Reddit's website uses DRM for fingerprinting (2020)
smitop.com
smitop.com
EFF appears to have rebranded Panopticlick as "Cover Your Tracks", but it's usually a fun thing to look at in discussions of this type as an example of what can go into a fingerprint and the informational value of various parts:
Thank you, but no.
The alternative (advertising) is not better.
> exclude all the people in the world who either don't have a credit card, or don't want to use one.
Advertising also excludes everyone except a tiny minority (the advertisers) who are allowed to call the shots because they’re paying the bills.
> The alternative (advertising) is not better.
Umm, adblockers, tor and whatnot can help with ads tracking and but you can't take back your privacy once you've given identifying information.
>> exclude all the people in the world who either don't have a credit card, or don't want to use one.
> Advertising also excludes everyone except a tiny minority (the advertisers) who are allowed to call the shots because they’re paying the bills.
You have no idea how extremely white this part of the internet is that we're currently on. Comparing not having credit card to having ads in your browser is ridiculously out of touch with reality.
Ad-blockers only work as long as there's a majority who does not use them. If everyone uses ad-blockers, the system collapses. Furthermore, ad-blockers encourage a game of cat & mouse where both the provider and the consumer are constantly at odds, with nasty side-effects like alternative clients being forbidden, etc.
> you can't take back your privacy once you've given identifying information.
My argument is that you should be able to give identifying information without it being abused for nefarious purposes.
> You have no idea how extremely white this part of the internet is that we're currently on
Oh come on, there was no need to bring race into this. But hey, if that's your argument, I'd say that having a bunch of white tech-bros in the ad & social media industry control the entire communications infrastructure and social fabric of "non-white" (to use your words) nations is not better.
> Comparing not having credit card to having ads in your browser is ridiculously out of touch with reality.
Do you really think that ad-supported platforms just offer service to the credit-card-less third-world for free? No, they do so because there are advertisers who are happy to pay, and those advertisers in turn know how to get their money back (and more than that) from those people without credit cards.
I doubt this is a win.
How so?
On topic, you could just have multiple payment methods side by side.
Coinbase, for example, only allows transfers of Zcash to transparent addresses, which can be traced, and buying Monero isn't possible.
Exchanges don't need to have this limitation, and some others don't have such a limitation. Gemini, to name probably the most prominent example, supports withdrawing to shielded addresses [2].
[1] https://f-droid.org/en/packages/com.nighthawkapps.wallet.android/
[2] https://www.gemini.com/blog/youre-one-step-closer-to-financial-freedom-with-shielded-zec-withdrawalsA black hat's wet dream of a site.
Eventually, the site owners won't want to deal with that either. So, who's court do we put the ball in now?
At LimeWire, for a while, the price for LimeWire Pro was a hidden field in the order form, because the CTO (rightly) wanted to minimize the amount of logic running on anything that touched credit cards. The form was generated on one host and posted to another, and the logic for experimenting with lower prices at certain times, etc. was kept off of the host that processed credit cards.
As a result, some more technical users could order LimeWire Pro for $1. But, they could also find LimeWire Pro using the free version, so no real loss there. However, some carding gangs also noticed, and would validate huge batches of credit card numbers by buying LimeWire Pro for $1. The cargebacks were a bit painful, but more importantly, if your fraud rate is above some threshold, your fees go up, and at some point our credit card processor gave us 2 months to bring down our fraud rate or they'd cancel our merchant account. The processor also refused to give us fraud information updates with any finer granularity than monthly, so we basically had two tries to bring the fraud rate down.
All of the existing CAPTCHA systems I could find required a shared filesystem between the process generating the CAPTCHAs and the process checking the answers. That was a no-go with our policy of minimizing attack surface of our credit card processing host. So, I wrote a CAPTCHA that used HMAC to generate a 96-bit tag from a timestamp (at 1 minute granularity), the user's IPv4/24, and the price. The other 64 bits of SHA1-HMAC output were used to seed the prng that generated the CAPTCHA. The timestamp and 96-bit tag became hidden fields in the HTML purchase form. That way, the credit card processing box could validate the time, IP address, and price, and check the CAPTCHA answer, all from the submitted form data. Answers with timestamps more than 20 minutes old were rejected, so the processing box only needed to remember all of the correct CAPTCHA answers over the past 20 minutes to avoid replay attacks. Making the timestamp 1-minute granularity prevented bots from hammering the system until they got easy CAPTCHAs.
