Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Trying to prevent browser fingerprinting? The odds are against you
LinuxBSDos.com ^ | 18 December 2015 | Staff

Posted on 12/30/2015 4:01:14 AM PST by ShadowAce

With recent revelations about browser fingerprinting, the race is on to find ways and means that will help reduce your browser's fingerprint, and with it, make it difficult for it (and you) to be tracked.

After trying Panopticlick yesterday, a tool released by the Electronic Frontier Foundation to help users determine if their browser is safe against tracking and fingerprinting, I set out to find out how to make my browsers less unique to trackers.

For the very paranoid, the results are not good.

Under default settings, a browser like Mozilla Firefox and Iceweasel emit very unique fingerprints, as shown in the result of a Panopticlick test in Figure 1. "Default settings" implies that DNT (Do Not Track) is disabled, and cookies are accepted. Pay special attention to how many other browsers have the same fingerprint as the target browser.

Browser fingerprinting
Figure 1: Browser fingerprinting under browser default settings

Enabling DNT makes no difference to the result of the test.
Browser fingerprinting with DNT
Figure 2: Browser fingerprinting with DNT (Do Not Track) enabled

Even with DNT and cookies rejected globally, the browser still has a unique fingerprint which was even worse than when cookies were accept.
Browser fingerprinting no cookies<
Figure 3: Browser fingerprinting with DNT (Do Not Track) enabled and cookies disabled

With Privacy Badger installed, still keeping DNT enabled and cookies rejected, the result is only as good as when DNT was enabled, which means not very good.
Browser fingerprinting with Privacy Badger
Figure 4: Browser fingerprinting with Privacy Badger installed

Throw NoScript in the mix, and your browser stands out like a sour thumb, which is counter to the expected result.
Browser fingerprinting with NoScript
Figure 5: Browser fingerprinting with Privacy Badger and NoScript plugins installed

On a KDE desktop, there's an option in the System Settings that can be used to disable browser identification in Konqueror, the native KDE browser and file manager. It can also be used to give a fake identification to the browser.
 KDE Konqueror browser identification
Figure 6: KDE Konqueror browser identification

However, disabling sending browser identification is useless, as it still leaves your browser with a unique fingerprint.
fingerprinting test on Konqueror
Figure 7: Browser fingerprinting test on Konqueror

So despite all the browser tools and options that can be deployed and tweaked to give a browser a less unique fingerprint, nothing seems to make any real difference. And from what I've seen so far, the more plugins installed and the more options enabled/disabled, the more unique your browser becomes. It's like getting your phone number on a "Do Not Call" list. To learn a bit more about this topic, the EFF has some suggestions here.


TOPICS: Computers/Internet
KEYWORDS: browser; internet; privacy

1 posted on 12/30/2015 4:01:15 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

2 posted on 12/30/2015 4:01:30 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

For later. Thanks.


3 posted on 12/30/2015 4:17:46 AM PST by lysie
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

The best way to prevent getting finger printed would be if your browser randomly browses thousands of different sites in the background, so it’ll clutter up the real data with garbage.


4 posted on 12/30/2015 5:24:28 AM PST by MNDude (God is not a Republican, but Satan is certainly a Democrat.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MNDude
It's the website that does the fingerprinting.

What other sites you may be browsing at the same time would not have an effect on what the browser is doing at that site.

5 posted on 12/30/2015 5:39:42 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ShadowAce

Interesting, but let me try an analogy using a house:
-covering your windows
-blacking out your house number
-removing your mailbox
-gated entrance
-surveillance cameras
-camo netting over house to hide from google earth(and maybe street) images

Now, no one knows who’s in there are what they are doing and can’t get in to find out. But you stick out like a “sore thumb” as they say in the article and everyone thinks you are doing something.... aka “you must have something to hide”.

Seems the way to go is to build a honeytrap version of NoScript, Ghostery, ABP etc. which makes servers think you are actually running the garbage they are serving out.

Or, thinking bigger, basically a behind the scenes “virtual browser” running in default/generic mode that talks to the website while you view selected parts in your visible browser.


6 posted on 12/30/2015 5:41:57 AM PST by ew63
[ Post Reply | Private Reply | To 1 | View Replies]

To: ew63

A better analogy (in terms of fingerprinting) is that you live in a tract house that is absolutely identical to every other house on the street—with the same house number, paint, and style.


7 posted on 12/30/2015 6:03:29 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce

yeah i guess the tract house is what i meant would be the default/generic browser, and with the modifications listed above for security/obscurity etc, you end up with something that sticks out like a sore thumb


8 posted on 12/30/2015 8:34:39 AM PST by ew63
[ Post Reply | Private Reply | To 7 | View Replies]

To: ShadowAce

Privacy died when anyone first plugged into a TCPIP network that routed to the rest of the world.


9 posted on 12/30/2015 8:40:44 AM PST by Alas Babylon! (As we say in the Air Force, "You know you're over the target when you start getting flak!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: MNDude
I have an extension that does something like that...AdNauseum.

Essentially, AdNauseam quietly clicks every blocked ad, registering a visit on the ad networks databases. As the data gathered shows an omnivorous click-stream, user profiling, targeting and surveillance becomes futile.

10 posted on 12/30/2015 9:45:48 AM PST by Bloody Sam Roberts (Democracy is not freedom. Democracy is simply majoritarianism. It is incompatible with real freedom.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Bloody Sam Roberts

Serious? It exists? I think I’ll get it.


11 posted on 12/30/2015 10:06:39 AM PST by MNDude (God is not a Republican, but Satan is certainly a Democrat.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: ShadowAce

Your ISP knows where you have been. The police regularly check with the ISP on the suspect to see what searches they made related to the crime like terrorism and PakistaniBrides.com


12 posted on 12/30/2015 10:31:03 AM PST by minnesota_bound
[ Post Reply | Private Reply | To 1 | View Replies]

To: minnesota_bound

Your ISP knows that first hop. There are quite a few services that provide “anonymous” VPN services that also encrypt the data.


13 posted on 12/30/2015 10:36:25 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 12 | View Replies]

To: MNDude

Yep. It’s all in the background so I can only assume it works.


14 posted on 12/30/2015 10:52:44 AM PST by Bloody Sam Roberts (Democracy is not freedom. Democracy is simply majoritarianism. It is incompatible with real freedom.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: ShadowAce

bkmk


15 posted on 12/31/2015 1:37:55 PM PST by AllAmericanGirl44
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

bump


16 posted on 12/31/2015 1:39:00 PM PST by apocalypto
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson