HNHacker News
TopNewBestAskShowJobs

user17843

651 karma · joined April 15, 2019

submissionscomments
user17843··on Browser Fingerprinting: A Survey
I have to withdraw my original statement, Looks like I have the same set of fonts as you.

So that part seems to work, I was just confused because the effect on overall uniqueness is very low. Still I applaud the efforts by the WebKit Team.

user17843··on Browser Fingerprinting: A Survey
the test shows unique system fonts for me.

Here's a quote: "There will also be new security measures to prevent digital fingerprinting, or the use of things like installed fonts and plug-ins to help track users across the internet even with privacy settings active. Websites will be given a stripped down, simplified system configuration so every user's Mac looks like every other user's Mac."

user17843··on Browser Fingerprinting: A Survey
why do the studies referenced in the above study only show a very low <1% prevalence? Do they omitt the "good fingerprinters"?
user17843··on Browser Fingerprinting: A Survey
the marketing department probably decided that it needs to be done and the safari engineers realized this would completely destroy usability for a majority of users, so they quietly abandoned it.

Especially as it isn't as simple as a standardized list of fonts when the Canvas hash is 100% unique for everyone.

Still very disappointing.

user17843··on Browser Fingerprinting: A Survey
it hasn't, it was PR. look up amiunique.org or panopticlick.eff.org with Safari.
user17843··on Browser Fingerprinting: A Survey
It looks like the prevalence is low and it can easily be blocked with blocking the scripts in question.

Nevertheless, what needs to happen is that all major browser makers come together and simply create a set of standard API values that do not harm daily browsing and make it possible for users to blend in with the masses, if they opt-in to activate

It would be sufficient to create a couple of uniform user agents, list of fonts, list of plugins, canvas hash, platform and webgl data to bring the uniqueness down.

user17843··on Firefox 66.0.4 is out, fixes disabled add-ons
I doubt this. There are extension update pings, and my guess is that the number of users is deducted from the update pings, but I could be wrong.
user17843··on Map Shows Millions of Acres of Lost Amazon Rainforest
hmm ok, he says everyone ignores him and he gets no money from any NG0, and that his system could regreen the entire planet.
user17843··on Firefox 66.0.4 is out, fixes disabled add-ons
It will be possible to roughly deduct this from the following statistics during the next days/weeks:

https://addons.mozilla.org/en-us/firefox/addon/adblock-plus/...

https://data.firefox.com

user17843··on Map Shows Millions of Acres of Lost Amazon Rainforest
Some comments are just tongue-in-cheek.

As long as environmentalists only complain about the bad things, instead of actually building from a positive vision, nothing will happen.

For example, why is Greenpeace et al. suppressing the knowledge from Allan Savory?

user17843··on Map Shows Millions of Acres of Lost Amazon Rainforest
There are many deserted regions around the world.

Desertification in those areas is increasing, especially North Africa, and Central Asia.

The focus of environmentalists on the Rainforest is not productive. Solutions need to be future-oriented, and not directed towards restricting economic growth.

In other words, it is of primary importance for enivornmental organizations to create a positive vision of a greened planet, with a systematic forestation program for Africa and Central Asia, to create a prosperous environment and give Africans and Asians a future.

This vision is central to the https://en.wikipedia.org/wiki/Global_Marshall_Plan as well as https://en.wikipedia.org/wiki/Holistic_management_(agricultu...

Meanwhile, let Brazil have their wealth and prosperity with cutting a couple of their trees, they have too many anyway.

user17843··on DuckDuckGo Proposes the “Do-Not-Track Act of 2019”
and they have a nice lite search: https://lite.qwant.com/
user17843··on DuckDuckGo Proposes the “Do-Not-Track Act of 2019”
I have split up my browsing and search among multiple browsers, depending on the use case, and I use Bing, Google, DuckDuckGo and Startpage, mostly for having different perspectives as I found out that only using google limited the stuff I found. (Google serves Startpages different results than what they show themselves)
user17843··on DuckDuckGo Proposes the “Do-Not-Track Act of 2019”
It was a cynical way of critizing that they collect so-called anonymized usage data, for example for people who really need something anonymous they could start offering a gateway to a search that doesn't collect anything at all.

https://help.duckduckgo.com/privacy/atb/?redir=1

user17843··on DuckDuckGo Proposes the “Do-Not-Track Act of 2019”
I rather want to see the "Duck-Not-Track Act", as DDG has a complete "data survaillance" system built into their product.
user17843··on DuckDuckGo Proposes the “Do-Not-Track Act of 2019”
Funny enough, everything is anonymous on paper when you take away the IP address.

Except, it is not, because the data profiles still exist.

In that way, Google could advertize itself as being anonymous, as they probably delete IP addresses relatively quickly as well.

user17843··on DuckDuckGo Proposes the “Do-Not-Track Act of 2019”
Indeed, no one talks about the privacy implications of referral links, although when it comes to the agreement with Bing, etc., I think everything is proxied. Not so much with the direct links to Amazon. Amazon knows when you are a DDG user.

Even though affiliate links are a low hanging fruit in regards to making money with search engines, it is not made transparent by DuckDuckGo.

