It means that Google has found out that among 1000 people, your browsing criteria with HTTP headers alone is unique enough to identify you with 95% accuracy, which is actually even more frightening.
It means that Google has found out that among 1000 people, your browsing criteria with HTTP headers alone is unique enough to identify you with 95% accuracy, which is actually even more frightening.
This seems to work pretty well for me (Google got really confused, thinks I am on Windows now - I am not).
Just don't turn off media.gmp-widevinecdm if you want to keep watching DRM-protected content (e.g. Netflix)!
If it is the latter, please file a bug against Firefox to get it fixed.
Nope, because the order a Browser Engine loads assets is different in Chrome vs. Firefox vs. Edgium, too. Combine that with Firefox's messed up Accept header and you'll have them TOR Browser users, for sure. "@supports" in CSS is additionally a very unblockable way to track users, as it varies uniquely per-Browser-version as features of CSS get implemented and/or get fixed.
Usually traffic analysis for a client (with a specific ETag header) is enough to uniquely find out whether it's the exact same machine, hence that's what the header is made for.
The approach behind my browser tries to actively modify the contents of said malicious HTTP headers and to rewrite the HTML, CSS and other assets in order to force-cache everything and by laying off as much traffic as possible to surrounding peers. [1] But it's far from production-ready.
There's also a frightening amount of CSS features that can be used to track users very easily. @supports, @media, and a combination of <link media=""> and "srcset" attributes in a quick prototype was enough to track every client with around 98.3% accuracy, and I decided to not release the fingerprint.css project due to concerns how it might be abused in the wild.
Especially with unicode behaviour inside the CSS files themselves. CSS ident-tokens [2] are specified as "non-ASCII" so they can be emojis, too. And those have varying support across all Browser versions due to the ICU library being embedded in them (and being absolutely unique in every single subminor release I've tested so far).
Mixing in noise feels like a solution because it is hard for a layperson to see how a signal can be extracted, proof by "difficulty to me". If you mix in noise that changes averages then you are removing signal. If you add in random noise, each individual measurement deviates, but the limit of the average will be the same value pre-mixing.
Some browser vendors have started to remove the specific version from the User Agent string, for instance. Tor browser window is an actual square specifically to make that value (browser width & height) the same across all its users and improve their privacy (by making that value useless in finding uniqueness)
Hope that makes sense, sorry if I mis-explained some things
For example suppose my user agent string (and canvas fingerprint, accept header, etc) was different on every request. Would this be enough to stop ad networks from correlating each of my very-unique requests, and prevent them from tracking me across different pages?
Worst thing is, unless this is used by a very large chunk of the population, it would even be another tool to identify you.
How exactly? It seems like a difficult problem for a website to me.
2. They would have to track the noise over page requests to know that it was noise. The saving of and correlation of the saved state would be a pain.