Fingerprinting Thread

Previous thread: browserprint.info/
panopticlick.eff.org/
ip-check.info
browserleaks.com/

Fingerprinting is a new way of tracking you across websites.
It's being done right now by companies like Google.
Because unlike cookie based tracking you can't defeat it just by disabling cookies.
There is currently NO FOOLPROOF DEFENCE against fingerprinting (except no Internet).

Google's privacy policy states
>Other technologies are used for similar purposes as a cookie on other platforms where cookies are not available or applicable
google.com/intl/en/policies/privacy/key-terms/#toc-terms-cookie

ReCAPTCHA probably contains fingerprinting code:
archive.is/9K5gs
This means that the majority of Sup Forums users could be being fingerprinted, and Google might know about your shitposting habits even if cookies are disabled.
To fix this you can get a pass (which allows you to be tracked by Sup Forums in a different way), or run Sup Forums with the no JavaScript CAPTCHA (use Sup Forums X to make Sup Forums without JS bearable).
Note: The no JavaScript CAPTCHA is broken for a lot of people.

Google releases limited hangout of how much they know about you:
news.slashdot.org/story/16/06/29/2038257/googles-my-activity-reveals-how-much-it-knows-about-you
>Oh, they're just remembering what YouTube videos I watched, nothing creepy about that, I already knew they were doing it!
>I guess all those people who fear tracking really are just conspiracy theorists!

Daily reminder to do all your Amazon / eBay / LinkedIn / botnet shit in a completely separate browser to your Googling or buying shit.
It's currently the ONLY way to truly defend against fingerprint tracking.
Double points if you have each browser running in a different VM with a different OS.
Triple points if you have each browser's VM configured with a different VPN.
The Tor Browser Bundle is still susceptible to many fingerprinting attacks that can uncover your true OS and browser.

Other urls found in this thread:

support.google.com/youtube/answer/3046484?hl=en
panopticlick.eff.org/
browserprint.info
browserprint.info/statistics
twitter.com/AnonBabble

What. That's just coincidence

Seriously?
It's showing Alex Jones videos and you think it's coincidence?
That's right wing conspiracy theorist shit that normies hate, and has nothing to do with the first set of videos

Not to mention that the Sup Forums videos have a couple hundred thousand views but all the other videos have millions upon millions of views.

who cares, you're just another number in a very, very large set of anonymized data.

what exactly are you trying to hide, op?

Wouldn't one VPN service with just different countries used be enough if you go the browser/vm route?

Yes that should be fine.
Many VPN services have many servers in many different countries, so I don't see why you'd need to use multiple services.

I used to use Sup Forums quite a bit and I have never got recommendations for that fucking idiot. It is a pure coincidence. His video could've been trending at the time this test was conducted.

What browser extensions do you have installed?
Do you set the do not track header?
Do you allow scripts on Sup Forums?

Also do you block 3rd party cookies or cookies in general?

Imagine in 10 years Google starts selling user profiles to employers as a kind of background check.
>So... it says here you visit that right-wing extremist site Sup Forums.org.
>I'm sorry but the position is no longer available

>Sup Forums
>right-wing extremist
is this what poltards actually believe?

It doesn't matter if you're a special snowflake hippy, Sup Forums is a lot more right wing than most websites and outsiders tend to judge us based off of two boards, Sup Forums and Sup Forums

Just tried it, was allowing scripts for google.com and gstatic.com to use the captcha on Sup Forums, allowing scripts from scripts for youtube.com and ytimg.com on Youtube for watching videos, had cookies from Google or Youtube blocked, and had do no track turned on.

fun fact: the vast majority hates both of the boards you've mentioned

Doesn't change a thing.
When people hear you're from Sup Forums they'll instantly thing Gamergater / Alt-right nazi / Trump supporter

It would be helpful if you could create an image like OP's that details the whole process.
Can't really show just the after image to people

>like OP's that details the whole process.
>Can't really show just the after image to people
Haven't been able to repeat it since. Maybe other people could just try it themselves?

I wish there was an easier way to detect tracking.
The youtube way is poor because it requires the data to go through like 3 or 4 sites before it hits youtube.
Maybe I could try with google ads. Does google even do ads anymore?

