EFF Browser Tracker Simulator
firstpartysimulator.org
firstpartysimulator.org
The best strategy I can think of is compartmentalisation. Essentially use several completely separate broswers. One with Javascript, tracking and ads allowed but only used strictly for logging into GMail or banking or stuff like that.
Another browser with reasonable safeguards (like say ad blocking) but nothing excessive like disabling Javascript, for authenticated sites.
And finally a highly locked down browser or the Tor Browser for general "browsing" of news sites and such.
This can reduce the ability for the tech giants and ad companies to track your activity outside each browser, interfering with their profile building.
I can think of no better way to guarantee you'll be put on a surveillance list of state level actors than to use Tor.
So sure you'll be watched over to some extent. But the fact is if you don't use tor you're EVEN MORE watched over because the intelligence services have "blackboxes" (that's how they call them in law) placed on the network, and anyway your ISP is required by law to keep track of each and every move of yours for 2 years.
So they know i'm using tor, so what? We're millions of people using tor, and every day there's more of us. At least they can't say i'm reading mediaslibres.org one of the only free press outlet online that's not censored by the French state.
(well now they can because i just confessed, but i didn't have to)
Citation needed.
Why is it acceptable for a website to require JS just to read some content? We should put more pressure on website owners to stop this nonsense.
This is exactly what Qubes OS provides out of the box, including Tor Browser. Has been working for me very well.
OP, the problem with your general browser is that most sites will be broken. You'll need to do captcha before each shitty modern news piece and that's even after you told your Tor browser to enable JS and less strict security. But still, I think with compartmentalization one can make tracking reasonably hard. For now.
My understanding is that they do nothing. You are on the same FF version with the same preferences and extensions and all. AfAIK, the containers will only keep cookies separate
Useful tool, and I'm really glad the EFF provides it, but take it with a grain of salt. There's nothing magic going on here, and there's no guarantee that the dataset of people visiting other more popular websites will be the same.
These "fingerprint" analyses all seem to fail to account for that fact.
"Bots" generally do not run Javascript.
The more information the client sends, the easier it is to create a more complex "fingerprint" and the more difficult it is for users to "copy" this fingerprint.
GET / HTTP/1.1
Host: firstartytrackersimulator.org
Connection: close
No Javascript.Of course, anyone can make a fingerprint from those three headers. However it is quite generic and very easy for any user to "copy".
Many website operators incorrectly assume this must be a "bot".
I can use a "modern" web browser that tries to send all sorts of information, but because I use a localhost-bound forward proxy that deletes, adds and/or modifies headers, these three headers are all the remote website will ever see.
The question is, what advertiser is seriously going to spend time and effort to try to show ads to a person who only sends three generic headers and does not run Javascript. There is little value in tracking such users if they do not convert.
You're likely attempting to use the same channels as attackers, but want to be treated differently 'just because'
Kind of hard to write rules for criteria like that.
My partner uses -- for work -- a vanilla Google Chrome on Windows browsing life. I use, for work, FF on Linux, usually behind a VPN or two in a different country to where we are.
I see maybe....100, maybe, 1000 times more captchas than she does? Embedded reCaptcha JS code on a page inevitably shows me fifteen pages of traffic lights and lets hers go through. Often sites geo-IP me (incorrectly) to the wrong location. It's a very far cry from the HTML 1.0 days. And nobody outside of HN even understands why this is a thing, and an annoying thing at that!
Honestly, to me the web feels unusable if I try to use a "modern" graphical browser with Javascript and a DNS resolver enabled. The way most people use the web, I guess. To me it feels like a tar-pit. I do some basic stuff like banking, etc. that way, but for recreational use, I do not use the major browsers.
The web is even faster when I'm using telnet/openssl s_client -connect, but that's not the point is it or even a fair comparison? I just want to browse the web without being tracked and categorised/labelled. It seems that's too much to ask.
Regarding CDN/Caching:
Google made a change[1] to how caching works which also has some CDN impact.
Instead of saving a resource with its full URL only, they have added two more bits of data to the saved information. Chrome saves the top-level site and the current-frame site next to the full URL of the cached resource. The browser uses the information to determine whether it should serve resources from the cache or not.
[1] https://developers.google.com/web/updates/2020/10/http-cache...
That's true; but it misses the point. If some bot visits some website, that doesn't expose me to being tracked. It might expose the bot to being tracked. It's when I visit a site, using my real browser, that tracking becomes an issue.
Edit: Here [1] is a relevant link from the mozilla support forum. It links to an old bug report in Tor, and they claim that this actually reveals less information about you. Imo it still makes tracking easier, but I didn't really dig into it.
[1] https://support.mozilla.org/en-US/questions/1200851#answer-1...
I don't want to make such a strong statement as to wholly blame it on the fingerprint resistance setting, but within a week of turning it on, my Google account that I use for my Android devices had all payments suspended.
As in, I could not buy anything from Google nor use their Pay service (not that I otherwise use it for everyday purchases).
Until I gave them a photo of my ID.
I finally reinstated my account last week after this happened over a half-year ago.
I originally saw it as a fun experiment to see how long I could go without needing to buy anything in the spirit of deGoogling, but I decided at this point, just in case, that I'd rather not find myself in some sort of preventable, inconvenient tough-spot somewhere down the line (largely out of an uncertain sense of physical safety).
That's fucking nuts. Why did you even accept such a thing? Why is it ok for a private company to ask for your ID and keep a copy indefinitely?
Maybe you have some other add-ons interfering?
Never was the confirmation that I'm a unique snowflake less welcome.
That being said the goal is that the vast majority of users come out unique even if everything is mostly normal individually anyways.
Bits of identifying information: 17.84
One in x browsers have this value: 233841.0
Edit: I tested this current tool and it recognized me after I returned. Opened it first normally, I'm unique. Opened it in a private window, unique. Closed that and opened a new private window, and bam, one other previous browser had my fingerprint already.
I don't have the data handy, but the idea of expressing this in terms of conceptual zip codes could be useful. e.g. a 5-digit US zip code has a wide range, but handwavy, let's say the average for all 5 digits of a given zip code is a population of maybe 5k people. 4-digits could be 50k people, 3-digits 100k etc.
12-bits of information is a one in a field of 4096, which implies to me that the Tor browser finderprint yields the unique information equivalent of sending a consistent zip code, just not your physical one. It means that your net level of anonymity requires other Tor users to also be in that "zip code" of fingerprints, which seems to have a very low probability.
I am surprised Tor doesn't appear to tumble these fingerprint features.
Do browsers ever try to fuzz any of these values? For example lying about what GPU I'm using, or occasionally swapping between equivalent timezones?
Brave does, and it is absolutely the right approach to fingerprinting. They call it "farbling" rather than "fuzzing":
https://github.com/brave/brave-browser/issues/8787
The alternative is what Firefox does (halfheartedly), which is to try to make users look similar to each other.
It really bothers me that Firefox is so stuck on this approach -- in every other way I prefer Firefox over Brave and I really do not want to switch just for this one feature. But Firefox's halfway implementation of "try to make everybody look similar" is doomed: a serious effort would turn Firefox into TorBrowser-with-javascript-disabled or worse, which is never going to work.
To Firefox's credit, one area where Brave is having problems with this is font fingerprinting, because they don't control their own rendering engine (it's Chromium). So Firefox could "do Brave-style antifingerprinting" better than Brave does, if they got serious about it:
It's more about the general paradigm of recognizing that yes, there are some web apps that would need extensive functionality that might be abused (e.g. advanced copy/pasting features for an online document editing tool, or the ability to connect to USB devices, or camera/microphone functionality, etc), but also that most web browsing does not involve things that user desires to be a web app, and all those sites should be limited to a quite narrow sandbox of functionality. All these fancy features with privacy risk that are needed for some advanced web app replacing desktop features are fine and useful, but they should be exceptions on a per-site basis, not enabled for the whole browser so that they can get used by random blog that includes a standard ad-network javascript file.
If you open in Firefox's safe mode though, it works fine. Which suggests it is uBlock Origin, but curiously the site doesn't work even if I disable uBlock for the domain.
PS. It seems Mozilla have removed the "report broken site" option from Firefox's Help menu. There is only report deceptive site.
Fundamentally, trying to make everyone look exactly similar is going to leave a lot of chances because you can only ever try, and it'll leave a machine learning algorithm or even a statistician with diff with a lot of information about what is important. The worst offence is that it relies on everyone else doing the same thing. It doesn't really work.
Randomising takes all that out. With no real way to predict it, no easy way of telling what's random and what isn't, and with no reliance on everyone else doing the same, you have just as many if not actually less bits of identifiable information, rely on no-one else, and feed garbage to algorithms which throws them off and possibly confuses you with many other people, protecting them at the same time.
I really don't get why the biggest and most well-known Tor browser, the Tor browser, would keep using such a flawed method. Better than nothing though.
Sure, an incomplete implementation of the randomizing method is less trackable than one of the same fingerprint method, but in practice
* even a non-perfect TBB method will protect you against pretty much all trackers
* and the TBB is, as a matter of fact, not fingerprintable on any of these tracking test sites.
Therefore I think saying that it "doesn't work very well" doesn't quite reflect reality (unless you have a good source on that, I might be mistaken here). And if your threat model requires 100% anonymity (which is an entire level above not being tracked by adtech), the only realistic way to achieve that is to disable JavaScript anyway.
I think something is pretty off.
They don't care that it's wrong because the exaggerated numbers scare people into believing in their cause.
Yes I get that it's possible that I'm the only iPhone in 70 million people that checked their site in the last 45 days but that's still exaggerating their point. Only a site that has lots of traffic would need to fingerprint you. So reporting that a site that gets almost no traffic and tell a couple of iPhones visited per day in the last month isn't remotely representative of a popular site that actually is trying to track
After testing, you can scroll down to see different test metrics and see exactly which fingerprinting methods (WebGL hash, AudioContext, etc) all contribute to your unique fingerprint.
It’s not just your phone model.
Also, it doesn’t include your IP address, which is the most identifying piece of information. All in all, a slanted site fit to push an agenda.
Intel Open Source Technology Center~Mesa DRI Intel(R) HD Graphics 630 (Kaby Lake GT2)
One in x browsers have this value: 13012.06
Also 1920x1200 isn't as common as I thought, "One in x browsers have this value: 95.68"
Given the way iOS works, does this mean only one in about 12k users are on iOS 14.6 using a iPhone 12 (my configuration). That seems to be what the fingerprint boils down to?