Detecting Noise in Canvas Fingerprinting
blog.castle.io
blog.castle.io
> Can I work for a bad company and still be a good person?
> No.
I counter it with my own- Yes.
By what standard are bad companies or good people measured? Do you define that? Religion? The current popular opinion?
There's literally an entire branch of study that tries to formalize it so it's not just "It's literally, like, my opinion, man".
> Most
That's quite a leap you made there.
No, I wouldn't say a majority are. But a significant proportion are. That's what I said. Moral relativism is a mainstream philosophical position. It's not some crazy fringe view or something.
"mugging" =/= stealing
Mugging: 1939 as "a violent physical robbery;"
Stealing: Old Frisian stela "to steal, rob one of,"
tracing it back to proto-Indo-European still has "rob" in the etymology for "steal". I am using EO because i don't want to go to my bookshelf right now.
you can "steal" an apple from a store and that's not a "robbery" but if you mug someone and rob them it's still "theft", they were still "stolen from".
In a thread about universal truths (or not) this is amusing.
Arguing against a weak interpretation of someone’s argument is arguing in bad faith when a stronger interpretation is plausible. It is in the guidelines:
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.
2. The original claim is "There are universal truths". Substituting that for "There are universal truths in every circumstance" isn't "strongest plausible interpretation", it's changing the argument entirely and attacking a strawman. It's like claiming "a^2 + b^2 = c^2 holds for right angle triangles", someone else objecting "yeah but it doesn't hold for all triangles", and then invoking "strongest plausible interpretation of what someone says" when he's called out for changing the claim.
Someone who uses threat of violence (real or otherwise), to steal from people.
>Does someone who has ever committed a mugging carry that label with them for the rest of their life?
Easily sidestepped by claiming that they're bad people in the moment, or for that action. You can still call an law-abiding citizen that volunteers in his community and donates to charity a "bad person", if one day he goes rogue and punches someone in a fit of range, for instance.
> If the mugging was committed on a serial killer, is it still morally indefensible in your view?
Yes, because such actions are extrajudicial (how do you know the victim was actually a serial killer?), and sets a dangerous precedent (how soon until people are mugging each other for being Trump/Kamala supporters?).
Sure, but is that universally true? Would someone be necessarily wrong if they still said that the puncher is not a bad person and was not a bad person in that moment?
I know i have "no right" to archive content, but it comes in handy.
Google? Amazon? Facebook? Tinder? Yes.
Boeing? Lockheed Martin? No.
Tesla? Pfizer? Unknown.
You're welcome.
To play the devil's advocate: Google has vastly improved access to information. Facebook has allowed hundreds of millions of people to remain in each other's lives even while separated by oceans. Amazon made it much easier to acquire very specific items. Tinder has helped people find love.
Well researchers employed by Google are where transformers were presented which is how all modern AI companies build their models. I'd categorize generative AI as generally interesting things. Or a massively useful search platform, they solved email (until they stopped really paying attention to it). They also promulgated Android which has a lot of fans. And that's just the very visible stuff you'll see as someone not in the field. They've also contributed to storage & distributed systems research in very tangible ways. Or the research they've been doing into protein folding with AI via AlphaFold.
Amazon pioneered modern cloud computing in such a way that they were the only game in town for a long time before Google and Microsoft attempted to compete.
But sure, it sounds like your bias is against any company that's a "virtual" company and for companies that produce "real" things. However, you may want to ask yourself whether those companies would be able to build those "real" things as efficiently without all the virtual technology supporting them & letting them offload that complexity.
In my eyes, advances in FEM simulation is what you can really argue for when talking about "support for builders of meatspace things".
And yes, cloud is definitely towards the future I want where I can easily spin up infrastructure to enable some project rather than having to figure out reliable hosting for myself from scratch every time. Cloudflare Workers are actually closer to what I want than the vision AWS and Google enable but it’s not as full featured yet and it wouldn’t exist without AWS creating the market in the first place. Of course there are issues around privacy of data and trusted compute that aren’t solved yet vs local, but the cost savings and simplicity va having to manage hardware (which I’ve also done ) are real.
Note the fingerprint isn't unique, it's basically a property of your graphics hardware + operating system. If you have a M4 macbook pro, in all likelihood you'll have the same fingerprint as all the other M4 macbook pro users.
>I know you can disable canvas in firefox, how does one do it in Chrome
Bad news. Disabling features is also a fingerprint vector, and having it disabled probably makes you more suspicious. Imagine you're at a border checkpoint that fingerprints you (many countries do that), and your fingerprints were burned off. How do you think the border guard will react?
er... maybe if they're using metamask or something with the viewport pixel WxH set arbitrarily. canvas size/window size, fonts installed (are you a graphic designer or typographer?), who knows what else. the EFF has a site that shows you all the nonsense we can be tracked with.
open safari on a second monitor? at the same time? probably globally unique WxH between the two windows.
I was talking about canvas specifically, since the OP mentioned "js with canvas enabled". The rest can be somewhat mitigated by avoiding configurations that stick out, eg. using a "common" window size (ie. maximized). On firefox you can also use RFP with letterboxing, which rounds windows dimensions to the nearest 100 pixels, and defaults to 1000x1000. However, that's also somewhat suspicious (who perfectly sets their window to multiples of 100?) that you're better off using maximized window + common display resolution + standard taskbar/dock size. RFP also has mitigations for some of the other issues you mentioned, eg. a font whitelist.
I'm just saying it's not as easy as all of that, even on a "computer" using the stock browser.
you'd also have to figure out where most users are in the timezone data as that narrowed my browser down to 95% unique all on its own. (UTC-5)
>you'd also have to figure out where most users are in the timezone data as that narrowed my browser down to 95% unique all on its own.
The best timezone to use is the one that corresponds to your IP info, because it doesn't reveal anything about you. You'd expect 95+% of users with a Californian geo ip to be on pacific time, for instance. Using anything else makes you stick out like a sore thumb.
Statistics like "95% unique" also make little sense. Being able to identify you as one out of 400 million people (5% * world population) seems... fine? You can get better targeting through geoip/latency measurements, for instance. If you use a VPN in California, that narrows you down to 1 in 39 million people.
i understand what you're saying, of course.
i'm unique in their dataset on firefox on a 2k monitor.
looks like my main culprits: useragent, timezone (lol), navigator properties (99.9% unique,) fonts, canvas (100% unique,) screen dimensions (available and .. actual?). all of these showed >99% unique.
In the EU it's not without explicit consent outside of a few, clearly defined cases.
Of course compliance is not 100%.
Browsers should do their best to make fingerprinting a non-viable approach.
One of the few good ideas Google proposed is Privacy Budget [1], which now appears to be abandoned. In short the browser estimates how much information each risky API call discloses, and blocks further calls if the sum exceeds some threshold
[1] https://developers.google.com/privacy-sandbox/protections/pr...
delete CanvasRenderingContext2D.prototype.toDataURL;
Shouldn’t delete set the function back to native code?
Same with:
const offscreen = new OffscreenCanvas(1, 1); const nativeToDataURL = Object.getPrototypeOf(offscreen.getContext("2d")).toDataURL;
Object.defineProperty(CanvasRenderingContext2D.prototype, "toDataURL", { value: nativeToDataURL, writable: true, configurable: true });
Or:
const iframe = document.createElement("iframe"); document.body.appendChild(iframe); const nativeToDataURL = iframe.contentWindow.CanvasRenderingContext2D.prototype.toDataURL; document.body.removeChild(iframe);
CanvasRenderingContext2D.prototype.toDataURL = nativeToDataURL;
I beg your pardon if my question is full of innocence.
Sure, Jan. Whatever lets you sleep at night.