Google starts tracking all your devices in 8 weeks
forbes.com
forbes.com
So I wonder: Why are we sending out all this info. Fingerprinting is the only actual use. The number of sites using it as it should is minimal. Lets just stop giving it. They don't need a list of audio or video devices. They don't need my installed fonts. They don't believe my language settings when I whack them over the head with it. Let's just fill in defaults everywhere. Maybe provide a whitelist for legitimate sites.
Even after setting my preferred language on my Google account, Google Search was still speaking Polish to me.
With the increase in ads on streaming platforms I've just reverted back to piracy. The enshittification has gone too far.
I seem to have to "change results to English" on google searches at least once a week when it forgets which language I've setup and used for the past ten years!
Google -> Reddit -> open translated post in app -> share in app with browser again -> click on show original.
I’ve never ever let any involved websites actually use my native language. Neither Google nor Reddit.
But you add a lot of entropy to the privacy violators.
I may understand Audio, because of Edge location storage costs, but Subtitles... that’s blasphemy.
You are generalizing. Google and big providers do that, usually (US)services that need to cater to the whole world. But a huge part of the normal web still uses and _needs_ preferred language. No one wants to be forced to use geolocation.
Just one very common example are info pages for sightseeing, they are usually available in all languages that people commonly visit from and just work if you browse to them. Not to mention that geolocation would be useless anyway in that case.
It is a if the web and browser developers lived in an innocent world
It's such a no brainer, I can't comprehend it.
No browser is safe from capitalistic rot at this point.
Now, all my pay-at-the-pump interactions at gas stations are all in French. A website I was purchasing from flipped to French when I entered my card info. There were a few surprise interactions where my language preference was clearly derived from my bank card setting.
I’m just hoping that being classed as bilingual is doing wonders for my “social” score at some clandestine data clearinghouse.
Google is really bad at handling multilingual users, or even just users that don’t want to use the language of the place they connect from. Now by default Youtube even translates the audio automatically, it’s unbearable.
And I have declared the languages I speak in my Google profile. It doesn’t seem to matter.
Paying for a search engine means that I am the customer, not the product. While you are correct that my data is an asset for Kagi, it is a one shot asset, vs my subscription, which is recurring revenue.
I can look at the privacy policy for Kagi (https://kagi.com/privacy), and see that I am not at risk of having my searches logged or data shared. I trust them because violating that privacy policy puts them at risk of being sued by me, and by any investors in the company.
As you yourself stated: either company is capable of building a profile. One has promised not to do that contractually, and google, more or less, has promised to do exactly that regardless.
Now, I don't speak or read Chinese and couldn't immediately find a way to change the setting back to English. Could probably find it on the internet but .. Oh well, I don't really use LinkedIn so it's just stayed that way now.
I can understand it if someone's sending out something like a Google Doc collaboration invite, especially to a non-GMail address, the email will be in the Google Docs UI language of the sender. But LinkedIn has your profile with all your preferences!
What next, a colleague shares the link to a location, you open it in your car, and your car UI turns into Chinese?
Frankly for a company that's a Spyware company, they sure are incompetent.
I do realize this is a tall ask, as many of these vulnerabilities arise from standards promulgated by the surveillance industry itself (chiefly Google, of course), and so are not easily mitigated. For example font lists and ask-to-use-microphone are straightforward to fix for general web browsing, whereas the fix for browser viewport size requires some kind of thoughtful design that subsumes the old model.
In general I'd say that browsers (or at least their operating modes) need to start differentiating into different things for the open [season] web versus app runtimes, so that vulnerability mitigations can be stronger for the open [season] web and sidestep complaints that it disrupts legitimate apps. Of course the two modes need to be indistinguishable by websites, lest every two-bit xitter-summarizing "news" site insists that it's some special snowflake needing app functionality to run its surveillance code.
Also since I'm apparently writing my Christmas list, we desperately need widespread privacy laws in the US. If you want a "value add" feature of your product to be shoving ads in people's faces, fine - people at least get immediate and actionable feedback from that. But persistent tracking supported by pervasive surveillance is completely at odds with individual liberty. And taking away the largest consumer surveillance market would mean much less being invested in new ways to attack users.
And from a technical perspective, Accept-language doesn't seem terribly hard to mitigate - exactly one language at a time, and UI that allows a user to easily change to another, as if it's part of the logical URL. It's all the javascript APIs, especially the graphics ones with their loads of weakly-defined behavior, that are especially pernicious.
Do any of the mobile-friendly alternative HN front-ends support commenting without giving up your creds?
This is obviously illegal in Europe, the UK and California (no consent), and an unnnamed regulator warns that it intends to take action.
(Yes, that’s contrary to the headline. That’s why I find it confusing.)
>You must not use device fingerprints...
Compare to the update: https://support.google.com/platformspolicy/answer/15738904
[no mention of device fingerprints]
>The changes... [are] less prescriptive with partners in how they target and measure ads.
My expectation is you don't fucking store any data about me to be used for advertisements/AI/etc and everything is opt-in, period. Where is that option?
Like, I know that apparently this one is a personal blog, but why does anyone even set up a blog at Forbes. Sometimes I wonder about this.
And actually, even when knowing it's a personal blog and me a serious, I cannot really take it serious anymore when seeing the Forbes URL. I am more inclined to skip chapters, to look for AI slop, and to not take the views of the author as independent. Not consciously, but subconsciously.
Regulators really need to cut them down to size. Was bad enough during anti-trust era in the US...now we're dealing with multinational entities the size of countries. Can't let that get out of hand or we'll end up living under corporations not governments.
Big tech or big business very much prefers the scoop shit and fight it out in court method as it gives them a huge advantage.
I got one link for ya buddy.
I wish HN would support creating snapshots on some sites by default
Those "journalists" were living in a bubble ? Google (and Facebook, and Apple, and Microfost) have been tracking our devices for years.
Right now anti-fingerprinting security is not very high on anyone's minds, but remember that your digital fingerprints follow you EVERYWHERE. You can't turn them off or disable them on your side like cookies.
It's sort of like the wholesale elimination of privacy as a concept, you might say.
But hence the stupidity! It's too bold a move not to elicit a reaction from developers and users (who have the power to discover just how many bits of information they are leaking about themselves using tools like https://pbtest.org/).
So on one hand I can have websites that offer richer functionality by being aware of my time zone and locally installed fonts, or on the other hand I can have privacy. Hmm, which is worth more?
Damn how is this possible when I'm using a stock iPhone? I look at the characteristics and apart from timezone and language, how can they tell the same model iPhone apart?
I'm honestly curious, if you don't mind clarifying a bit more. How do your digital fingerprints follow you everywhere without your being able to erase them? This thread goes into device fingerprinting, but if one rigorously changes devices and certain use/account practices, how can they still be tracked so totally?
Your account practices will need to include only using an account on one device. Every time you use an account that identifies you on a device, that device can be associated to you; at that point its fingerprint is your fingerprint. Rotating devices faster just adds more devices to your identity.
The result is a worst-of-both-worlds: To an end user, it will still feel as if you're being tracked, with ads following you around, etc, but no worries, your privacy is safe because the advertiser doesn't have access to the data...
The site you're talking to can still read your data, but most third party sites can be cut off. Privacy Badger will let you block Google Tag Manager, and while it warns you that some sites will break, few do.
It would be interesting to purposely feed a bogus GTM cookie though. It might actually throw their tracking and fingerprinting off if somehow you were able to send random GTM tags on every request.
- nowadays (iirc) you can serve/proxy those scripts via your own domain (to circumvent ad blocker blocklists) - there are limitations re the number of blocking rules in Manifest V3
It’s cat and mouse at this stage, we’re getting to the point where blocking ads will be as hard/annoying as, say, installing 3rd party apps on your iPhone. Too much of a hassle even for fairly techie users
Use Firefox. uBlock Origin on Firefox also gets around CNAME cloaking to make advertiser domains appear as first party, which Chrome does not give sufficient access to do that.
It doesn't get around actually serving these endpoints mixed directly in with first party endpoints, but these are a hard sell on the advertising side too, from the technical effort from the publisher to implement it to the advertisers reluctance to trust the stats when the publisher gets to be the man in the middle.
Obviously, this requires significantly more resources. But it feels like a more productive use of the hardware power that we already have, compared to the most recent Electron monstrosity.
Https://butter.sonnet.io
(Because you deserve butter.)
(And yes, this is all kinda silly in a sense that it's an insane amount of effort and resources to spend on, basically, blocking unwanted shouting. Obviously the long-term sustainable option is to just kill ads altogether.)
Which of course was the whole purpose for google pushing for this v3, to benefits ads and hurt users.
Also, are there any decent plugins that block all of google instead of just the ads? I imagine they’d need to MITM static font assets, etc.
I also wonder if / when this means Google will start fingerprinting and tracking tenants’ customers on GCP.
I already do this for local DNS circumvention, which is probably a lot more common than hardcoded IPs.
It’s definitely not perfect, but it does de job for now.
I couldn't believe what they were saying. Their words didn't make sense to me. I ended up in removing all adblock- and privacy-related settings in our router - it felt like a defeat.
Browsers use system calls to provide the information used for fingerprinting the device, so why not intercept these calls and lie. Have all users present an identical fingerprints and we're back to pre google times. Yes, we lose some important functionality, but maybe it's a price worth paying?
Never mind the other elephants in the room that do worse than track your browsing habits...
You would have to have some kind of launcher where you can select the isolated chroot/sandbox you want to run that specific program in.
Implementation-wise this could actually be done with eBPF, as most if not all syscalls can be intercepted and "farbled" (Brave's terminology) there. Features-wise this would probably be a separate filesystem for each program context, plus the things that firejail implements in userspace. Shared libraries would have to be loaded separately into memory, and glibc would have to be changed to not use any environment variables or debugging related function calls.
Welp, maybe docker+xorg is easier.
I've been wondering how hard it would be to make a completely fingerprint-proof browser.
One idea would be to run it in a deterministic emulator. All machine code instructions would be guaranteed to take exactly the same amount of time to execute on every machine, as far as is observable to the browser, and threads would be scheduled in the same order every time. Zero access to the host system through fonts, WebGL etc.
This would mean a massive performance penalty, but modern computers are fast enough that it might be usable for many sites. You could have a small number of discrete speed tiers, where you use the fastest tier that your computer is capable of.
If there was no tracking, anonymous content sensitive ads would be more popular and thus valuable.
Unfortunately even Mozilla is now trying to appease advertisers with their PPA initiative. I don't want purchases to be attributed.
I will continue blocking all ads forever and circumventing them in other ways possible (like pirating content and using paywall blockers). I'm done trying to fix the system.
How convenient.
Then again, my workplace is using Google. Is there any relatively easy way of routing Google traffic via an intermediary, say a vps?