The first day we put my CAPTCHA system in production, we saw an IP in Virginia very rapidly trying to make purchases without the CAPTCHA. Then it paused for a few minutes while the attacker figured out what was going on and manually solved one CAPTCHA. Then a rapid-fire batch of purchases came through with the same CAPTCHA answer, and only the first purchase came through. A couple minutes later, that exact same CAPTCHA 96-bit tag and answer came in from a UK IP address, but it was rejected because the 96-bit tag didn't match the HMAC.
Those were fun days, but it's a shame incentives are so misaligned.
While I can appreciate that, how much time did this take, of how many people, for how long? I ask all of that as someone about to launch a public facing retail site, and absolutely dread this type of stuff. It's a side hustle project on top of my actual day job/contract jobs, AKA I don't have a lot of time to dedicate to this.
Stuff we built at a neoBank to prevent credential stuff from password leaks was a lot more sophisticated. Couldn’t trust email based 2fa because people re-used passwords. We did invasive hashing of internal networks with webRTC and also pierced proxies with STUN. Along with using a commercial waf that did real time profiling.
I mean, not horrified enough to prevent them from paying my company $18.88, but still horrified.
In retrospect, given that we were a 13 person company selling software with a marginal cost near zero, we should have left the system in place and never processed the $1 charges. Instead, we should have used a CRC32 of the upper-cased name and credit card number (in case they verified consistency) to accept 98% of $1 purchases without ever charging any of the cards. Even better would be to do a 2-part credit card transaction, first placing a hold on the credit card for the full purchase price, and waiting one minute to see how many different credit card numbers came from the same IP address in the next minute. If less than 4 different numbers came in the past minute, go ahead and complete those transactions, otherwise put the IP on the hellban list to start getting randomized results. Injecting pure noise into the carding ecosystem would have cost us nearly nothing (and given a 100% discount to a bunch of active duty sailors).
They also have a separate "Checkout" offering [1], which requires some code client- and server-side to generate the page.
So far, Stripe has been awesome for me selling $2.50/mo subscriptions using just the link [2], and as far as I know, suspicious transactions are very likely to be blocked by Stripe Radar which is across all of Stripe.
However, their chargeback protection service (0.4%/tx for total protection for any chargeback) [3] is only offered for the Checkout version. This means I won't be protected in the case of a chargeback, whether by a customer or fraud that slipped past Radar. ("Currently, Chargeback Protection is only available on the new version of Checkout" is what I was told by support)
[0]: https://stripe.com/payments/payment-links
[1]: https://stripe.com/docs/checkout/quickstart
[2]: As a student I get fees waived for the first $1000 in volume, otherwise fees would eat through 20% of my revenue immediately at this price point. I posted about this side business recently as a Show HN if you would like to know more :)
I've had the displeasure of getting hit with a bunch of fraud charges and the resulting chargebacks. It literally ended our small 2-person operation as we not only lost the money from the sale but also the product that had been shipped. This was early '00s, and online merchant accounts back then were not any where like Stripe. This is the one area of a trying a new online biz that concerns me the most.
A sad state of affairs in finance when this is a legitimate concern.
Google tmf match for more info. One such result: https://stripe.com/docs/disputes/match
You can manually trigger a 3ds authentication flow when setting up the payment intent: just set payment_method_options[card][request_three_d_secure] to "any".
Ran a 3.000+ tx/day business with this and got less than double digit disputes per month which are usually lost by the customer. Those disputes are also not for "stolen credit card", but "not delivered product" or similar bs.
Fun fact: If three_d_secure.authenticated is false but three_d_secure.succeeded is true, the bank did not authenticate the payment but you are still protected from chargebacks since the bank accepted the liability shift. (Happens for smaller purchases, e.g. < 30€ && known device && customer authenticated another purchase in the last three purchases he did with the card)
If you are using a no-code solution and are not setting up your payment intents manually, you can also subscribe to radar and create a rule for 3ds if amount >= 0€.
* These numbers are from my experience of running our shop for a software company.
Or if you want, use virtual credit cards that give you a new number every time, and will pass without a name/address match
For small business, this kind of thing could be the death of that small company.
I've heard that it worked for Metafilter but I wouldn't be surprised if it prevents a site from scaling users past a certain point. (I mean, sounds great to me, but probably isn't what someone running something like Reddit wants.)
I wonder if you've looked at the Bitcoin transaction fees for a $0.05 payment lately...
Highly profitable attacks, or using stolen credit cards bypasses this protection, since it's either still worth your while, or somebody else is paying
I just looked to double check nothing changed since I last bought something and it looks like the have a customer match but only as a holdout/narrow. Which is weird if true? as in can't upload a list and target those users if i'm reading their page correctly
pushing their s*t redisign and mobile app on us with more feed ads might mean they are trying to push for 1st party data based targeting though
Unlike the vote system there is nothing the admins do to counter this problem.
