You are viewing a single thread.
View all comments
74 points
*

This has been the case for years. I develop fingerprinting services so AMA but it’s basically a long lost battle and browser are beyond the point of saving without a major resolution taking place.

The only way to resist effective fingerprint is to disable Javascript in its entirity and use a shared connection pool like wireguard VPN or TOR. Period. Nothing else works.

permalink
report
reply
17 points

How can you live with yourself?

permalink
report
parent
reply
22 points

I do it as a security measure for private institutions and everyone involved has signed contracts. It’s not on the public web.

permalink
report
parent
reply
6 points

I know right. I was offered a job at a betting site and online casino with those addictive games and shit. Gave that a hard pass, said no thanks, don’t think that’s the right business area for me. I would feel so dirty going to and coming from work every damn day.

permalink
report
parent
reply
15 points
*

Hello grease monkey and no script, my old friends

permalink
report
parent
reply
6 points

What are some good scripts for grease monkey?

permalink
report
parent
reply
5 points

Wouldn’t selective disabling of JavaScript make fingerprinting easier? Your block and white list are likely to be unique.

permalink
report
parent
reply
1 point

Tracking scripts are usually separate from the scripts that do stuff. But also giving them less info is always just better.

permalink
report
parent
reply
10 points

Disabling JavaScript entirely is another data point for fingerprinting. Only a tiny fraction of users do it.

Besides, without JavaScript most websites are not functional anymore. Those that are are likely not tracking you much in the first place.

permalink
report
parent
reply
6 points

Yeah unfortunately disabling JS is not viable option tho onion websites are perfectly functional without JS and it just shows how unnecessarily JS had been expanded without regard for safety but theres no stopping the web.

permalink
report
parent
reply
3 points

I disable JS with noscript.net and it really is an enormous pain. It has some security advantages, like I don’t get ambushed so easily by an unfamiliar site and pop ups. I often will just skip a site if it seems too needy

permalink
report
parent
reply
7 points

This is what I’ve been saying for months in the reddit privacy sub and to people IRL. Some people seem perfectly happy to just block ads so they don’t see the tracking. Literal ignorance is bliss. Most simply don’t have time or wherewithal to do the minimal work it takes to enjoy relative “privacy” online.

FWIW, any VPN where you can switch locations should do the job since the exit node IPs ought to get re-used. My practice is to give BigG a vanilla treat because my spouse hasn’t DeGoogled, and leave anything attached to our real names with location A. Then a whole second non-IRL-name set of accounts usually with location B with NoScript and Chameleon. Then anything else locations C, D, E, etc.

Ugh… This all sucks.

permalink
report
parent
reply
5 points

What are you people trying to hide ??? /s

permalink
report
parent
reply
3 points

So… how effective is it? The fingerprinting. I’m guessing there are studies? Also don’t know whether there’s been legal precedent, ie whether fingerprinting has been recognized as valid means of user identification in a court case.

permalink
report
parent
reply
4 points
*

It’s super effective but there are very few real use cases for it outside of security and ad tracking. For example you can’t replace cookies with it because while good fingerprint is unique it can still be fragile (browser update etc.) which would cause data loss and require reauth.

Usually fingerprint plays a supporting role for example when you do those “click here” captchas that’s actually just giving the browser time to fingerprint you and evaluate your trust to decide whether to give you a full captcha or let you through. So fingerprint is always there in tbe background these days tho mostly for security and ad tracking.

As for court cases and things like GDPR - the officials are still sleeping on this and obviously nobody wants to talk about it because it’s super complex and really effective and effects soo many systems that are not ad tech.

permalink
report
parent
reply
2 points

Usually fingerprint plays a supporting role for example when you do those “click here” captchas that’s actually just giving the browser time to fingerprint you and evaluate your trust to decide whether to give you a full captcha or let you through. So fingerprint is always there in tbe background these days tho mostly for security and ad tracking.

I’ve been wondering about those “click here” captchas and their purpose 🤔

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 8.9K

    Posts

  • 228K

    Comments