasn’t and it’s great.
Games for my young kids have terrible ads and finding quality, ad free ads (even paid) is very hard to do. I really wish Apple Arcade would release some early-ed games.
Presuming you have a decent set of rules it can block ads and shield the IPs of your kids devices.
1: apps on my Windows, Android, iOS devices along with specifying it as the default nameserver in my routers.
Reading this, I was actually surprised to find that for some reason or other this has gotten a lot better for me during the 2+ years I've been using uMatrix.
At first it's rather annoying to enable CDNs and stuff for the sites you frequent, but mostly I've started noticing that the sites that break for basically no good reason are the ones that a sane person probably shouldn't visit anyway. So maybe it is just that I've started steering clear of those sites.
Also as a side note, uMatrix is awesome. Many times even on HN I'm surprised to find comments complaining about pop ups or something, and realize that uMatrix silently made my browsing actually tolerable.
It is high maintainance, only if you visit many new sites every day. For a single site/domain, set it once and go.
There are built in 'recipes' allowing YT embeds, twitter embeds, google capthas if a site wants it.
Once you globally whitelist CDN's (cloudflare and others), it's enough. For popular sites (reddit, YT, twitter use the Recipes)
I should try globally allowing the CDNs as you suggest and see how it feels. At that point, though, I wonder how much I'll be blocking that won't already be blocked via the blocking lists.
https://apps.apple.com/us/app/wipr/id1030595027 Or like, any similar app. There's hundreds of them.
Yes.
My concern with ad blocker proliferation is that it invariably leads to paywalled content. Which I’m sure most HN users are ok with, thanks to their 6 figures jobs, but I think it’s a bad thing overall.
Your browser fingerprint appears to be unique among the 303,579 tested in the past 45 days.
Currently, we estimate that your browser has a fingerprint that conveys at least 18.21 bits of identifying information.1. Blocking redirect tracking is about more than just fingerprinting users. I'm a huge fan of Panopticlick's work here, but it's not a be-all end-all measure of whether a browser is getting more or less private. There are a lot of different, complicated things we're talking about when we bring up browser privacy.
2. Disable Javascript with something like uMatrix by default, and that number will drop dramatically. By default with JS disabled, I think my Firefox leaks about 8 bits of information, which Panopticlick lists as sufficient protection.
Major caveat in that non-JS users are likely disproportionately represented at Panopticlick, and people shouldn't use Panopticlick as more than an indicator of what's possible. In the real world, disabling Javascript will leak more bits since fewer other users will be doing it.
However, it's still likely worth doing if you can tolerate the inconvenience. And of course, the more people that block JS by default, the better protection it provides.
The point of these by-default protections is that they are supposed to work for most people. Suggesting that someone techie can do extra stuff that most people won't do is not really germane to the conversation.
Of course this depends on what sites you frequent, but you'd probably be surprised. I disable Javascript by default, I'd say 70-80% of the sites I visit load. An even larger percentage load with only 1st-party Javascript enabled.
I do think excessive required Javascript on the web is a problem, but I also think Hackernews overstates this problem sometimes, to the point where people think it's literally impossible to browse the web without Javascript.
I don't think that characterization is helpful, a lot of us browse the web every day without Javascript running by default. Most news sites are fine, high-end publications like the NYT actually tend to be pretty good at progressive enhancement. Lower-quality engineered sites like Kotaku won't load images, but the articles are still completely readable.
And to be clear, permanently enabling Javascript for a specific site in UMatrix only takes 2 mouse clicks.
> Suggesting that someone techie can do extra stuff that most people won't do is not really germane to the conversation.
I suspect at least 50% of Hackernews readers are smart enough to disable Javascript and selectively enable it when a site breaks. It's germane to the conversation in that those people might want an effective way to mitigate tracking.
I don't have to restrict myself to the lowest common denominator of features when I'm choosing a browser, and I don't think other users should need to either.
Of course raising the lowest common denominator is important, but if you really care about your own security and privacy, at some point you have to make technical decisions that go beyond that. I think it's relevant to the conversation to point out in a technical forum that those options exist for people who need them and can use them.
