Privacy Possum 的评价
Privacy Possum 作者: cowlicks
cowlicks 的回应
开发者回应
发布于 8 年前TL;DR Panopticlick and Am I Unique use a homerolled assortment of tracking code that is impractical for commercial tracking.
I'll go into a little detail about Panopticlick to explain more. Panopticlick uses a deployment of the open source fingerprinting tool Fingerprintjs2, along with their own unique fingerprinting code.
I added some debug code and visited Panopticlick I see Privacy Possum detects the page accessing 12 API's that are marked for watching for fingerprinting. Except this is split over 3 different scripts:
https://panopticlick.eff.org/static/fp2.js
https://panopticlick.eff.org/static/fetch_whorls.js
https://panopticlick.eff.org/static/deployJava.js
Privacy watches for fingerprinting on *per script basis*, this is a reasonable assumption because, normally a websites tracking code is bundled into one place, so that the tracking info can be easily aggregated and used. I'm not aware of a real deployment where tracking is split up like this. It is practical for panopticlick (and Am I Unique) because they want to present information about your tracking independently, and manage the code to do that in a more practical way.
For a demonstration of the fingerprinting detection code, I usually point folks to:
http://valve.github.io/fingerprintjs2/
I think it is worth considering cases like Panopticlick, or Am I Unique, because they can be used to evade PP's novel detection. But I have not seen a case like this in the wild.
I'll go into a little detail about Panopticlick to explain more. Panopticlick uses a deployment of the open source fingerprinting tool Fingerprintjs2, along with their own unique fingerprinting code.
I added some debug code and visited Panopticlick I see Privacy Possum detects the page accessing 12 API's that are marked for watching for fingerprinting. Except this is split over 3 different scripts:
https://panopticlick.eff.org/static/fp2.js
https://panopticlick.eff.org/static/fetch_whorls.js
https://panopticlick.eff.org/static/deployJava.js
Privacy watches for fingerprinting on *per script basis*, this is a reasonable assumption because, normally a websites tracking code is bundled into one place, so that the tracking info can be easily aggregated and used. I'm not aware of a real deployment where tracking is split up like this. It is practical for panopticlick (and Am I Unique) because they want to present information about your tracking independently, and manage the code to do that in a more practical way.
For a demonstration of the fingerprinting detection code, I usually point folks to:
http://valve.github.io/fingerprintjs2/
I think it is worth considering cases like Panopticlick, or Am I Unique, because they can be used to evade PP's novel detection. But I have not seen a case like this in the wild.
423 条评价
- 评分 5 / 5来自 Firefox 用户 19909981, 18 天前
- 评分 5 / 5来自 Firefox 用户 19898777, 24 天前
- 评分 5 / 5来自 Firefox 用户 19885048, 1 个月前
- 评分 3 / 5来自 Firefox 用户 14497672, 5 个月前It breaks login on some sites but i guess it's a good thing to have
- 评分 5 / 5来自 Arman Daneshjoo, 7 个月前
- 评分 1 / 5来自 Firefox 用户 5905964, 7 个月前Malware. Timezone monkeying (nonsense values) makes you very, very unique and very, very easy to track! Says privacy on the tin, but achieves the opposite.
- 评分 3 / 5来自 Firefox 用户 16480293, 1 年前Appears to be interfering with some websites' login procedures. Trying to login to artstation with this enabled results in an infinite loading screen.
- 评分 5 / 5来自 Firefox 用户 19026513, 1 年前
- 评分 5 / 5来自 Firefox 用户 15514956, 1 年前
- 评分 5 / 5来自 Firefox 用户 18903740, 1 年前
- 评分 5 / 5来自 Juan García, 1 年前
- I was trying to find an extension that I pair with other privacy focused extension then I found this, although I didn't find it on Android add-on but at least I can add this to mine i thought it'll crash my browser but it's not instead it work like normal which is what I'm not expected and yes I love how this extension work.
- 评分 5 / 5来自 Firefox 用户 18619481, 1 年前
- Used to be ground breaking, but it has not been updated since Jul 18, 2019. Now it seems to break a lot of sites. I wish it had a better interface so we could toggle global settings of what we wanted enabled and disabled. It seems with a lot of the new privacy laws, browsers are starting to build these features in.
- 评分 5 / 5来自 Hsmalley54, 2 年前