>Recently uploaded
>You're subscribed to one of the channels

No kidding it's displayed

>It's showing Alex Jones videos and you think it's coincidence?

In the top image, he's showing the popular channels feed, which aren't shaped by your browsing history, they're shaped by youtube general popularity

In the second image, he's showing Recommended and Recently Uploaded.

That Alex Jones one is showing because it's new and he's fucking subscribed to him, notice the checkbox next to the channel name.

My shitposting habits from job application sites and background check agencies for them, for one. Also, fuck anyone trying to learn how to manipulate me.

...

What the hell are you talking about? It's a direct measurement of the efficiency of google's instant activity monitor that you can do with any site using google's services, like recaptcha or analytics.

That's Google's verification badge you tard, it has nothing to do with subscribing to a channel:
support.google.com/youtube/answer/3046484?hl=en

>3rd party cookies are hard to block omg I'm retarded

>youtube has sign in button in the upper right corner
>user has self destructing cookies set to delete cookies when they close the tab (bottom right of browser)
Yeah, sure they are.

>panopticlick.eff.org/
am i being rused?

Nigger what? I wasn't even logged into YouTube, dumbass

See
Are you guys fucking retarded?
How the fuck would I be logged in if I cleared all history?

FUCK

what do I do?

See

The simplest thing to do is keep your botnet shit in one browser and everything else in another

>hurf durf I don't know how to protect my privacy general

"lol"

Also TBB is not vulnerable to browser fingerprinting because every TBB is the same, sans OS. You are the one introducing the vulnerabilities by letting Flash run and installing addons and crap into it.

>User Agent Mozilla/5.0
>Number of occurrences: 1

Get blender and fix your contrast. Even better, use Tor for browsing or Tails in a VM (won't be able to get reliably fingerprinted even if you do use JS).

>You are the one introducing the vulnerabilities by letting Flash run and installing addons and crap into it.
You mean by enabling JS.

>You mean by enabling JS.

Yeah, that too. Sorry for forgetting, Flash is just the one that pisses me off the most because it's done for dumb shit like Facebook videos.

use monospace for programing or terminal commands, it looks stupid, cool but still

>that image
Google still tracks you by IP even if you're logged off. They don't know what you posted, just that you visited Sup Forums, since Sup Forums uses google analytics. If you're really paranoid you can just block google scripts and this won't happen.

Don't forget that you then need to use Sup Forums X if you still want to be able to use the catalog, quickreply, and links to responses while using the noscript captcha.

Not true. There are ways to force the noscript captcha and still allow Sup Forums scripts. You need to use a blocker to block the captcha script from loading and a userscript/addon to display the noscript captcha, but it's pretty simple.

Or you could just be a good goy and buy a Sup Forums Pass™

>and a userscript/addon to display the noscript captcha,
...that's what Sup Forums X is.

But you said you need to use Sup Forums X, which is not true. You do need to use a userscript or addon, but only something to insert the captcha html into the page without disabling scripts completely.

brah, I got something scarier.

>having drinks with my friends
>drunkass talking
>at some point we were talking about soda brands
>one of them mention a really peculiar brand: Jarritos
>come to Sup Forums next day
>browse typical gentoo, nvidiots, amemedes and applelfags threads
>decide to shitpost in one of them
>guess what was the captcha about?

>Select all drinks
>Fucking bottle of Jarritos right in the middle

>it has also happened with places or sports

Do you have an android phone?
You know those listen to everything you say and send it to google waiting for you to say "ok google" or whatever those magic words are to activate the voice commands

yeah but we never said such words or did an actual search for it.

also, didn't have my phone close to me at that time

AudioContext fingerprinting

Do you have any chips in your body?
E.g. Google's new brain wave transmitter?
I'd heard they'd been implanting them in people during their sleep, but I thought it was just a rumor.