Out of curiousity, what is the "threat model" when using Panopticlick? Is it suited for users that just want to avoid tracking for commercial purposes? If the user does not enable Javascript, what good is that user to such trackers? How much commercial tracking is conducted without any use of Javascript (and without cookies)?
So something like disabling Javascript might mean that that you blend in on Panopticlick because a lot of users disable Javascript. But on a small news site or ring of nontechnical blogs, it might help narrow you down because very few people disable Javascript.
The other thing I want to get at is that privacy isn't just about fingerprinting, it's also about the effects of being tracked, and what specific information that you're leaking. So what you bring up -- that not having Javascript makes a user less useful to an ad network -- is true. Not having Javascript makes it harder to show you flashy ads or to guarantee that you're looking at them. It makes it harder (but not impossible) to set up persistent tracking that works over longer periods of time and across multiple devices. It also makes it harder to detect and circumvent adblockers.
Disabling Javascript doesn't address threat models like using your location to change the content that you get served, or sticking information into cookies, or doing some screwy things with image caches.
But that's... sorry, it's just a kind of complicated question. I'm not sure I can give a short, concise answer about how good you should feel about a low Panopticlick score, I think that's dependent on what sites you visit and what kinds of tracking you're trying to prevent, and what other measures you're taking. It's just a very broad topic.
> why not just disable (HTTP) redirects?
Unfortunately that would break a lot of sites, so it's not feasible as a default setting in the base browser. That being said, I believe that what you're looking for is `network.http.prompt-temp-redirect` inside `about:config` if you want to disable it for yourself.
I'm not sure I'd advise it, and I suspect that it's a kind of superfluous setting if you're already invested heavily into other privacy settings, but maybe there's some benefit. I haven't played with that setting to know for certain whether or not there would be non-obvious downsides or caveats.
There is some relief for the location issue. It is not too difficult to discover alternate geolocated IP addresses for websites that choose to employ such strategies. Further, proxies, even just Tor with a proper config file, can give the user a specific geolocation of the user's choosing.
Do users choose different user-agents for different web usage? On smartphones we routinely see users choosing a variety different applications for different purposes, e.g., an online shopping app versus a news reading app. For example, if the user is engaged in online shopping, then she almost certainly will need to enable Javascript and cookies. However, if the user is reading^1 news on small news websites or nontechnical blogs (to use your examples) then IME neither Javascript nor cookies are required. Using the same application (the same "modern" browser) for both purposes, and with Javascript and cookies enabled, is, IME, from a technical standpoint, unnecessary. The text of the articles can be retrieved and read with much simpler software; none of this software needs Javascript nor cookies to perform its respective task.
1. The situation changes if the user is "viewing" news (photojournalism) or "watching" news (autoplaying videos). IME, neither Javascript nor cookies are required, however short of the user writing custom Javascript to process page contents, employing some software, e.g., standard UNIX utilities, other than a modern browser, to extract the image or video URLs, is sometimes necessary.
Well, to push this a step farther, the great thing about extensions like uMatrix are that you can turn off Javascript+Cookies on a site-specific basis. So I know people who would feel like it was too cumbersome to juggle two browsers at the same time, but who don't have the same aversions to saying, "oh sure, I could turn Javascript and cookies off by default, but turn them on for this one specific video/shopping site."
> There is some relief for the location issue.
Definitely. I didn't want to go too in depth here, but this one of the things I'm getting at when I say Panopticlick shouldn't be the only thing people look at. Panopticlick doesn't even consider geolocation around IP addresses at all, so there's an entire vector there where Panopticlick won't tell you whether or not you're vulnerable.
There's a world of considerations here that are just hard to fit into a single comment.
> employing some software, e.g., standard UNIX utilities, other than a modern browser, to extract the image or video URLs, is sometimes necessary.
cough youtube-dl cough
If you're a user who's comfortable with the terminal, this can be a game changer even ignoring the privacy aspect. I see people all the time on HN complain about bookmarking a video and having it disappear later. Not a problem if you download them.
