So that part seems to work, I was just confused because the effect on overall uniqueness is very low. Still I applaud the efforts by the WebKit Team.
651 karma · joined April 15, 2019
So that part seems to work, I was just confused because the effect on overall uniqueness is very low. Still I applaud the efforts by the WebKit Team.
Here's a quote: "There will also be new security measures to prevent digital fingerprinting, or the use of things like installed fonts and plug-ins to help track users across the internet even with privacy settings active. Websites will be given a stripped down, simplified system configuration so every user's Mac looks like every other user's Mac."
Especially as it isn't as simple as a standardized list of fonts when the Canvas hash is 100% unique for everyone.
Still very disappointing.
Nevertheless, what needs to happen is that all major browser makers come together and simply create a set of standard API values that do not harm daily browsing and make it possible for users to blend in with the masses, if they opt-in to activate
It would be sufficient to create a couple of uniform user agents, list of fonts, list of plugins, canvas hash, platform and webgl data to bring the uniqueness down.
https://addons.mozilla.org/en-us/firefox/addon/adblock-plus/...
As long as environmentalists only complain about the bad things, instead of actually building from a positive vision, nothing will happen.
For example, why is Greenpeace et al. suppressing the knowledge from Allan Savory?
Desertification in those areas is increasing, especially North Africa, and Central Asia.
The focus of environmentalists on the Rainforest is not productive. Solutions need to be future-oriented, and not directed towards restricting economic growth.
In other words, it is of primary importance for enivornmental organizations to create a positive vision of a greened planet, with a systematic forestation program for Africa and Central Asia, to create a prosperous environment and give Africans and Asians a future.
This vision is central to the https://en.wikipedia.org/wiki/Global_Marshall_Plan as well as https://en.wikipedia.org/wiki/Holistic_management_(agricultu...
Meanwhile, let Brazil have their wealth and prosperity with cutting a couple of their trees, they have too many anyway.
Except, it is not, because the data profiles still exist.
In that way, Google could advertize itself as being anonymous, as they probably delete IP addresses relatively quickly as well.
Even though affiliate links are a low hanging fruit in regards to making money with search engines, it is not made transparent by DuckDuckGo.
They also use all the data they can get, they just tell us they get rid of the identifying information as fast as possible (IP address). I wouldn't be surprised if, from a privacy-standpoint, using Google and DDG as a non-logged in user is basically the same, especially if you use google with an ad blocker. The process of Google ads is basically to have a profile based on cookie data, which the user can easily control.
But where is the evidence that malware has ever switched off safebrowsing for example?
Your entire premise of extension signing and AMO store moderation rests on the premise that this is actually helpful for keeping extensions safe, but then you say nothing is safe.
There is only one gateway for malware to change the about:config settings in the first place, and that is through your signed extension process.
How safe should things be?
Edit: Maybe you could allow disabling the signing process via enterprise policies under the condition that the about:config settings are locked, which in my understanding would make it basically impossible for extensions to change anything. Would that help make it more secure?
Basically, the management set their own salaries, the entire work force gets a 40% yearly bonus, and they have no one from the outside to report to.
On top of all of this, the money flows regardless of what anyone is doing. (While there is a yearly loss of 10% of their users, the past deal with Verizon made them very rich, so they can go like this for years). Revenue has been only going up, despite a loss of absolute users. So this explains why they continue to do bad things even though outside observes can not understand - during the last 5 years losing users did not impact their financials in any meaningful way. While people were complaining and users leaving the product, revenue was increasing.
They do take care of their employees with lots of benefits and other stuff, so as an employee you don't want to risk all that with speaking up against your superior.
Over the years they have created a company culture where there are endless number of small teams doing irrelevant stuff, with absurd hierarchies, with some people doing no work at all. With 16 people in the upper management, there's also fragmentetion of decision making going on. It's all a bit headless.
Due to the complicated hierarchies in the company everyone is content with doing just enough to not make life harder for anyone else - suggest to change things fundamentally and actually work on delivering a great product and you will not get very far.
If an extension turns out to be malicious, you simply deactivate it in the store, and then proactively deactivate the existing installs. This is how Chrome is doing it.
But having a certificate does offer Mozilla the feeling of absolute control, which seems to be of primary importance for them nowadays.
This is probably the reason release and beta users are not even allowed to deactivate signing in the about:config settings.
The downside is that the process of updating the software becomes a bit fragmented, which is probably confusing users now.
The disabling happened right after the announcement by Mozilla to implement a new policy towards extensions.
Maybe someone didn't realize their mistake, so now everyone thinks it was an old certificate.
What you experience is a synced remote interface, you don't own your software anymore.
Granted, the secret lies in providing such an excellent and subtle service that the majority of users actually either endorse or not even notice the dependency.
Which means changes should be subtle and consistent.