-incognito

Tor is kinda shit, m8.
Enjoy waiting 20 minutes for a page to load.
Enjoy being forced to spend 3 hours solving unsolvable CAPTCHAs because some cunt website owner thinks Tor users are all hackers.
Enjoy supporting a bunch of SJWs who'll probably end up putting a back door in Tor to "prevent the harassment of women in the project"

Not to mention enjoy being on the NSA watch list.
Enjoy having some random exit node operator looking through your browsing history just because he can, or worse.
Enjoy never being able to customize your browser.
Enjoy supporting censorship circumvention software developed by posers who heavily censor their community.

See this is what I don't get. Normally some anti surveillance groups are very social justicy. But at the same time they'd give it all away for the freedom of whymen to say stupid shit and not be criticized.

nope, no chips or accessories like hands free or smartwatch

JTRIG pls
>Enjoy waiting 20 minutes for a page to load.
It takes a few more seconds, boo hoo.

>Enjoy being forced to spend 3 hours solving unsolvable CAPTCHAs because some cunt website owner thinks Tor users are all hackers.
Never had one not go through on the first time.

>Enjoy supporting a bunch of SJWs who'll probably end up putting a back door in Tor to "prevent the harassment of women in the project"
>muh SJW boogie man
Well shit, better throw away any thought of privacy instead.

>Enjoy having some random exit node operator looking through your browsing history just because he can, or worse.
>what is HTTPS
Also all they could look at is the traffic that goes through that node, not your entire browsing history.

>Enjoy never being able to customize your browser.
It's still better than having no privacy whatsoever.

>Enjoy supporting censorship circumvention software developed by posers who heavily censor their community.
wat

Wow, so they actually managed to hack the human brain.
Detect the EM waves emitted by the brain, decode them, and use them for advertising and user experience purposes.
That's terrifying.

If you spend time on the Tor IRC channels you'll see their censorship.
It's understandable on the development and tech support channels like #tor, but they even do it on general chat channels like #nottor and #notnottor.
You talk about anything they don't like or say anything they don't like and they'll set the channel to invite only then kick you.
And recently they set it so you can't connect via Tor, since people were using Tor to evade bans.
Fucking authoritarian hypocrites

It's probably another glitch from the matrix. Lately I only get "grass" and "lakes" captchas

>You talk about anything they don't like or say anything they don't like and they'll set the channel to invite only then kick you.
Let me guess, you went on there and started shitting up their channel calling them pedo enablers or something similar.

People hate on Sup Forums lingo, but I still see it everywhere off Sup Forums
Stay mad

No.
I barely said anything just watched.
They had one user who liked to talk about drugs and the justice system and the mod would sperg out every time.
Even if I did go there to call them pedo enablers that doesn't justify massively hypocritical censorship.

This isn't Tor at all. What the fuck guys?

I don't ever visit Sup Forums because of how retarded they get

And for me it's been a pleasure to actually look around and understand what's going on rather than stay comfortable in a little space full of circle jerking idiots who cry when there's a disagreement of any sort. It's disheartening to see that this is getting so deep that right now former friends who cried the whole "durr boogeyman no one cares nothing's happening" are now losing their patience.

I like Tor.
I just don't believe it magically fixes all problems.
I think they should allow you to use the TBB without Tor.
And I think its community is kinda shit.
A lot of social justice fascists who identify as anarchists just because "duh police is evul".

I agree Sup Forums is dumb and over-the-top, but they're not a circle-jerk. They have russians from a board that got shutdown that are hardcore communists, they have libertarians, national socialists, Trump/alt-right, social anarchists, all and the colors of the rainbows on top.
The drive-by shitty threads that also plague Sup Forums and any other faster, low content creation boards plague them like hell and drives the hate imo.

Tor's community has nothing to do with the software or developers. In fact, that they consider themselves anarchists while claiming to be a part of a community for software developed by the U.S. Navy shows just how idiotic they are and how little credence you should give to their rantings. I've only met Dr. Syverson by a crazy coincidence, but he's a really cool, intelligent, and I expect the rest of the important guys are just as great.

I really hate how "no true Scotsman" this sounds, but IRCs really are shitholes, get out and meet the devs. Also don't let shitheads ruin your enjoyment of things.

I don't know.
Nick Matthewson identifies as a "social justice artificer".
And Dingledine has stated he wants to shut down the Tor mailing lists are replace them with moderated ones, not to mention he was behind the "you can't disagree with women on Twitter" community guidelines.

