this post was submitted on 23 Apr 2024
279 points (98.6% liked)

Privacy

31818 readers
222 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

It was at the Securedrop website. How did I end up there ? I read something about Sequoia and encryption and then wanted to see what Securedrop entailed.

Meanwhile I've raised the security settings. Still, today someone in this community (?) mentioned that Tor browser does not protect the remote to check for the OS, and now this. Color me surprised.

you are viewing a single comment's thread
view the rest of the comments
[–] brbposting@sh.itjust.works 28 points 6 months ago (3 children)

Wow nice. Any opinions on how these fingerprinting evaluators compare?

CreepJS:
https://abrahamjuliot.github.io/creepjs

EFF’s Cover Your Tracks:
https://coveryourtracks.eff.org

Am I Unique?:
https://amiunique.org

Sad a pretty stock iPhone that’s blocking via some filterlists and using iCloud Private Relay (a “VPN”) is so detectable! Should be so many browsers appearing similar but there’s always this & that that mean I’m unique.

[–] delirious_owl@discuss.online 8 points 6 months ago

They renamed panopticlick to cover your tracks? It was such a good name!

[–] ExcessShiv@lemmy.dbzer0.com 6 points 6 months ago* (last edited 6 months ago) (1 children)

Just tried amiunique.org and got this...

"Yes! You are unique among the 2561164 fingerprints in our entire dataset."

So much for using VPN and "hardened" Mull browser 😅

[–] brbposting@sh.itjust.works 1 points 6 months ago (1 children)
[–] ExcessShiv@lemmy.dbzer0.com 3 points 6 months ago* (last edited 6 months ago)

It really makes it feel like we're all just wasting time here on a futile effort trying to get digital privacy. Clearly the steps I've taken make absolutely no fucking difference, so it's not really worth the hassle TBH.

[–] refalo@programming.dev 4 points 6 months ago (1 children)

Haven't used amiunique but the EFF one I have seen people criticize because it only checks your uniqueness among people who opted in to take the test, so the results can be highly skewed.

[–] pingveno@lemmy.ml 2 points 6 months ago (1 children)

The results aren't going to be that skewed. They operate on a simple principle. There are many features available on a modern web browser with a high degree of variability. Even not having a feature is itself a piece of a fingerprint. The combination of those many, many features is going to produce a high degree of uniqueness for almost any browser.

[–] refalo@programming.dev 2 points 6 months ago (1 children)

I wasn't trying to debate how the uniqueness is calculated, you're absolutely right on that, and other sites like creepjs do the same, but I think where the eff site is a tad misleading is in how it presents their "just how unique AM I" part of the results, because they only have their own collected data to compare that against.

Sadly I think even disabling JS entirely would take away so much "blending in" that it still wouldn't be hard to uniquely fingerprint a user without it. Even CSS (without JS) and standard HTML tags like "picture" can be used to fingerprint now.

[–] lemmyreader@lemmy.ml 1 points 6 months ago

Sadly I think even disabling JS entirely would take away so much “blending in” that it still wouldn’t be hard to uniquely fingerprint a user without it. Even CSS (without JS) and standard HTML tags like “picture” can be used to fingerprint now.

Right. I guess there's also a difference between wanting to be as anonymous as possible and wanting to not be tracked too much by some sites.

In some browser profiles I do block JS completely for a few reasons.

  • Let's me read a lot of articles. Even articles with supposedly "paywalls".
  • Clutter free reading. Does it matter that the remote sites can recognize me based on a unique FP and build a profile ? I'm not too bothered. Should I ?

For other use cases I prefer Tor browser without any added extensions.