Maybe it's forgotten. Maybe it lies. Maybe every time I rev Firefox Nightly I change identity.
What is true is that every time I leave an email address, it's tagged with the name of the site where I left it.
Maybe it's forgotten. Maybe it lies. Maybe every time I rev Firefox Nightly I change identity.
What is true is that every time I leave an email address, it's tagged with the name of the site where I left it.
But note that a constantly changing fingerprint doesn't make it useless for tracking - if a site can keep any kind of cookie to persist between browser updates, it could add the updated signature. Then when you purge cookies and persistent storage, a site can re-add the cookie to keep on identifying you if your signature hasn't changed.
You'd have to purge all persistant storage at the same time as an update to avoid this, and even then (or if you never had persistent data to begin with) your IP or even geographical location will likely be enough to identify you again.
I use Google Apps (possibly not a good idea but soo convenient :/) with a catchall. I didn't catch any offender so far...
However (off topic), spammers are spoofing addresses as if they were coming from my domain. I receive two to three dozens automatic replies from mail servers (this address does not exist...).
I've properly set up DKIM and SPF records, making it obvious that these mails are spoofed, but I'm afraid my domain will end up on grey/black lists... Anyone out here familiar with this kind of issue?
Obviously you can never give out the "something@example.com" address and then assume that everything that goes to that address must be spam, but I've had legitimate contact from companies who have had to email me by removing the + portion because their internal email system wouldn't allow addresses with a + in them.
If you do go this route, I'd recommend using a whitelisting approach. I do get a lot of spam sent to random addresses at my domain.
^[a-z0-9_.]+@(?:[a-z0-9-]+\.)+\.[a-z0-9]+$https://en.wikipedia.org/wiki/Email_address#Valid_email_addr...
Unless the nightlies have a different behavior than the releases, the patch level is not reported anymore. The changes went into 16.0.2 which was released on 10/26/2012. initial report on b.m.o[1] reads as follows:
Steps to reproduce:
1) Load http://www.delorie.com:81/some/url.txt
Actual results:
The User-Agent header exposes the security patch level as either a minor version
number or as an alpha/beta/pre indicator. This data is exposed twice: in the
Gecko version and in the application version.
While it is of value to expose this data to e.g. AMO, exposing it to all sites
makes the browser more fingerprintable (see https://panopticlick.eff.org/ ) and
doesn't serve a purpose more important than user privacy. Point releases don't
change functionality beyond security and stability fixes, so sites shouldn't be
sniffing the patch level anyway.
Making trunk, alpha and beta builds look like release builds for sniffing
purposes reduces sniffing-related failures that waste time when treated as
functionality-related regressions by mistake.
Expected results:
Expected the version numbers to show the major version of the most recent
Firefox beta that Mozilla has shipped and not to show the security patch level
or an alpha/beta/pre indicator.
Additional information:
Internet Explorer doesn't expose the security patch level in its UA string."
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=728831"Within our dataset of several million visitors, only one in 857,908 browsers have the same fingerprint as yours."
As it doesn't allow for plugins, my fingerprint should (cookies aside) match that of any other <popular device> user.
So maybe the solution here is coming up with a 'secure browse' profile that every browser reports the same fake fingerprint.
Security in numbers.
There already is: https://www.torproject.org/projects/torbrowser.html.en
This also has the advantage that no other solution has: it completely hides your location as well, whereas even with a "standard" browser, your IP address + time zone alone can do a lot to identify you.
Just mentioning this lest anyone get the wrong idea that setting your browser to update frequently might be a defense.
Indeed; the user agent is part of the fingerprint.