There's one thing this site gets wrong. And it's central for their mission to correct that. Because I guess everyone else does get that wrong, too. Very likely including those guys who do the profiling (although their wage probably depends on not realizing that mistake):
You do not need cookie banners to ask for consent to set a cookie. You are required to ask for consent to process people's information, to profile them, stalk them, fingerprint them. Cookies are one of the ways to do that. But not the only way.
This site - as basically every other site using ad providers - did all of this without asking for consent, but was required to ask. At least for visitors from the EU (like me). It didn't matter that they didn't use any cookies for it. They need to ask and they need to respect a rejection. It's also not ok to do it and just say that everyone else does so, too.
That's the message that should come across. Not "hey look what we can do without cookies". It's "hey, cookies are a scapegoat. We don't need them. We'd have to ask for consent but since everyone is so preoccupied with cookies, we just didn't. Like all this ad tech companies spying on you didn't ask, too. They should be held accountable."
Funnily enough, there was a user on Lemmy who literally did that. Every post contained a signature like that. Haven’t seen that line in a while though. I guess they just gave up or stopped posting on Lemmy.
The important thing is that every site is misprofiling you the same way, which doesn't actually help you. Your fingerprint just has a distinctive scar across it
Why don’t we have a plugin that randomizes all of the fingerprinting data? Anything you type gets copy/pasted into the site after you finish typing so you don’t leave typing info for the site to read etc. Or we could try to set all browsers to report the exact same information which ruins the premise of fingerprinting.
It detected a bunch of databases running on localhost. Which is weird because although all of the DBs it detected are present in my network, they're not on localhost. How did it figure that out?
Technically interesting, at the same time a bit far fetched with calculations that do not make much sense. For example they say that the resolution I use is rare and that the Do Not Tracl feature is off, makes it even rarer.
However, this is just a regular iphone with regular Safari. Based on those two factors, you cannot determine a user, as they are too broad, even in combination with others.
So yeah, fun numbers, fun to see how much information the browser exposes to the server, just to increase comfort.
30 Comments
elvith@feddit.org · 64 pts · 16d
There's one thing this site gets wrong. And it's central for their mission to correct that. Because I guess everyone else does get that wrong, too. Very likely including those guys who do the profiling (although their wage probably depends on not realizing that mistake):
You do not need cookie banners to ask for consent to set a cookie. You are required to ask for consent to process people's information, to profile them, stalk them, fingerprint them. Cookies are one of the ways to do that. But not the only way.
This site - as basically every other site using ad providers - did all of this without asking for consent, but was required to ask. At least for visitors from the EU (like me). It didn't matter that they didn't use any cookies for it. They need to ask and they need to respect a rejection. It's also not ok to do it and just say that everyone else does so, too.
That's the message that should come across. Not "hey look what we can do without cookies". It's "hey, cookies are a scapegoat. We don't need them. We'd have to ask for consent but since everyone is so preoccupied with cookies, we just didn't. Like all this ad tech companies spying on you didn't ask, too. They should be held accountable."
lambalicious@lemmy.sdf.org · 24 pts · 16d
Well now either that's passive-aggressive or aggressive-passive.
Atherel@lemmy.dbzer0.com · 18 pts · 16d
shocking
Hamartiogonic@sopuli.xyz · 15 pts · 16d
DNT doesn’t really work. That’s why Firefox removed that feature.
Source
starman2112@sh.itjust.works · 9 pts · 15d
Yeah, it's about as effective as ending every comment with "I do not consent to my comments being used to train AI data sets"
Hamartiogonic@sopuli.xyz · 6 pts · 15d
Funnily enough, there was a user on Lemmy who literally did that. Every post contained a signature like that. Haven’t seen that line in a while though. I guess they just gave up or stopped posting on Lemmy.
PRIMEcavitationfetishist@quokk.au · 3 pts · 16d
This is why anyone not caring about their privacy should be punched in the face.
phoenixz@lemmy.ca · 13 pts · 16d
5 seconds on the site and I closed it. The text writing on screen effect is beyond annoying
modus@lemmy.world · 4 pts · 15d
Seriously. Just print it all at once. I've seen all this before anyway. It's just presented differently.
RickyRigatoni@piefed.zip · 7 pts · 16d
my location was blank at least, thanks vpn
schnurrito@discuss.tchncs.de · 6 pts · 16d
Similar thing here: https://sinceyouarrived.world/taken
Marija_@programming.dev · 4 pts · 15d
I believe Politecookies should be the default standard.
BaraCoded@literature.cafe · 4 pts · 16d
It misprofiled me, so I guess I'm chuffed?
starman2112@sh.itjust.works · 4 pts · 15d
The important thing is that every site is misprofiling you the same way, which doesn't actually help you. Your fingerprint just has a distinctive scar across it
BaraCoded@literature.cafe · 2 pts · 15d
Hm, I see...
deadbeef79000@lemmy.nz · 3 pts · 16d
Neat.
ColdCreasent@lemmy.ca · 3 pts · 15d
Why don’t we have a plugin that randomizes all of the fingerprinting data? Anything you type gets copy/pasted into the site after you finish typing so you don’t leave typing info for the site to read etc. Or we could try to set all browsers to report the exact same information which ruins the premise of fingerprinting.
fruitycoder@sh.itjust.works · 2 pts · 15d
The tor browser aims for the latter approach
Lauchmelder@feddit.org · 3 pts · 16d
It detected a bunch of databases running on localhost. Which is weird because although all of the DBs it detected are present in my network, they're not on localhost. How did it figure that out?
ILikeBoobies@lemmy.ca · 3 pts · 16d
Port scanning, Steam does it to track everything on your network.
https://github.com/ACK-J/Port_Authority
As an add-on it'll let you know when a website tries and blocks but you can allow.
piccolo@sh.itjust.works · 2 pts · 15d
And this is why i ssh tunnel into my local services.
Kolanaki@pawb.social · 3 pts · 16d
I am over 70 miles away from Sacramento. How is it that far off of my actual city?
PRIMEcavitationfetishist@quokk.au · 3 pts · 16d
Omg! Where are you?
Kolanaki@pawb.social · 4 pts · 16d
Methdesto.
PRIMEcavitationfetishist@quokk.au · 6 pts · 16d
I'm so sorry!
riquisimo@lemmy.dbzer0.com · 2 pts · 16d
This is so cool!
pelespirit@sh.itjust.works · 2 pts · 16d
I'm 1 in millions, that's what I got out of this, lol. Fr, this is kind of scary even though I knew it was like this.
vala@lemmy.dbzer0.com · 1 pts · 15d
Site is unusable on FF android
Aeri@lemmy.world · 1 pts · 14d
WebRTC handed us your public IP directly: 0.0.0.0.
Well that doesn't seem right I really wish I could just tell my computer to stop handing over all this information for no fucking reason
antianarchist@sopuli.xyz · 0 pts · 15d
Technically interesting, at the same time a bit far fetched with calculations that do not make much sense. For example they say that the resolution I use is rare and that the Do Not Tracl feature is off, makes it even rarer.
However, this is just a regular iphone with regular Safari. Based on those two factors, you cannot determine a user, as they are too broad, even in combination with others.
So yeah, fun numbers, fun to see how much information the browser exposes to the server, just to increase comfort.