Chrome client “variations” can be used to identify you (2020)
zapek.com
zapek.com
We were angry at different browsers and standards (formats, behaviors) at some point. Now this is fixed and only few chosen control the entire “market”, doing whatever they want. Time to learn the lesson?
Expecting people to put in the time and effort individually to understand the benefit of switching browser, the tech knowhow needed to download and install the software, and how to move their data over to it, all for the benefit of society as a whole, is a pretty big ask.
For a new, neutral browser to take any significant market share there has to be a benefit for individuals that's more than simple neutrality. Either that, or there would need to be some sort of international regulation of browsers to force vendors to stop tracking users so much. I don't see either happening.
Then a bunch of people decided browsers should be a platform on its own instead of displaying interactive documents.
I guess my point is it goes far beyond Chrome. Google is running the Borg hive mind.
... Kubernetes, or "kube" for short. ;)
Source: https://en.wikipedia.org/wiki/Kubernetes?wprov=sfti1
(The Borg have cybernetic enhancements, I’m guessing that’s the link)
There's a lot of security theater around this where people will de-google their software and then run random binaries compiled by unknown people on the internet instead
It doesn't need to be compromised. The biggest ad and ad tracking company in the world has all that data.
How about a browser company that syncs your data on their servers but doesn’t examine it. Even better, they couldn’t do that even if they wanted to, because your data is encrypted on their servers. That company has also never been compromised. Does that sound better?
complete E2E encryption Signal style with you having sole access to the keys and sync is technically pretty non-trivial across multiple devices (also the reason they don't sync device history on previously unlinked devices), so there's a usability / security trade-off.
Honestly not certain whether that fits the need of most users for most data they have.
Signal is blocked in China, and I'm pretty sure it isn't handing the population's intel over to anyone.
Full disclosure I work at Google.
Fortunately, since I use Chrome, I was able to log in and get them clouded over. Whew!
It sounds like it'd add an additional layer of complexity to my situation without an obvious up-side over my existing solution.
Sure, they claim they are open source and that the infrastructure was audited, but this does not prevent them from just configuring their auto-update server to serve a very special update to user at a specific IP.
This is false. The decryption code was run on the server, which means the password was sent to the server briefly. Hushmail simply stored the password for a few accounts. No client code was modified nor any auto-update changed. In fact, if the criminals had used the Java applet, they'd likely have gotten away with it (assuming they didn't update it)
>However, installing Java and loading and running the Java applet can be annoying. So in 2006, Hushmail began offering a service more akin to traditional web mail. Users connect to the service via a SSL (https://) connection and Hushmail runs the Encryption Engine on their side. Users then tell the server-side engine what the right passphrase is and all the messages in the account can then be read as they would in any other web-based email account.
>The rub of that option is that Hushmail has -- even if only for a brief moment -- a copy of your passphrase. As they disclose in the technical comparison of the two options, this means that an attacker with access to Hushmail's servers can get at the passphrase and thus all of the messages.
Only if you enable it, right? And I don't think it's enabled by default, I think it prompts you asking whether you want to or not.
Full disclosure I work at Google, but not on anything related to this.
As an attack surface, if you're worried about being spied on by the company that you got your browser from, I'd be more concerned about the closed-source control they have over the code in the browser itself than the unique identifier you're sending to their servers when you use their browser.
[1]: https://developer.chrome.com/docs/extensions/mv3/mv2-sunset/
As for this thread: let's try to talk about the specific claim in the article. Generic "boo Chrome" or whatever is too repetitive for a good HN thread.
> Additionally, a subset of low entropy variations are included in network requests sent to Google. The combined state of these variations is non-identifying, since it is based on a 13-bit low entropy value (see above).
Moreover, should use Unmozilled Firefox as well.
Why would they introduce even 1% of ambiguity if they don't have to? It would make no sense to them.
Although the combination of those numbers can still be used for tracking, this is specially hard because many users have the same varient combinations.
I've been using Firefox as my primary browser for about 2 years now - and the javascript engine on it has recently... sh*t the bed (I cannot paste links or images into facebook, I cannot paste text with line breaks into twitter, I cannot paste using reddit's "markdownmode").
I use google-chrome for netflix, recently chromium stopped working for netflix (apprently the browser is no longer supported)
Edge isn't an option for me, brave isn't on my radar (WHY include cryptojunk with a BROWSER???, it's like the early 2000s where a major vendor was trying to claim that the browser is tied so closely to their kernel as to make it a part of an OS)
Is Opera any good?
This is not normal, something's broken with Firefox in your setup. Probably worth filing a bug.
(Also it's almost certainly nothing to do with the JS engine.)
The 'cryptojunk' facilitates funding content sans our traditional advertising dystopia. Whether that's you're cup or tea or not neither the rationale nor the mechanism is difficult to understand. The cryptojunk is also off by default[1].
Should you manage to overcome this hangup and give it a try you'll have a browser that is almost indistinguishable from Chrome except that the bulk of Google's abuse has been removed, among other benefits.
I'm curious why Edge isn't an option for you? I've started using it recently and so far it's a fairly decent experience. Sure, it's Microsoft and run into the same trust and privacy issues you get with Google Chrome, but that being said, my browsing habits are pretty benign so I just accept it for what it is. Let's be honest, options are slim when choosing a web browser.
Another browser on my radar is Valvadi [https://vivaldi.com/], another Chromium based browser with a ton of bells and whistles, most of which can be turned off. It has very much an Opera vibe.
[0]: https://arstechnica.com/gadgets/2021/12/microsoft-edge-will-...
I would love to (1) see the two separated and (2) have a much smaller chrome on top. For example, I don’t even need tabs when my WM can handle that stuff for me. I’d also be quite happy for the browser to store no state in between sessions (yet still have the ability to assist with usernames and passwords — if I need persistent state between visits it’s usually handled by logging in to the handful of sites I care about.)
This is part of a wider earthy-crunchiness I’ve found in my later life, including only using a (recycled, 100$) desktop computer instead of my MacBook, and turning it off when I’m not using it. In the true pedigree of earthy-crunchy types I also apparently cannot help proselytising about my life choices!
(Having to re-log-into everywhere on every new session sounds like a nightmare, though, especially with phone-based 2FA, which unfortunately is still the best that most sites offer.)