this post was submitted on 22 Aug 2026
78 points (100.0% liked)

Privacy

50637 readers
453 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

Bit of an uphill fight with captchas everywhere. Do people here conduct all online activity over VPN whenever possible? Only for the sensitive stuff? Or perhaps the inverse because the bank already knows you? Maybe when travelling or getting around region blocking? Something else?

The one provided by my work aside, I realized that I don't have any consistent rules around using VPN. Except sometimes, you know, when downloading ISO's for my favorite distos.

you are viewing a single comment's thread
view the rest of the comments
[–] chicken@lemmy.dbzer0.com 5 points 6 days ago (1 children)

Mostly just for torrents, one machine on my local network is always using a VPN to connect to the external internet. I would use it for more things like private web browsing, but without substantial additional setup I think my web browsing is guaranteed to be fingerprinted regardless of whether I conceal my IP so until I bother to set that up it doesn't seem like there is much point.

[–] hirihit640@sh.itjust.works 4 points 6 days ago* (last edited 6 days ago) (2 children)

Do not try to do anti-fingerprinting yourself. Cobbling together your own configuration will only make you stand out more. Use a pre-configured browser from a reputable company. This way you blend in with everybody else using the same browser. And don't install extensions either unless you really know what you're doing. Extensions usually change your fingerprint.

Use Tor Browser for browsing over Tor, Mullvad Browser for everything else. Librewolf is fine for when you don't care about hiding your fingerprint, like when you are logging into email and bank accounts.

[–] willington@lemmy.dbzer0.com 1 points 5 days ago* (last edited 5 days ago) (1 children)

fonts, screen resolution, many things can affect fingerprint.

The solution is not "a browser from a reputable company."

It will be a browser designed by security professionals to spoof fingerprints, along with a "crawler" that analyzes the current blend of fingerprints already out there, crawling not web pages but the request headers instead, and canvas outputs, etc.

I don't think such a browser plus infrastructure exist yet, but they will. It is inevitable.

Such a browser will output garbage yet plausible and believable fingerprints that maximize ambiguity.

[–] hirihit640@sh.itjust.works 1 points 5 days ago (1 children)

What makes you think the Tor Browser and Mullvad Browser are not made by "security professionals"? Have you used either of them? They already have defenses against font, screen resolution, and many other fingerprinting vectors.

Also, "plausible and believable" fingerprints were already considered by Tor Browser and Mullvad Browser, and I believe are actively in use by Brave Browser. I forget why Tor Browser and Mullvad Browser opted to instead give everybody the same fingerprint, but there was a reason for it.

[–] willington@lemmy.dbzer0.com 1 points 5 days ago* (last edited 5 days ago) (1 children)

Of these Tor is the best for protecting identity, however Tor produces a recognizeably Tor-like fingerprint, which for my preference is not ideal.

So for example Tor browsers can all be denied access, because Tor, not the individual user, but the kind of browser used, can still be identified.

My ultimate latent goal isn't to only protect the anonymity of a security-conscious user, but to poison all fingerprinting data so that the entire technique is abandoned as useless.

[–] hirihit640@sh.itjust.works 1 points 5 days ago (1 children)

Adversarial methods like that won't work. Google will know when their data starts getting poisoned. Their ad targeting will lose effectiveness, their profit margin impacted. And they will tweak and tighten their trackers until they can squeeze out a good fingerprint again. In the end Google simply rolls out Web Environment Integrity, and consumers won't be able to use the web unless they prove their identity. If you want to fight big tech, this is the endgame they will push toward. If you want to play a cat and mouse game with big tech, big tech wins in the end since they have all the money.

Tor Browser recognizes this. So Tor Browser just erases any existing identifiers, while accepting that websites can identify Tor users and block them if they want. It's a very explicit signal that "this is a user that cares about privacy", and it's up to the website to accept that user or not. If a website doesn't care, then usually it will work fine in Tor Browser. If a website does care and tries to block Tor users, then Tor Browser doesn't bother fighting it. There are better places for them to focus their energy.

Ultimately if you want the web to be private, the only solution is to convince everybody else to want the same. Websites won't block privacy-seeking users, if everybody is a privacy-seeking user. Then, even big tech will have to concede.

[–] willington@lemmy.dbzer0.com 1 points 4 days ago* (last edited 4 days ago) (1 children)

Just fundamentally, to fight, you have want to win.

You are arguing to stop fighting on the basis of a supposedly improper desire. Wanting small bite sized things is proper. Wanting something audacious is not. Your kind of argument could work in theory if my desire is unserious. That's just psychology, not technology.

The scariness and the capabilities of an adversary is never, on their own, a proper reason to not fight.

The valid reasons can be: a deeply reasoned and deeply felt long term change in priorities, or a tactical hiatus to rest, regroup, reload. These are completely internal affairs, meaning, a serious person cannot be casually argued either into or out of these. I would check in with my soul to know whether or not to fight. Not with strangers on the net.

People fight to satisfy a certain hunger, and not because it looks easy or is a popular thing.

[–] hirihit640@sh.itjust.works 1 points 4 days ago (1 children)

But there's strategy to this. What I'm saying is that it's more productive for privacy advocates to spend their efforts convincing others that privacy is important, or pushing for privacy-friendly regulation, rather than trying to fight a war of attrition with big tech.

[–] willington@lemmy.dbzer0.com 1 points 4 days ago* (last edited 4 days ago) (1 children)

I don't think what you're saying here in this last reply competes with what I am saying.

It is both/and. Not either/or.

My strat combines naturally with using advocacy, electoralism, lying flat, malicious compliance methods, militancy, legal/beurocratic methods, economic methods, etc.

I am for all of these. Whatever works.

But ignoring the human relationship dimension and exclusively focusing on prosecuting tech, imo, is not a serious strategy.

Besides, someone who needs to hide their ID now should use Tor now. Someone who has a lower risk profile can afford a solution that aims to poison the well for the long term in preference to a better ID protection.

I am not doing anything illegal, I want to poison the well if I can. I still use Tor sometimes anyway. I want the whole fingerprinting industry to just go away.

[–] hirihit640@sh.itjust.works 1 points 4 days ago (1 children)

I want the whole fingerprinting industry to just go away.

Be careful what you wish for. As hardware attestation continues to spread, companies won't need fingerprints to identify you. Though if you want, hardware attestation can be thought of as an unique and unforgeable fingerprint. Poisoning the well won't work for it.

Just to clarify, hardware attestation is not bad in itself. It can be used by the user to secure their device (aka secure boot). It's when third-parties try to use it, where it becomes a threat to privacy. Like a website asking for your hardware-attested device id.

Of course we don't want to give our id to these third parties. But we need to convince everybody else to do the same. Because if everybody else gives up their id, then websites won't care about the few "privacy extremists". And those people will simply be locked out of the web.

But anyways, back to fingerprinting. I feel like the best way to get a sense of the scale of the issue, is to simply dive into the developer discussions around it. Look into mailing lists and feature discussions for Tor browser, Mullvad browser, and Brave. I guarantee you there are discussions around trying to make the browser look identical to the average user, and the challenges of doing so.

[–] willington@lemmy.dbzer0.com 1 points 4 days ago* (last edited 4 days ago) (1 children)

Again we're back to bad fear-based logic.

You're saying hardware attestation is a looming punishment for poisonin fingerprinting.

Wrong.

The enemy wants hardware attestation now, and they want it bad. Nothing you do or avoid doing can influence this because they, the enemy, are responding to their own hungers.

I repeat, there are only two valid reasons to stop prosecuting a fight, and this isn't one of them.

You are offering an incorrect model of the enemy as a nanny who will try to shape my behavior in responce to my behavior. I "need" to please the nanny and I "need" to avoid pissing off the nanny. Your argument is designed for that sentiment: nanny-pleasing.

The correct model is one based on INTERESTS. The enemy has an interest in hardware attestation regardless of what we do or don't do. They will prosecute their interests KNOWING those are deeply unpopular. Look at the Guardians Of Pedophiles party, the GOP in USA. They are unpopular. They are hated. They KNOW this. They keep trucking. Why? The INTEREST didn't go away. The interest is not socially shaped, unfortunately (or fortunately?).

[–] hirihit640@sh.itjust.works 1 points 4 days ago (2 children)

If you believe hardware attestation is inevitable, then why bother poisoning the well for fingerprinting? None of that will matter once hardware attestation takes hold

[–] willington@lemmy.dbzer0.com 1 points 4 days ago (1 children)

I apologise for a 2nd reply, I just wanted to clarify.

What I cannot readily control (or don't know how) is the internal hunger stemming from the soul (mine or enemy's).

But which hungers get to dominate in a public arena, I do have a say in that. So having some hunger may be inevitable, but making that personal hunger into an impositional system for everyone, that's not inevitable.

So yea, they want hardware attestation now. They're not relaxing until they find out what we do with the fingerprinting ecosystem first. That's laughable.

Since they're going to do what they're going to do, and since the outcome is never set in stone ahead of time but instead has to be discovered by living life, we have no reason not to chase our dreams and ambitions as much as they chase theirs. I have no reason to preemptively block or throttle my energy. I am not here to please any would be nannies. I have fears, but do not allow my fears to impact my logic. And besides I fear surveillance capitalism more than whatever else the "punishment" is promised to be.

[–] hirihit640@sh.itjust.works 1 points 4 days ago

I admire the drive. And I am not here to discourage you. The privacy world could always use more driven people. There are tons of projects that can use more supporr, like I2P, Tor, Monero, Internet Archive, Whonix, Qubes, etc. Keep at it and I'm sure we can win.

[–] willington@lemmy.dbzer0.com 1 points 4 days ago

Nothing is inevitable. Everything is negotiable.

[–] lemmingsareawesome@sh.itjust.works 1 points 6 days ago (1 children)

tried tor on tails and on whonix in a qubes vm. still being tracked by google. it might work for you though.

[–] hirihit640@sh.itjust.works 2 points 6 days ago (1 children)

If you enable Javascript there's still some crazy ways you can be tracked beyond the normal fingerprinting techniques. Stuff like mouse and keyboard tracking. Or looking at your behavior (what posts you view the longest, which photos you zoom into).

Disabling Javascript (using Tor Browser in the Safest setting) is the safest. Second to that, is enabling Javascript for websites you trust. You can use the NoScript extension to allow some scripts while blocking others. Usually you only need to allow scripts from the website itself, and block ones from third-parties like Google.

What were the issues you ran into?

[–] lemmingsareawesome@sh.itjust.works 1 points 6 days ago (1 children)

i disable javascirpt and use safest setting

I use invidious to check if google is tracking me (i get recommended videos i like on the first page so i know its not behavoir fingerprint)

[–] bleustenns@lemmy.ml 1 points 1 day ago (1 children)

I'm not sure Google is tracking you via Invidious recommendations. I think whatever instances are popular just get used by people with the same general content interests, so those IP addresses get served that sort of content.

[–] lemmingsareawesome@sh.itjust.works 1 points 20 hours ago (1 children)

can u tell me what you see when you go to invidious (not the search page the popular page)

(genuine question)

[–] bleustenns@lemmy.ml 1 points 3 hours ago

Sure! Here's what I see on the nadeko Invidious instance. Screenshot of the nadeko Invidious instance