I kid you not, I had an offer for $500 to sell my account.
At that level I'm curious if you have some sort of special high value account (ton of karma, a mod of major subreddits, or have a lot of domain specific reputation), or if that offer is coming from someone who's trying to scam you in some way.
Edit: From a sketchy account buying site that I wouldn't trust too much, the price for Reddit accounts runs from ~$3-16 per thousand accounts, depending on age. For comparison, Twitter accounts with 100 followers are ~$4, Instagram accounts with 500 followers are ~$12, Hotmail accounts are ~$100, and GMail accounts are several times that, depending on age and provenance.
They offered $200 and I haggled to $500 then ghosted them just to see how far I could take it for kicks. Definitely didn’t sell it. I don’t drink the Reddit kool-aid but I’d rather not directly contribute to astroturfing for pay.
No web code should be given technical means to do such things in the first place. A big part of the problem is browsers are too liberal in exposing various unreasonable APIs.
Edit: Even in the IE days they were always playing catchup. Firefox is just the poor/free man's alternative to the corporate browser of the moment. They don't really steer the ship, just follow trends.
And these days Mozilla is basically an adware company anyhow. They just keep bundling random crap with their browser.
I think fixing the browser is a less tedious task than limiting useful internet surface like this.
not since the port scanning from ebay have i seen something this reprehensible
That was the same company/script btw.
Pretty sure this bot is just an excuse for ads and retargeting.
Make forums great again please
It's true there is a need for a programming focused community that is outside reddit. Reddit host objectively depraved material along with scientific or programming subs, and has been caught spreading revenge porn or grooming minors multiple times. Never used discord.
Unfortunately it's a single point of failure and randomly entire types of subređdit are banned and disappear forever a recent example that springs to mind were the "sporetrading" mushroom ones, some 12+years old guttednowhosting none of the same content although the topic is only legally restricted in 3 states.
So it goes.
Discussion:
For that to happen, someone's going to need to write some great (and ideally open-source) forum software -- something that's as engaging to use as the centralized alternatives like Reddit and Discord. Most of the classic forum packages like phpBB have fallen by the wayside; more modern solutions like Discourse or Invision fail to hit the mark for various reasons.
With forums you sometimes have threads of over 100 pages that started in 2015 or older where people are still talking about the same thing and newcomers can diagonally read through the pages and see the progress of something.
I see this sentiment a lot here but people don't seem to understand why reddit "won." You essentially have access to thousands of forums without having to maintain an account on each of them. You may see this as a feature not a bug but given the popularity of reddit, I'd say most people disagree.
I recall in the old days there were a few services that would do hosted forums, but nobody seemed to think "hey, let's combine them under one hood and ebable discovery."
Forums, for reasons we could go into, just never were as compelling to most people as Reddit's solution, though they are good for other things.
They were also extremely juicy targets, not only from a "steal a bunch of emails and password-hashes" angle, but to spam with links for SEO-purposes. I think this constant attrition is what ultimately killed them. It simply became untenable for one person to stem the tide. Reddit lives because it has the economies of scale on its side.
Then, I cleared all of my cookies/autofill/local storage data, connected to my phone's hotspot (which I had never done before), and made another account, and it still got banned shortly thereafter. I have to guess this is why they are fingerprinting.
* They said it was for ban evasion, but I wasn't banned anywhere as far as I knew. The only thing I can guess is that their systems grouped my accounts with someone else's accounts(maybe we connected via the same coffee shop hotspot at one point, or something), they got banned, and then it looked like they were evading the ban with my accounts.
None of them have anywhere close to the performance or loading problems reddit has (Safari related bugs however? Probably on par).
It's slow and bloated to force you out of chrome/firefox and into the app they control.
Yes, but nobody makes a slow and bloated app on purpose. It's slow and bloated because they have deprioritized the web app.
Mobile apps do provide better experiences in most cases for sure, of course, but crippling web-based one on purpose is a dark pattern IMO.
Yeah, I'd never work on such a thing unless I'm desperate about money immediately, it would be sad but it's also sad for me to think that somewhere, someone is probably tasked with it.
Reddit's website uses DRM for fingerprinting - https://news.ycombinator.com/item?id=23774394 - July 2020 (540 comments)
If yes, is there an extension to block extension checking
I often wonder what the GDPR implications might be for these providers; given the amount of invasive, uniquely identifying telemetry they hoover up.