Introducing Collusion: Discover who’s tracking you online
mozilla.org
mozilla.org
To answer an issue which Nostromo and others have brought up, I am well aware that the addon is incomplete until it also includes data on Flash cookies, tracking pixels, localstorage, iframes, useragent fingerprinting, etc. I plan to add all of these things; the bug for adding Flash cookies is at https://github.com/toolness/collusion/issues/22 and I would greatly appreciate help with implementation from anyone who's interested (hint, hint!)
I'm also working on making the graph actionable, i.e. you should be able to click any node and say "Block" (or "whitelist" for sites you are OK with). Firefox already has the ability to set site-specific 3rd party cookie policies, but the interface to it can charitably be described as "for experts only". Collusion could provide a much more usable way to control your browser's policies.
The graph, for those who asked, is drawn using d3.js and SVG.
The demo does not require flash; it uses SVG. You just have to click "click here".
EDIT: found the old HN post, http://news.ycombinator.com/item?id=2741249
I'd really like to see the browsers take on this practice. Safari, for example disables 3rd party cookies by default, but leaves open this huge hole via Flash.
NoSciprt allows you to do that, so does Flashblock. I'm sure there are similar plugins and extensions for browsers other than Firefox (well, maybe not NoScript, it seems pretty unique).
Check your browser at http://panopticlick.eff.org/
Basically, using useragent, plugins, time zone, language, screen size, etc etc etc, you can fingerprint a user pretty reliably without using cookies.
Cookies are just an easy way to track users client side, but if there is an 'assault' on cookies, then people will just start relying more on server side tracking of users instead.
Disabling 3rd party cookies etc really achieves nothing.
Also, there's numerous methods you can use to store "cookies" in the browser these days, (localstorage api, http cookies, flash, cache etc)
If you really don't want to be tracked for some reason, disable javascript, clear out your user-agent, and use TOR.
One interesting thought: how much space would you need to pull this off? Chromium generates 12 KB of data which can gzip to 3KB, Firefox generates 5 KB of data which can gzip to a little over 1KB. Truncate-then-gzip could be used to keep perhaps 0 - 4 KB per person. Assume that your average user uses ~2KB. That's still rather a lot, when compared with what you can do with counters -- 8 bytes or so to store. If you wanted to keep your database under 2 TB, you could only handle a million people, not hundreds of millions. So it would really be a big distributed project to link identities as they evolve over time. I imagine that's one huge factor in using tracking cookies; it's lazy for scaling.
An interesting project might be to create a database having a table with the useragent hash as the primary key, and associate each identity in the user table to a number of these useragent hashes.
fairly successful? eh.
Those may be unique for your browser right now, but if you were to update your fonts or your plugins, that would generate a completely new user and all their information about you would be lost. Same as if you delete your cookies, but I bet it happens more frequently.
Likely this could be done in a way that doesn't violate any terms of service or data disclosure promises. After all, pushing out "browser fingerprint 'abcd' and 'efgh' are the same person" isn't disclosing information that most people would realize they're trusting someone with.
More than likely, only the browser version will change. For larger updates, would-be-broken plugins would disappear or see a newer version. It would be a ton of effort to track users this way, but I think it's within the realm of reason for those with enough incentive (NSA, maybe advertising companies)
User Agent provides quite a lot of identifying information; OS/OS version, browser version. Panopticlick breaks this down for you, one in every 186,062 data points they have has my User Agent. This provides 17.5 bits of identifying entropy (log2 of 186062).
They mention they have a total database size of 2,046,684, which requires 20.96 bits of identifying information. So to answer your question about how much identifying information you can get from Javascript, a lot.
You can then also get Flash Version, Time Zones, Browser Plugins, IP Address, Screen Info.
At which point the word BS comes to mind.
But just for grins, I repeated the test with a Chromebook fresh out of the box, and of course it's flagged "uniquely identifiable".
I'm not saying the underlying claim - browser characteristics can be used to track you - is bogus. I am saying that I think that site is intentionally exaggerating for effect. Or, more realistically, that while they can extract 20+ bits of info from those strings, the values in that 20+ bit domain are far from uniformly distributed.
But just because, I tried two more chromebooks (same model), both in guest mode, both stock configuration - and they're both flagged as "unique" too.
Maybe I'm just a victim of a really long update cycle of their database.
(Addendum: I went back with my original laptop, all cookies cleared, and it's indeed not considered unique any more. So maybe I really just saw some lag in updating their DB)
(Addendum 2: Just to clarify, I never doubted that you can be uniquely identified. But the "unique" part was wrong for my sample. )
I know that incognito mode is geared towards not leaving a trace on the user's computer rather than being anonymous to the server, but I guess I assumed that with the plugins disabled they wouldn't be visible to the server.
An alternative I'd like to see is a standard somewhat fixed small set of plugins and fonts.
AFAIK it's not very useful information and certainly removes one of the bigger unique factors.
Most of these tracking pixels are not flash anyway so blocking flash won't accomplish anything. Blocking Javascript will do something of course but some are only images so it will still be pointless and you'll still be tracked.
The reality IMHO is that it's better to be targeted by relevant ads than to see dating/scammy ads everywhere.
IMO it's better simply to add "rm -rf ~/.macromedia" to the list of shell commands that get executed upon every login -- or add the commmand as an entry on your personal crontab.
Windows users:
Documents and Settings/yourusername/Application Data/Macromedia/Flash Player/Shared Objects/your flash userid/
Documents and Settings/yourusername/Application Data/Macromedia/Flash Player/Macromedia.com/Support/Flashplayer/Sys/
Mac users: Places/yourusername/Library/Preferences/Macromedia/Flash Player/SharedObjects/your flash userid/
Places/yourusername/Library/Preferences/Macromedia/Flash Player/Macromedia.com/Support/Flashplayer/Sys/
Wow. I have flash cookies from over 700 sites.You can set it to clear your Flash cookies at the end or beginning of each session.
> If you're not paying for something, you're not the customer; you're the product being sold.
http://www.mozilla.org/en-US/collusion/demo/
I also find the name "collusion" unfortunate. Part of my paycheck comes from advertising, and I include google analytics on my site. However, I also work hard to have a crystal clear privacy policy and I don't opt in to the shared analytics logging for my site, so the data only goes to me. But I'm lumped in with the scummiest of ad networks.
Mozilla, of course, offers a free browser. Their funding ultimately comes from the "collusion" they're talking about here and the search traffic they generate feeds it. More directly, you can argue that they sell our search data to the highest(?) bidder. Why isn't DDG the default search provider? Why aren't third party cookies disabled by default and the Do Not Track header enabled by default?
These are actually hard questions, and trite soundbites that ignore actual economics and the tensions inherent in the internet we have today do us no favors. Transparency is the answer in many of these problems we've created for ourselves, I believe, but we need to be able to talk about them with equal intellectual clarity.
edit: as an example, I really liked EFF's Peter Eckersley's quotes in the ars technica article on DNT today:
http://arstechnica.com/tech-policy/news/2012/02/can-do-not-t...
I think the understanding is that advertising is required for many free things on the net (including Firefox), but that unless advertising behaves in a reasonable manner, and the user has some control and understanding over it, it'll be self-defeating as everybody will go start running Adblock, Ghostery, etc.
Do Not Track works due to exactly the same economics. I think there was a public statement that if Do Not Track were enabled by default - no-one would respect it.
There is no conflict of interest here. You either self-police or you're shut down.
It's a similar argument for the name "collusion". Good marketing, yes, and maybe that's important to get attention and the name isn't that negative. At the same time, it paints everyone with the same brush when, again, the ostensible goal is not to shut down all ad networks on the internet, or the sites that are funded by them, but to give transparency into the links between the ad networks and the sites we visit, in order to hopefully force responsible behavior and give plain choices to end users.
And that's why I pointed to the EFF's statements in that article. They acknowledge the tensions inherent in the internet we've built and inherited, and postulate that it's possible to force everyone to be better actors without having to burn the house down. Moreover that meaning is exactly what they say, without resorting too much to rhetoric.
An excellent question. Does DDG have the infrastructure to handle that many searches? It didn't last I checked...
> Why aren't third party cookies disabled by default
Because it breaks things entirely unrelated to ads. For example, with third-party cookies disabled I can't buy tickets to http://www.puppetshowplace.org/ online for my kids.
> and the Do Not Track header enabled by default
Because then it would be completely useless. See http://blog.mozilla.com/privacy/2011/11/09/dnt-cannot-be-def...
I do agree that there needs to be a distinction between "showing ads" and "tracking users", of course. Those are not the same thing.
1. Tracking ad frequency and performance (e..g, did you buy something after you saw an ad; don't show you more than X ads for a given product)
2. ID synchronization between ad exchanges, ad buyers, and data targeters
3. Retargeting (e.g., showing you an ad after you've been to a site)
4. 3rd party data: things like guessing whether you're interested in cars or ceramic figurines and selling the ability to target you with ads
5. Site performance data (omniture, google analytics etc)
This demo only showed me 3 cookies from IMDB (which I browsed in this session I guess).
Note: the "restore my last session" link in firefox will work against this setting and reload your cookies from the last session.
Perhaps that's an irony that the bank should consider, or anyone that has weird password requirements that end up working against their goal.
Typically, an ad network wants to conform to the guidelines set by the IAB [1], which explicitly recommends against flash cookies, calling them illegal [2].
So, all in all, if something can hurt a brand's reputation among consumers, advertisers generally don't spend their money there. Shady practices like these are among them.
[2] http://www.iabeurope.eu/news/iab-europe-condemns-%E2%80%98re...
https://addons.mozilla.org/en-US/firefox/addon/cookie-monste...
