13 ms·
Very cool research and wonderfully written. I was expecting an ad for their product somewhere towards the end, but it wasn't there! I do wonder though: why wo
by lpapez 5mo ago
Very cool research and wonderfully written.
I was expecting an ad for their product somewhere towards the end, but it wasn't there!
I do wonder though: why would this company report this vulnerability to Mozilla if their product is fingeprinting?
Isn't it better for the business (albeit unethical) to keep the vulnerability private, to differentiate from the competitors? For example, I don't see many threat actors burning their zero days through responsible disclosure!
- hrimfaxi 5mo agoThey probably are not relying on it and disclosure means others can't either.
- valve1 5mo agoWe don't use vulnerabilities in our products.
- lyu07282 5mo agoSo it's the criminal that convinced themselves they are the good guys, I didn't expect that one. You are a malware company get a grip.
- celsoazevedo 5mo agoWould you prefer that they kept this for themselves instead of disclosing it? I get criticizing their business and what they do wrong, but doesn't seem right to criticizing them for doing the right thing.
- trinsic2 5mo agoIt means they are suspect. I think its right to be wary of motives if they are involved in the very thing they aim to bring awareness too. Questions arise in my mind as to why they would do something like this in the first place. Its been my experience that the general public doesn't seem to follow patterns and instead focus on which switch is toggled at any given moment for a company's ethical practices. This is the main reason why we are constantly gamed by orgs that have a big picture view of crowd psychology.
- celsoazevedo 5mo agoI don't trust them more because of this and maybe they've disclosed it for the wrong reasons, like not allowing a competitor to use it when they don't, but at the end of the day they did disclose a serious issue, and that's good for users. I understand where you're coming from, by the way, but sometimes the worst person you know does the right thing and it's not fair to criticize them for doing it (you could say nothing, don't have to change your opinion about them, etc). We also don't want someone to go "if I'm bad no matter what I do, then might as well make some money with this" and sell the exploit.
- trinsic2 5mo ago> I understand where you're coming from, by the way, but sometimes the worst person you know does the right thing and it's not fair to criticize them for doing it (you could say nothing, don't have to change your opinion about them, etc). We also don't want someone to go "if I'm bad no matter what I do, then might as well make some money with this" and sell the exploit. I hear you. I guess I just want to promote more vigilance. Looking at patterns and motives helps us stay balanced about these things IMHO.
- lyu07282 5mo agoWhat are you even saying? It's like getting upset at somebody who criticizes a criminal because they once helped some grandma across the street. I'm not upset at the criminal because they helped a grandma across the street obviously that's not the fucking point.
- celsoazevedo 5mo agoI'm not upset, I just don't think we should criticize someone for doing something good. Maybe they're a terrible org, maybe they deserve criticism most of the time, but not in this instance. It's not like you can't point out that they did a good deed, but that they're still in the shitty business of fingerprinting users. Also, if people only get the stick no matter what they do, then eventually some will embrace the dark side and at least make money out of it. And that's not good for you.
- lyu07282 5mo agoThe inverse is also true, letting them whitewash their image by pretending they care about your privacy and seek to protect you will be good for their public relations, but only if we let them. I refuse to be this gullible and run to their defense for no apparent reason.
- celsoazevedo 5mo agoThey can pretend all they want. I know what their business is, my opinion on the practices haven't changed. And yet, they did a good thing. I will criticize everything else, but not what they did right. It doesn't mean I'll go out of my way to praise them either... if it wasn't your comment, I wouldn't have said anything at all.
- diydsp 5mo agoThis isn't a someone. It's a corporation, a legal fiction explicitly designed to dissolve responsibility.
- 5mo ago
- somerset 5mo agoResponsible disclosure and commercial fingerprinting aren't contradictory.
- lyu07282 5mo ago[flagged]
- flufluflufluffy 5mo agoIf you take their claim that they don’t use vulnerabilities in their products as true, then I don’t see a contradiction. If it isn’t true, then obviously there is a contradiction. But your considering of all methods that enable fingerprinting as vulnerabilities is your own opinion. There are definitely measurable signals that are based on a user’s behavior, rather than data exposed by the browser itself.
- kube-system 5mo agoIt's a little bit disingenuous to call intentional wont-fix features "vulnerabilities".