Yeah I think I explained myself poorly. Didn't mean Sup Forums was the circle jerk itself but actually the people they despise. The communities we have all over there with the "inclusivity" and "diversity" that will kick you out as soon as you accidentally say something that someone might consider wrong but you were conditioned to take it as a joke because you happened to be an adult and you got into a kindergarten by mistake.

So even though I dislike alt-righters quite a bit I usually don't silence myself when there's some bullshit going on and because I tend to lean a bit to the right I'm automagically Sup Forums. I consider that there's a little bit of an issue and suddenly I represent the extreme end of the spectrum, by collectivists ironically speaking.

So I see a bunch of people advocating for freedom, for justice, open source software, anti-surveillance and such, that is all nice. But we could focus on that instead of trying to free some people from some artificial shackles while putting some on others.

It is almost inevitable at this point to talk about politics in almost any subject or community, because the situation has gotten quite crazy enough for politics to leak into many areas related to science, technology or entertainment. It has been a quick and noticeable change that you could be blissfully unaware, talking about your cartoons and stupid shit with some higher ups you considered colleagues at this point, then next day see the news and comment on it, and suddenly get banned, pointed at and shunned. Some people lost their jobs to this political leak.

If you are talking about something with tour friends and you keep your android phone within earshot, the first Google suggestion (autocomplete) will be about the thing you were talking about.
Try it, it's creepy as fuck. I even have the OK Google thing disabled..

This will be the near future if we don't resist.
The second I heard about phones which are always listening for commands I knew it was a bad idea

>the vast majority hates both of the boards you've mentioned
strange given how large both Sup Forums and Sup Forums are. I'm not sure that's even possible.

Is anyone getting significantly less than 11.0 bits of entropy on browserprint.info ?
I've tried it with three physically different machines through diff vpn gateways and they're all between 10-12 bits.

Would be nice if sites like this printed a histogram of the distribution.

The point of these sites are basically that every browser is unique

I get that, but I expected a little bit more variation even with the few thousand samples they seem to have. panopticlick by comparison you can change a significant number of bits of entropy in their model.

There was a study done a few years ago by Microsoft Research titled Host Fingerprinting and Tracking on the Web: Privacy and Security Implications
They found that they could track 60-70% of users using just user-agent string.

So i shouldnt use 4chans?

Then what can i do? what other chan is there?

Don't quit Sup Forums.
Just disable JS, then use Sup Forums X to make the site bearable.

browserprint.info/statistics didn't see the link at the beginning, I'm retarded

interesting. I use randomized useragents in two of my sessions but finding current lists of useragents is somewhat pita, so I have to updating manually.

but that doesnt stop google does it?

That will stop google from following you to Sup Forums.
I almost guarantee it.
Unless Jackie Sup Forums has undetectable fingerprinting on the site and sells that data to Google. But that's tinfoil levels of paranoia.

For other sites you need to build other defenses.

Actually it's possible that with the JS-less CAPTCHA Google does passive fingerprinting (which is weaker) like looking at your IP and user-agent.
We shouldn't get too comfortable with ourselves.

If you're using IceCat, Firefox with Blender installed, or TBB, plus you're blocking scripts with NoScript you should be safe from Sup Forums's NoJS CAPTCHA.
That means user-agent isn't unique, accept-headers shouldn't be unique, CSS font detection will be blocked, and CSS screen size will work but screen size is a pretty shitty tell.

Except IP address

Why doesn't 4c stop using captcha from Google?
There are other providers

scary shit

I READ THAT THE TOR PROJECT WAS FINANCED BY THE U.S GOVERNMENT.

IS THIS TRUE?

Im not as experienced user as you guys, so please explain to me, why cant this whole mechanism be fooled by receiving mutiple, random, opposite data, so the real pattern would be lost among flood?

You can in some ways, but it's hard to go all out with that.

>Finger Family videos
>complete normie stuff

Finger Family videos are probably one of the creepiest things on YouTube.

Yeah I'm pretty sure they still receive large amounts of funding from the government.
I don't think that's a good reason to distrust them though

Tried it with opera but I'm not sure, I think it didn't work because the VPN was banned.