Achieving Great Privacy with Safari
matanabudy.com
matanabudy.com
That site then says:
I found that the uBlock Origin extension breaks the final result. To fix it, add adblock.turtlecute.org as an exception in uBlock rules.
Exactly the kind of belly laugh I needed right now. That side also falsely "measures" that my ad blocker lets all kinds of sites through when in fact my setup lets absolute zero third party sites through. Hilarious!
I wonder how many people fall for sites like that.
Each private browsing tab has its own cookie / data bucket[1]; and
Private browsing tabs and windows are preserved across restarts. (This is optional and can be configured to forget them upon restart.)
These make it practical to use private browsing for nearly all browsing, which isn't really the case in other browsers, where private browsing is clearly designed as an occasional-use thing. (And of course if you use private browsing for most things, you can still open regular windows for sites where you want to stay logged in.)
[1] If a link or script in a tab opens a new tab or window, then they share the same cookie bucket. This preserves compatibility with sites that require such a flow.
I am totally stumped – how do you enable this on the Mac? I can’t find the option at all, and Google is no help.
google relations with Firefox always prevented this.
they explained to users that having 4 containers was good enough and screwed up every step of the ui implementation.
https://support.mozilla.org/en-US/kb/introducing-total-cooki...
Containers are no longer necessary unless you're logging into the same site with multiple accounts.
This distinction matters, if you primarily use private browsing, and have lots of tabs open from a site (say, Wikipedia, or Reddit, or pick a social networking service you don't want to track you by cookie[1]) - that particular website will know all the different tabs are from the same user potentially over a long stretch of time if at least one of those tabs remains open.
[1] Ad networks also track by IP address, so you need to take measures there too.
That being said I was a lifelong Windows user up until 5-6 years ago, and while everyone else in my family uses apple devices I was never interested in using one(since I like building my own PCs :p)
I had a look at Kagi official discord and Vlad (HN: @freediver) says they let the eff test run as non-malicious, i.e. other sites may not be able to see as much.
Correct.
FWIW (disclaimer: I'm the developer of StopTheMadness Pro, mentioned in the article) I just ran two tests in Mac Safari, with StopTheMadness Pro enabled and disabled, and the results were exactly the same each time: "at least 18.06 bits of identifying information". Alas, that's a unique fingerprint, but apparently my extension doesn't make anything worse. If you look at the detailed results, the identifiers are things like User-Agent, screen size, time zone, and language.
(also, thanks for StopTheMadness Pro!)
One relatively small complaint if you don’t mind me hijacking this thread. The update process could be a lot better! Especially on Firefox. I’m used to it now, so it’s become just a bit of an annoyance but the first few times were tense moments, and especially panic inducing a couple times when I was pressed for time and couldn’t use the browser before updating the extension.
In any case, it’s an awesome extension and I recommend it to others frequently!
I assume ad networks and analytics are the main ones actually fingerprinting based on client-side factors. I could be totally wrong.
Any reasonable adblocker that prevents requests to those services probably neuters 99% of any fingerprinting capability that anyone is going to encounter day to day.
Having a unique fingerprint is ideal, as long as it's unique every time. It's insane to think that you can successfully account for every data point that can be collected from a browser. Fingerprinting techniques are changed and new methods are being discovered even while browsers themselves keep adding new features that can be used (or abused) to identify people.
Rather than praying that you (and some fingerprinting website) are 100% aware of every single technique that's ever been used anywhere and that nothing new will be discovered giving trackers even just a single unique data point which is all they need to tell you apart from everyone else, it's a lot safer to appear to be someone new with every request.
As far as I know, you can't change this setting.
Technically, all script-writable storage.
> you can't change this setting.
Settings, Feature Flags, Disable Removal of Non-Cookie Data After 7 Days of No User Interaction
Edit: it resets that setting after Safari updates apparently.
If you set it in the global defaults, then Safari won't touch it.
adblock testing websites http://brave.com/blog/adblocker-testing-websites-harm-users/
fingerprinting test websites https://github.com/orgs/privacyguides/discussions/7#discussi...
Used useless extensions[1] for example "Privacy Badger"[2]
[1] https://github.com/arkenfox/user.js/wiki/4.1-Extensions
[2] https://github.com/arkenfox/user.js/wiki/4.1-Extensions#-don...
>Redundant with Total Cookie Protection (dFPI)
https://privacybadger.org/#Is-Privacy-Badger-compatible-with...
> I try to stay positive about my choices
> As someone deeply embedded in the Apple ecosystem
author clearly mentioned these and that is nice. But then that is what it is. This post is "how to do few of X things in Safari browser". There are no comparisons, none - nothing at all. Because something like privacy stands nowhere until we know what else is out there, how better you can be protected. Because I am pretty sure Internet Explorer (current name is Edge, right?) must have been saying from the day 1 "we take your privacy very seriously", just like good old Zuck's toys say.
But then the author happily turns to the browser wars (something they explicitly said they are not into; repeatedly) and brings Firefox in the conversation. "For fun" of course :)
But still all good. Eventually it boils to that and author kinda says it - they just want to be happy about their setup and that is all. That is what this blog post is - a "so called" happiness post. That is nice. Very nice.
PS. And god, Hush never works. At least it doesn't work for me :D
Recently Mozilla integrated their VPN service directly into the browser too and it is Container aware.
https://support.mozilla.org/en-US/kb/protect-your-container-...
Edit: see jshier’s response.
https://support.apple.com/en-ca/guide/iphone/iphd27a9ff22/io...
Tested on Chrome for Android and Firefox with (and without) ublock Origin.
The only thing you can do is minimize and standardize the amount of identifiable characteristics shared like the tor browser does.