- mtlynch 5mo agoI don't understand what you mean. What separates this from other fingerprinting techniques your company monetizes? No software wants to be fingerprinted. If it did, it would offer an API with a stable identifier. All fingerprinting is exploiting unintended behavior of the target software or hardware.
- giancarlostoro 5mo agoIt makes sense to me, they're likely not trying to actually fingerprint Tor users. Those users will likely ignore ads, have JS disabled, etc. the real audience is people on the web using normal tooling.
- baobabKoodaa 5mo agoUhh okay, so they do exploit vulnerabilities, they just try to target victims who can be served ads? What a weird distinction.
- exe34 5mo agoWell presumably they want to make money.
- adastra22 5mo agoPainting fingerprinting as vulnerability exploit is your own very biased and very out-of-norm framing.
- foltik 5mo agoHow would you frame it?
- SiempreViernes 5mo agoInstead of trying convince-by-assertion, maybe you could try offering an actual objection to the argument raised up-thread? On what basis do you claim that software developers, who did not establish a means of for third parties to get a stable identifier, nevertheless intended that fingerprinting techniques should work?
- NoahZuniga 5mo agoThe real reason is that fingerprint.com's selling point is tracking over longer periods (months, their website claims), and this doesn't help them with that.
- vorticalbox 5mo agoit allows you to track a browser forever because it is stable fingerprint point. This helps with long term tracking a great deal.
- PoignardAzur 5mo agoIf I understand correctly, it was only stable until you restarted Firefox / your computer.
- negura 5mo agocorrect. the ordering persists for as long as the original process continues to run
- vorticalbox 5mo agoOk that’s change it a bit but on the other hand I’ve had my browser open for weeks now and I only restart it when the “update” button turns red lol
- stackghost 5mo agoAll fingerprinting is a vulnerability, unless the client opts-in.
- lmz 5mo agoThe opt in checkbox is labeled "Enable Javascript"
- ranger_danger 5mo agohttps://fingerprint.com/blog/disabling-javascript-wont-stop-fingerprinting/ https://fingerprint.com/blog/disabling-javascript-wont-stop-... https://github.com/jonasstrehle/supercookie https://github.com/jonasstrehle/supercookie
- autoexec 5mo agoWhen I go to https://noscriptfingerprint.com/ https://noscriptfingerprint.com/ all I see is a blank page. My browser is pretty locked down in other ways which probably helps, but I'm still taking that as a good sign.
- ranger_danger 5mo agoThe site seems to have been taken offline, but the code is here: https://github.com/fingerprintjs/blog-nojs-fingerprint-demo/ https://github.com/fingerprintjs/blog-nojs-fingerprint-demo/
- danlitt 5mo agoRidiculous comment. People should not have to choose between functionality and privacy.
- eimrine 5mo agoImplement it then.
- kqp 5mo agoI’m going to go out on a limb and guess that you define “vulnerability” as something like “thing that will be fixed soon”. After all, Joe Random not liking a behavior doesn’t make it a vuln, there needs to be a litmus test. Am I close?
- jachee 5mo agoAny method of “fingerprinting” and invading a browser’s privacy is inherently an exploit.
- dlenski 5mo ago> We don't use vulnerabilities in our products. With all due respect, and acknowledging that your work is technically excellent… Isn't everything that you do an exploitation of vulnerabilities? https://news.ycombinator.com/from?site=fingerprint.com https://news.ycombinator.com/from?site=fingerprint.com Fingerprinting is all about extracting information about a site's visitors which those users didn't explicitly intend to reveal.
- kippinsula 5mo agothe business answer is boring: you don't sit on a browser zero-day that your own product depends on. if it leaks form somewhere else, the blog post writes itself and the trust you've built with every privacy researcher and enterprise buyer evaporates. honestly the hiring page line alone, 'we found and reported X to Mozilla', is probably worth more than the fingerprinting edge they'd keep.
- tcp_handshaker 5mo ago>> why would this company report this vulnerability to Mozilla if their product is fingeprinting? Maybe because is not as serious as them and their title, made it to be? Did you read it fully? The identifier described is not process lifetime stable, not machine stable, or profile stable, or installation stable. The article itself says it resets on a full browser restart... So this is not a magic forever ID and not some hardware tied supercookie. Now what should we do with that title, and the authors of it?