@FireFoxDudes You need to be addressing fingerprinting
@FireFoxDudes You need to be addressing fingerprinting
It can be mitigated, a bit, but I don't see how browsers can win that battle.
Finger printing is a lost battle in my opinion, unless we drastically reduce what a web engine can do (like Tor does).
There's the kind that tries to find out what browser vendor, OS, and sometimes hardware you use, and the kind that tries to identify you across visits, unrelated origins etc.
I agree that the former is probably inherently impossible to avoid to a large extent, but the latter is both a bigger privacy issue and at least in theory possible to prevent.
The former is traditional analytics and is not enough to uniquely identify an individual.
Not all analytics are as privacy invasive as fingerprinting.
shockingly little information is required to uniquely identify someone.
"traditional analytics" (lets just say os + browser + some hardware info) is likely to be uniquely identifying when combined with just one other sparse dataset.
>Not all analytics are as privacy invasive as fingerprinting.
fingerprinting isn't a separate category of analytics. every data point can be (and often is) used for fingerprinting.
A colleague of mine made a recent post here: https://ritter.vg/blog-webaudio_alibaba.html
we know from the boy who cried wolf that too many warnings quickly turns into legitimate warnings being ignored
~every piece of data can be used for fingerprinting. settings and preferences, browser, os, etc. fingerprinting is not its own category of data, it's the correlation of regular data.
the "pressure" ends up being: stop receiving any data at all (which would obviously break ~everything), or put up a warning (leading to fatigue).
consider accessibility settings: absolutely required for some people to browse the internet, but also extremely high-value data for fingerprinting a user.
there is no technical method to know whether a site asking about a visitor's accessibility settings is doing it so that they can properly display content or so that they can fingerprint the visitor. (i.e. there is no "evil bit")
There's always been one, but it's been defaulting to 1 ever since the Web 2.0 upgrade, and the API to set it back to 0 has been deprecated.