They also use all the data they can get, they just tell us they get rid of the identifying information as fast as possible (IP address). I wouldn't be surprised if, from a privacy-standpoint, using Google and DDG as a non-logged in user is basically the same, especially if you use google with an ad blocker. The process of Google ads is basically to have a profile based on cookie data, which the user can easily control.

user17843··on Update Regarding Add-Ons in Firefox
Thanks for the explanation. Can you provide me with a link to learn more about how google manages extension certs? I am interested in learning how their system differs from Firefox, if at all.
user17843··on Update Regarding Add-Ons in Firefox
Imho, making it available via about:config switch would be entirely sufficient. There are dozens of settings that already affect security, like ssl handling, safe browsing, firstparty isolation, and tracking protection.

But where is the evidence that malware has ever switched off safebrowsing for example?

Your entire premise of extension signing and AMO store moderation rests on the premise that this is actually helpful for keeping extensions safe, but then you say nothing is safe.

There is only one gateway for malware to change the about:config settings in the first place, and that is through your signed extension process.

How safe should things be?

Edit: Maybe you could allow disabling the signing process via enterprise policies under the condition that the about:config settings are locked, which in my understanding would make it basically impossible for extensions to change anything. Would that help make it more secure?

user17843··on Update Regarding Add-Ons in Firefox
I doubt google has certificates that run out automatically. Rather, the best way is with each signing to include signing the date and not allow the certificate to expire retroactively.
user17843··on Update Regarding Add-Ons in Firefox
some things I wrote I can not prove, that is right. I would love to revise my negative opinion in light of better evidence.
user17843··on Update Regarding Add-Ons in Firefox
nowadays they seem to make it a hobby to make negative headlines at least once every quarter. I fear there will be no negative repercussions for the leadership.

Basically, the management set their own salaries, the entire work force gets a 40% yearly bonus, and they have no one from the outside to report to.

On top of all of this, the money flows regardless of what anyone is doing. (While there is a yearly loss of 10% of their users, the past deal with Verizon made them very rich, so they can go like this for years). Revenue has been only going up, despite a loss of absolute users. So this explains why they continue to do bad things even though outside observes can not understand - during the last 5 years losing users did not impact their financials in any meaningful way. While people were complaining and users leaving the product, revenue was increasing.

They do take care of their employees with lots of benefits and other stuff, so as an employee you don't want to risk all that with speaking up against your superior.

Over the years they have created a company culture where there are endless number of small teams doing irrelevant stuff, with absurd hierarchies, with some people doing no work at all. With 16 people in the upper management, there's also fragmentetion of decision making going on. It's all a bit headless.

Due to the complicated hierarchies in the company everyone is content with doing just enough to not make life harder for anyone else - suggest to change things fundamentally and actually work on delivering a great product and you will not get very far.

user17843··on Update Regarding Add-Ons in Firefox
You are right. It doesn't make any sense to use certificates for this kind of stuff.

If an extension turns out to be malicious, you simply deactivate it in the store, and then proactively deactivate the existing installs. This is how Chrome is doing it.

But having a certificate does offer Mozilla the feeling of absolute control, which seems to be of primary importance for them nowadays.

This is probably the reason release and beta users are not even allowed to deactivate signing in the about:config settings.

user17843··on Firefox/Normandy/PreferenceRollout
it's one step closer and more direct control, which is why this is now being used to deliver the quick fix.

The downside is that the process of updating the software becomes a bit fragmented, which is probably confusing users now.

user17843··on All extensions disabled due to expiration of intermediate signing cert
Is it possible that this wasn't an expired certificate but someone accidentally changed the signing process?

The disabling happened right after the announcement by Mozilla to implement a new policy towards extensions.

Maybe someone didn't realize their mistake, so now everyone thinks it was an old certificate.

user17843··on Firefox/Normandy/PreferenceRollout
modern software (especially browsers) with auto-update = SAAS.

What you experience is a synced remote interface, you don't own your software anymore.

Granted, the secret lies in providing such an excellent and subtle service that the majority of users actually either endorse or not even notice the dependency.

Which means changes should be subtle and consistent.

user17843··on Firefox/Normandy/PreferenceRollout
This partial fix via Normandy means a relevant part of the user base may still be in the dark: tech-savvy power users with many extensions who have chosen to disable normandy. (This is probably also the group which is most affected by reset extension settings)
user17843··on All extensions disabled due to expiration of intermediate signing cert
Thanks! Do you know how many active users were affected by this certificate error and subsequent addon disabling? I guess most users were spared due to the timing and short duration of the error.
user17843··on Google Will Soon Let Users Automatically Scrub Location and Web History
Do you think my interpretation of Google not having long-term user-profiles of non-logged in users due to GDPR is correct? I read that Google has rolled out their GDPR compliance worldwide.
user17843··on All extensions disabled due to expiration of intermediate signing cert
Thank you for speaking out here! I hope that mozilla employees manage to free themselves from their leadership and change the organization from within. It's possible, even though most employees who could change something have decided to simply leave over the years. Maybe mozilla needs a stark revenue drop to get humble again?
← PreviousPage 4 of 5Next →