They have complete freedom on their servers. On my computer, I make the rules. They are lucky if I allow their code to run at all.
a somewhat bigger problem is that to a very significant extent the actual owners of the machines are microsoft, google, and apple, not the users; they make the rules, and the users are lucky if the owners allow their code to run at all. under those circumstances, blocking fingerprinting is practically quite difficult, because the 'they' who want to fingerprint you and the 'they' who make the rules about what code run on your machine are the same people, not two opposing groups
an additional problem is that an increasing part of the web is run by criminal elements like harvey weinstein and the rest of the mpaa, who will block you if they can detect you attempting to protect your privacy from them by blocking fingerprinting, even if apple decides it would be a good idea; cloudflare and google are perhaps the most prominent enforcers here, perhaps somewhat reluctantly
But I would also accept all those multimedia APIs (canvas, WebGL, WebGPU, everything audio and video, including the <video> tag) and some others (e.g. service workers and everything else app-like) requiring a permission. Again, most websites don't need them, so given the abuse potential, there's no reason why they should be openly available.
But most of it is bullshit tracking, anti-scraping and similar stuff.
Safari still has show stopping perf bugs in WebGL 2 (a 2017 finalized spec): https://forums.developer.apple.com/forums/thread/696821 https://forum.unity.com/threads/unity-webgl-poor-rendering-p... so Mac/iOS users wouldn't notice a difference probably.
If you want a unit of energy you need power multiplied by time not divided, so “gigawatt days” not “gigawatts per day”.
Try to decode mpeg video at HD resolution in software sometime.
If a website that has no obvious case for using the GPU, but is instead using it to fingerprint, then the user won't experience any slow downs from a software renderer (as it is usually done relatively quickly).
If a website needs the GPU for their videos/graphics, but also incidentally wants to fingerprint you, you're shit out of luck in that case. But this is no worse than what we have current day.
It would still be way less than what large companies are burning on training proprietary LLMs. Do you think the ChatGPT model you use daily was the success at first go? And in that same world, consumers should not even try to protect themselves from GPU fingerprinting?
> The same people who have spent the past 40 years getting confused and worked up about cookies?
Stop with the condescension. It's not about being confused; it's about mitigating genuine privacy concerns. We're not idiots, and dismissing genuine worries won't make the issues disappear.
And most websites most users visit will need the GPU to be remotely usable. For them enabling specific permissions for every website they visit is very inconvenient.
But you can probably also use those to fingerprint, but probably not as precise.
Firefox has only started to ship hardware accelerated video decode a few versions ago. Until very recently, all my video playback was software decoded.
Privacy in browsers is a lost cause. It's a 30+ year old technology that has become ridiculously bloated in scope, with privacy and security only considered as an afterthought.
A bit like Ad Nauseam that loads ads in an invisible sandbox and clicks on all of them to mess up their reporting.