Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, but you can also use DDG without CSS or JS, https://duckduckgo.com/html/


You can still be fingerprinted by HTTP request headers alone. You can test the number of identifying bits your browser generates at EFF's Panopticlick[1]. It's scary.

https://panopticlick.eff.org/index.php?action=log&js=no


They explain their methodology and some defenses in a linked paper (PDF):

https://panopticlick.eff.org/browser-uniqueness.pdf

All in all it's pretty scary though. My browser is unique among 5.3 million or something. And then there's the algorithm they mention that can detect fingerprint changes with 99.1% accuracy, and be used to do things like recreate cookies that you deleted.


That's pretty cool (from a technical point of view, not cool from a privacy point of view). It says my particular configuration of browser plugins is unique among 1,827,392 browsers tested. Taken together with all the other unique things means I'm unique among 5,482,178 browsers tested. Shouldn't there be a way to hide most of that so you would be far less unique?


You could manually set your user-agent string to a more polular one (IE on Windows 7?). There are several browser extensions that allow you to set UA string manually for Chrome and Firefox.

However, an adversary can also fingerprint your OS/patch level based on packet structure[1][2] - which can't be easily changed. This will add more identifying bits.

1.http://nmap.org/book/osdetect-fingerprint-format.html

2.http://www.windowsecurity.com/articles-tutorials/intrusion_d...


Disable javascript, use ublock/umatrix, and browse in incognito mode


Huh. So apparently I'm the only Conkeror user in the world (or at least that Panopticlick has encountered).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: