Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't see how using containers in Firefox or auto-deleting cookies would have any negative effect here.

None of the cache deletion/isolation addons should inject any Javascript into the page or alter headers in any way, so they shouldn't be detectable to sites you visit. So in terms of unique behavior, all that site isolation means is that you're going to hit caches more often and be missing cookies.

I mean, sure, a website can recognize that you don't have any unique cross-site cookies to send them and make some inferences based on that, but the alternative is... having a unique cross-site cookie. So it's not like you're doing any better in that scenario.

I can see an argument against a few of these like DecentralEyes, since they change which resources you fetch at a more micro-level. But uBlock Origin and Multi Account Containers seem like strict privacy/security improvements to me.

UBlock Origin especially -- if you care about privacy, you should have that installed, because outside of very specific scenarios your biggest threat model should be 3rd-party ad-networks, not serverside 1st-party timing attacks/fingerprinting. No one should be running Chrome or Firefox without Ublock Origin installed.



Auto-deleting cookies or other content in a way that doesn't resemble Safari ITP would indicate that a device at your IP address is constantly losing tracking cookies in an uncommon manner, theoretically increasing your trackability.

Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways. If all Firefox 85+ users are partitioning, then any inferences drawn from that behavior do not increase your trackability — and it could well decrease it, as those Firefox 85+ users will be joining the swarm of Safari users whose browser has already done the same sort of partitioning for a couple years.

Multi Account Containers are an oddity, and alone they would not be particularly distinguishable from a multi-user computer (which, at a home residence, could be unusual; many people don't have User Accounts on a shared device). However, when combined with cross-container tracking infection (such as URL parameter tags designed to survive a transition to another container, e.g. fbclid or utm_*), it's possible to identify that a user is using containers, which is a very rare thing and not available by default, thus increasing risk of being tracked.

UBlock Origin allows far too much customization for me to prepare any clear reply there. I imagine it is possible to run UBO with a ruleset that only interferes with requests to third-party adservers, without letting the first-party know that this is occurring. I doubt, however, that a majority of UBO users are running in such a circumspect mode. Adblocking often requires interfering with JavaScript in ways that are easily visible to the first-party (who has a vested interest in preventing ad fraud).

Fingerprinting is a known defense against fraudulent clicks, so there's a lot to puzzle over there. But I definitely don't like to take active steps to make myself stand out from others. I'm annoyed that I'm tracked a little on the web, but I'm indistinguishable from the general pool of "users with default browser settings" today. That's a type of protection that addons can't provide. I'm not wholly certain what I think yet, but happily the browsers continue advancing the front of protection forward, so maybe by the time I decide it won't matter anymore. YMMV.

ps. I'm glad to see your much more nuanced consideration of this balance, and I wish that more took your careful approach here when recommending "privacy" setups to others.


> Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways.

But if the defaults don't block those cookies, then the alternative is that you have unique cross-site cookies, which are an instant game over. Having a site make inferences about you is preferable to having a unique cross-site cookie set that can perfectly identify you across multiple websites.

> [...] and I wish that more took your careful approach here when recommending "privacy" setups to others.

Similarly, I appreciate your approach and concerns, and you are correct that browser uniqueness is a valid concern, one that many people don't consider. But I fully stand by my advice. Your first priority as a user who cares about privacy needs to be blocking unique cross-site cookies. If you have them set, it's just game over, it doesn't matter whether or not someone is fingerprinting you somewhere else.

Your priority list should be:

A) block cookies and persistent storage that can track you across sites.

B) block tracking scripts from ever executing at all.

C) keep your browser from standing out.

D) etc...

uBlock Origin is the easiest, simplest way that you can make progress towards addressing A and B. To your overall points about stuff like advertising networks looking to prevent fraud, this is exactly why it's important to block advertising networks; they're the low hanging fruit that's most likely to be trying to fingerprint you at any given moment. To your point about it standing out that you don't have certain query params set, those query params are unique identifiers and referrers. If you don't delete them it's game over, you have been identified. You can't blend into the crowd if you have a tracker attached to you.

There are very few one-size-fits-all approaches to security/privacy, but I fully stand by the belief that virtually every single person running Chrome or Firefox should have uBlock Origin installed. I don't have much nuance or any caveats to add to that statement: block unique identifiers first, worry about fingerprinting second. You don't need to worry as much about your browser standing out if you block the majority of tracking scripts from reaching your browser in the first place, and in most (not all, but most) cases you should be more worried about 3rd-party tracking on the web than 1st-party tracking. That's just where the current incentives are right now, and it's important that we calibrate our threat models accordingly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: