If you're doing fingerprinting for tracking purposes, you're gonna be tracking a lot more in-depth data.
But in the end, there are pretty much three types of Internet user today: 1. The person who uses the default browser installed on their device. 2. The user who always downloads Chrome when they first get a new computer. and 3. Nerds who do something else.
I don't remember the discrepancy that the study found, but it's significant.
So… we keep optimising for Chrome, as if that's the bulk of our audience. That makes things shittier for everybody else, and we think it's okay because they're such a small part of the group. This reminds me of a former client burning almost 9 million euros every year because they excluded IE6–8 from their reporting, yet they would account for 15% of the traffic.
I'd rather be trackable but secure -- the big draw for me is NoScript. Paired with uBlock, I'm safe from malvertising[1]
[1] https://en.wikipedia.org/wiki/Malvertising#Examples_of_malic...
Only things uBlock doesn’t replicate:
NoScript’s anti-XSS and anti-clickjacking heuristics (uBlock just blocks the sources, not sanitize payloads).
NoScript’s control over other active content types (e.g., WebGL, media codecs, etc).
What data do you have to support this assertion? uBlock doesn't seem to have the ability to selectively enable only JS nessecary for functionality, and if it does, the UI makes it much more difficult to enable.
I just ran a test -- merely uBlock use renders me unique, whereas one in 5742.77 had the same fingerprint as me when using NoScript. (I suspect that's the number of people also using Firefox with NoScript who own this particular monitor size)
A big chunk of the fingerprinting techniques require JS -- it's pretty hard to ascertain what specific extensions are installed with it. I tested disabling it and it didn't seem to do much difference in terms of bits of entropy on EFF's tool.
I encourage you to try for yourself and then think hard on your advice.
I'm going to assume you meant to say "I have not".
If you can't judge the validity, maybe you shouldn't give out advice that might be read by vulnerable populations, given the sources you list do not address my points.
I can get feedback with access, I can't get feedback with tracking. That's why I mentioned access.
By contrast, tracking people on the web is a multibillion dollar industry, and there are out of the box commercial libraries that do very sophisticated tracking. None of these solutions rely on user agent string alone.
The vast majority of websites by count are not doing anything sophisticated. But some are.
> By contrast, tracking people on the web is a multibillion dollar industry
Of which Netflix is a part of. > The vast majority of websites by count are not doing anything sophisticated. But some are.
And this is my point. Somewhere like fingerprint.com is trying to use all the tools available. But most places aren't. Facebook and Google? Sure, I buy that. But mentioning that many places are lazy is not the same thing. It is a game where we can't win completely and we still need to let people know that small gains are still meaningful. A major problem we face with privacy is that people feel so powerless that it is useless to fight back. But that's not true. Just because your bulletproof vest doesn't stop a missile doesn't make it useful. A bulletproof vest that only stops small caliber is still better than no vest, since most shots are small caliber. Pareto is still alive and well here.But ultimately, Netflix is just trying to check a box in their contractual obligations, and/or prevent high-schoolers with chrome dev tools from sending movies to all their friends. They're not really interested in spending large sums of money to figure out your browsing history. It's just not relevant to their revenue stream.
>> tracking people on the web is a multibillion dollar industry
> Of which Netflix is a part of.
I was referring to businesses that do web activity tracking as their primary business. Facebook and Google's primary business is advertising, which isn't the same thing, and they control enough products that they don't actually have to do very much fingerprinting in order to target ads effectively. Most of their data, people voluntarily hand over. I was getting more at the big ecosystem of commercial tools that others can implement that do these sorts of things. e.g fingerprint.com and many others.
If a website has 100 visitors, and 99 of them use Chrome, and 1 user uses Firefox, it doesn't matter how good their fingerprinting resistance is, they're always the one using Firefox.
Even if every Firefox browser gave off the exact same fingerprint, that wouldn't make the network traffic indistinguishable between Firefox users. There is a lot of entropy that is provided by your network stack of your device, the networks you connect to in order to get to the end website, the behavior of your requests, etc.
Now, most websites aren't doing this kind of analysis. But it isn't unheard of or impossible. There are major websites that are known to do TLS fingerprinting.
[0] https://radar.cloudflare.com/reports/browser-market-share-20...
However, if you're trying to search for somebody, and you're able to eliminate 96% of the data, you're in a much better position to accomplish your goal.
Whether or not you should care about this depends on what kind of tracking threats you're trying to avoid.