I browse with Flash disabled (tip: there are ways of bypassing the Flash Block add-on, so disable the flash plugin completely when you don't need it, it's easy to re-enable and reload a page on occasion) and have the Better Privacy add-on cleaning up Flash cookies on a timer and at browser close:
https://addons.mozilla.org/en-US/firefox/addon/betterprivacy...
Also, the Ghostery plugin is a nice lightweight alternative to AdBlock to just block tracking scripts without wiping out ads everywhere. It kind of side-steps the tracking issues this Firefox Collusion plugin is highlighting.
(Note: I work at Mozilla, however have no clue specifically about Collusion.)
If you can reproduce the bug using 'generic' websites (I don't want to know about your private browsing habits), would you mind filing a bug report in https://github.com/toolness/collusion/issues ? It would be a big help. Thanks a lot.
2. You can disable third-party cookies in Chrome's preferences if you like
In fact, based on advertising trends, they actually find it useful and respond well to it - adverts that show you products that you've recently been browsing for etc.
This doesn't, however, block all tracking scripts, as some may get your IP via an embedded 1x1 gif or other request. There's still the issues of super-cookies, or Flash cookies, or scripts that embed a unique image in your cache and then read it out, etc. So for this I recommend AdBlock or Ghostery.
Edit: Here's aseful link on this topic: http://samy.pl/evercookie/
The demo mentions the privacy concerns of third-party cookies, but does not mention that there are significant positive uses for such cookies. In the demo, reference.com sets cookies for thesaurus.com and dictionary.com, which are different domains run by the same operator. Such cookies allow the operator to provide customized services across the domains. Third-party cookies allow for richer embedded-content experiences. Video is a great example of that.
The revenue sites can get from third-party cookied ad networks is significantly higher than from unpersonalized third-party ads. Large sites like HuffPo and NYT are able to sell a lot of their premium inventory directly, so a big reduction there is likely to disproportionately affect smaller sites.
In order to do this, a browser (or extension) would need to track through which sites a 3rd party cookie was set, and only send the 3rd party if you're on that same site again. Else it should just pretend there is no 3rd party cookie.
I'd definitely install an extension that would implement this process.
I know it sounds strange, but it doesn't bother me one bit.
My config is as follows:
1. AdBlock (+privacylist)
2. Ghostery
3. RequestPolicy
4. HTTPS Everywhere
5. /etc/hosts with common tracking hosts pointing to 127.0.0.1
6. Disconnect.me
7. Disable 3rd party cookies
8. Uninstall Flash (when I need Flash, I use Chrome)
9. Configure Chrome Flash to not allow any local storage
10. about:config set dom.storage.enabled to false.
This is just a start and it would be nice to have some consistent way to disable localstorage.
* AdBlock Plus (with 16 filter subscriptions)
* BetterPrivacy
* User Agent Switcher
* RequestPolicy
* NoScript
* PrivacyChoice TrackerBlock
* Ghostery
* QuickJava
After installing Collusion and going to both the BBC webpage and a random selection of Gawker Media's webpages, the Collusion graph is empty. I can now confirm my selection of security plug-ins prevents tracking. Sweet! :-D
It sniffs your local packets and tells you all the sites that connect to your computer while you browse.
Then I organize them by number of times connected to your computer. It reveals some really weird sites. Like somehow pandora knows my age and sex....
http://f.cl.ly/items/3A2C0x2a1f0F370Y0d3E/Screen%20shot%2020...
It also seems to want to push some graph nodes off the screen.
Essentially, just about any banner advertisement will show up on Collusion. Also, any type of javascript visitor tracking like GetClicky or Google Analytics.
http://code.google.com/apis/analytics/docs/concepts/gaConcep...
On a side note, the doubleclick cookie is explicitly excluded from linking without explicit consent:
> We will not combine DoubleClick cookie information with personally identifiable information unless we have your opt-in consent.
In theory, I see your point about Google not having direct access to a site's first party cookies, but Google is clever. If you monitor the requested resources when you visit any site with those cookies, you'll notice a request to http://www.google-analytics.com/__utm.gif? followed by parameters sending the values of those cookies to Google. So, they are tracking said cookies.
So I think Analytics "sees" 80% of your browsing but it's multiple fragments, each going to different analytics domains. It's never seen as a single user.
Can't Google make certain (admittedly imperfect) inferences based on seeing the same IP address visit gmail.com, then AllThingsD.com, then CA.gov, etc? (All of which use Google Analytics) It doesn't take rocket science to place a high probability that the the IP address that visited gmail is also me across all those domains.
Why go through all the pain of setting analytics such that: it uses per analytics domain first party cookie, serves the javascript and the tracking gif on google-analytics.com (no google.com cookies are transmitted), but they would then try to reconstruct user behaviour based on IPs?
That would be quite deceptive (and might not allowed by the FTC and the privacy policy).
And they can already do global tracking with the doubleclick cookie. But it is explicitly not allowed to link it with other data without consent.
Edit: by the way, thanks for your questions, I never really digged into this and also at first assumed they would have access to a lot more information. But analytics is actually pretty well designed.
Will try it out on OS X later ...