If you want to go even farther and you're comfortable with Bash scripting, youtube-dl even has options around managing playlists, so you can kind of "subscribe" to ongoing playlists/channels and treat them like podcast RSS feeds.
But with that I'm straying off topic.
It's just that Firefox is noticeably slower than Chrome (or at least was about a year ago). Even simply switching between open tabs around what feels like 0.5 seconds, whereas on Chrome, tab switching is instantaneous. I've run Firefox in multi-process mode (since that was an option), but even with it, in general it seems like Firefox gets noticeably slower than Chrome when you have a lot of open tabs. I've always preferred and wanted to use Firefox over Chrome, but the performance degradation was too much to bear.
Sorry ... hijack ...
Could you please implement a special:
settings://tabs
... URL that just gives a plaintext list of tab URLs currently open ?
As it stands, the only way to get this list is to poke around in /Library/ files and then use JSON command line tools to export ... etc., etc.
I just want a built-in page that gives me all the URLs of current tabs. I could then cut and paste them, or save the page, as I see fit.
1. Shift+Ctrl+D to bookmark all open tabs (in the current browser window) in a new bookmark folder.
2. Right-click on the new bookmark folder and select "Copy".
3. Then paste into your favorite text editor.
This isn't so much a feature request as it is a request for some simple debug info which can be accessed with a special://url (whatever those are called ...)
FWIW this sounds super easy to do within an extension: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
It probably is but I feel like debug/info URLs are simple and lightweight and belong in the core feature set - especially this one which you can find hundreds of examples over decades of people asking how to get this information.
I actually never filed a bug report. I didn't think of the slowness as a bug per se. I thought it was just that Firefox was slower.
One thing I should note is that I've been using an ancient Firefox profile. I copy the profile onto new installs, and I've got bookmarks going all the way back to 2008 or 2009 (my bookmarks are organized into 50 or 100 folders). I also have a bunch of extensions.
I typically have well over a hundred tabs. I used to use the extension Tree Style Tabs, and sometime get close to a thousand tabs (with like 5 to 10 windows, with between 100 to 200 tabs per window).
Also, Firefox was slow on every laptop I used, but not on my desktop. I have a desktop that's fast by 2015 standards. It's got a i7-5280K, 32 GB RAM quad-channel, etc. The few laptops I've had have had far slower CPUs (the fastest one being an 8th Gen Intel i7 "U" processor). While on my desktop, I might average 700 tabs, on my laptop I try to have under 200 tabs.
I've always been on the newest versions of Firefox. For my laptops, I was on Aurora / the Developer Edition. On my desktop (which has an Ubuntu-based Linux distro), I'm on Firefox nightly.
Not sure if all of that info helps. I haven't investigated too much into what's happening. The most probably culprit might be my ancient Firefox profile. Perhaps, if I go back into Firefox with a fresh profile, it'll be a lot faster.
N.B. I'm currently a happy user of Brave as it has integrated AdBlock-style blocking, fingerprinting protection, and HTTPS Everywhere. I'm always evaluating my options as a user, though!
Google Docs performance is a long-standing issue, but it sounds like you're seeing an unusual problem. (I usually have 10-20 Google Docs tabs open all day in Firefox Nightly.) Perhaps try reproducing with any Firefox extensions disabled. Some, particularly ad blockers, can cause performance problems as they repeatedly scan the page's DOM.
So there might be a factor there. But perhaps it could be an add-on. I discovered that Lastpass injection feature to autofilled had a performance impact.
Switched to Bitwarden and it was noticibly faster.
Could you guys please add a feature where any link opened from within a container opens in the same container category? (Like if i'm in Personal, I stay in Personal unless I explictly opt-out)? It's such a pain to constantly right-click and open tabs. Thanks :)
Open the extension, click on 'Personal' and deselect 'Limit to designated sites'
PS: You can ctrl+click on the 'plus' button on the tab bar to open a new tab in the current container.
Try one of the many browser extensions that spoof Chrome useragent. For me it makes a big difference on Google search results and Youtube
I am replying only because I think your comment can be misleading to other readers of HN.