Identifying People by Their Browsing Histories
schneier.com
schneier.com
Question: Was Mozilla replicating using a "vanilla" browser (e.g. no adblocking/tracker protection)? Or is this even after tracking mitigations are put into place? Mozilla's own Firefox now has built-in "tracker" protection in all versions of its browser, so it seems like they would be well-positioned to test whether the de-anonymization is thwarted with tracking protection toggled on or off.
Should the top concern be about identification or deep collection of browsing history?
It's not talking about a browser.getHistory() API. Owning the 3rd party resource (CDNs, analytics) that is loaded on most big websites is far better than that.
I'm surprised how many companies (Facebook, Verizon, Adobe, Oracle, Twitter) are almost matching Google's tracking networks. Google's makes sense based on the amount of Adsense / Analytics trackers there are out there, but I hadn't realized these other companies are just as pervasive.
Edit: typo.
I get that a browsing history C is unique, but if I clear it, how can you identify that my new history D is tied to C and not unique?
But any given website is much tighter than that: a regular visitor to Cambridge Evening News is unlikely to be based in राजनांदगांव, and vice versa.
Someone is regularly accessing the website of one local take-away restaurant in Larnaca, a gay men-only dating website, and Ars Technica? That’s probably already got you down to 2-15 people out of the ~3e9 on the internet, with just three specific websites in their history.