it's funny that firefox is recommended here, but i've learned the hard way that my heavy reliance of firefox has lead me to be tracked server side since i use it on linux and android exclusively -- making me easier to finger print... apparently.
the most surprising part is that it doesn't matter how many vpn's, proxy's, container tabs, private tabs, privacy extensions i use; facebook, instagram, reddit, google are clearly able to track me. instagram doesn't even bother anymore with 2fa authentication when in private mode; they already know it's me and just let me log in with a simple password.
I mean, idk, you can resist fingerprinting and tracking all you want, if you log in to a tracker and tell it "yes, I'm me" then it'll always be able to track you. The fact that you're logging in with your identity at all seems to be negating all anti-tracking efforts.
yes, that seems to be the weak point that the server side tracking keeps leveraging successfully.
every single anti-tracking practice and extension i use usually works for a while, but -- inevitably -- they become ineffective at some point and i'm learning that i can't keep up with this perpetual cat-and-mouse game as i age.
i don't, but i'm glad i tried because i made me aware of how ineffectual my privacy practices and technology have become against meta or google or any other entity with virtually unlimited resources like meta.
I mean, no matter how good your opsec is, you logging into your acct is handing them your identity on a silver platter. Like, you go to facebook using Tails with good opsec, the log in page doesn't know who you are, but then you type "[email protected]" and "hunter2" and it knows you're either a hacker or you're actually you, so they send you an email "blah blah been accessed from such and such IP/IMEI/etc" but unless you say "fuck no it wasn't" then they're like "alright, guess it's him, add this to the list of tracking this guy's shit." It's like, the guy at the liquor store doesn't "know who you are" but then you pull out your ID and all of a sudden he does, "yeah, because you gave him your ID."
You'd need to create a new acct with fake details you haven't previously used and a fresh email. Or just like, not sign in at all.
you misunderstand, i didn't provide any email or password; it automatically let me log into the account without any credential challenge like i had an active cached session already.
but it did send me an email saying that i logged in from an unknown location, so go figure.
Ah, I see. Had you ever logged in with that device before? Even if you'd reset it, you can't reset the IMEI number (and apparently there's a similar tracker on windows).
this community has a reflexive habit of seizing on typos and minor imprecision for condescension sake. so i sometimes remember it and to tailor how i write as a result.
What do you mean by "Firefox lets you get tracked on the server side"? Use that Doh function with any DNS I recommend, like NextDNS, ControlD, or AdGuard, to prevent tracking via the server side. Also, you can use a VPN to hide your IP.
You use container tabs and private tabs, so how are Facebook and Google going to collect your data? A Firefox container means the entire Google login is limited inside that container only; it has no access to outside what happens. At the same time, you have to use a UBlock Origin or any other content blocker to block other types of tracking scripts outside that container.
About fingerprinting. You can tweak the config to make your Firefox more resistant to browser fingerprinting or consider using user scripts like Arkenfox, Better Fox, or Phoenix. There are also preconfigured browsers like LibreWolf and Mullvad Browser available if you are okay with constant breaking of functionality on websites. If none of this is enough, there is tor browser.
you misunderstand me -- firefox is helpful in this respect, but there's only so much it can do.
and i engage in anti-tracking practices and extensions when i learn of them and the point of my comment is that the the developers on the server side inevitably keep finding ways to circumvent each iteration eventually.
i'll always continue to do my best, but it's clear they're the better supplied side in this arms race
to answer your question: my comment was spurred on my instagram recognizing who i was on a device that i had never used before, on a sim/phone plan that i had never used before, using firefox in private mode.
i'm best guess so far is that some sort of 3rd party tracker was part of a different service that i had used the device earlier in the day clued in instagram into who i was.
First of all, avoid giving your mobile number on instagram. It is a very unique identity to identify you. Firefox private browsing mode alone won't help you but browser/profile isolation can be a better solution.
keep in mind that your privacy is not only in your control but other people who saved your number on their phone with real name, other services you used before or the isp iself can sell this data to data brokers. If you used whatsapp with this same number, then that's too a reason behind this.
Furthermore, device fingerprinting, browser fingerprinting, network fingerprinting, etc. pose significant drawbacks in privacy on platforms like instagram.
Note that it doesn't prevent sso sharing. I was signed into Amazon and a separate Firefox (actually librewolf) tab I had opened looking up a movie star on... IMDb force created an account for me using my Amazon account. No I did not get a prompt to accept it and no I did not click anywhere near the login buttons. Seen that this has happened to a few people but not everyone so it's almost like they're slow rolling it.
I've since isolated Amazon into its own profile altogether and added Amazon to unlock on my main browser profile. And of course requested deletion of my sudden imdb account
30 replies
Great writeup, I didn’t know about a bunch of these. Oh and how hostile the internet turned out…
Thanks.
it's funny that firefox is recommended here, but i've learned the hard way that my heavy reliance of firefox has lead me to be tracked server side since i use it on linux and android exclusively -- making me easier to finger print... apparently.
the most surprising part is that it doesn't matter how many vpn's, proxy's, container tabs, private tabs, privacy extensions i use; facebook, instagram, reddit, google are clearly able to track me. instagram doesn't even bother anymore with 2fa authentication when in private mode; they already know it's me and just let me log in with a simple password.
I mean, idk, you can resist fingerprinting and tracking all you want, if you log in to a tracker and tell it "yes, I'm me" then it'll always be able to track you. The fact that you're logging in with your identity at all seems to be negating all anti-tracking efforts.
yes, that seems to be the weak point that the server side tracking keeps leveraging successfully.
every single anti-tracking practice and extension i use usually works for a while, but -- inevitably -- they become ineffective at some point and i'm learning that i can't keep up with this perpetual cat-and-mouse game as i age.
The answer is simply "do not use facebook, instagram..."
i don't, but i'm glad i tried because i made me aware of how ineffectual my privacy practices and technology have become against meta or google or any other entity with virtually unlimited resources like meta.
I mean, no matter how good your opsec is, you logging into your acct is handing them your identity on a silver platter. Like, you go to facebook using Tails with good opsec, the log in page doesn't know who you are, but then you type "[email protected]" and "hunter2" and it knows you're either a hacker or you're actually you, so they send you an email "blah blah been accessed from such and such IP/IMEI/etc" but unless you say "fuck no it wasn't" then they're like "alright, guess it's him, add this to the list of tracking this guy's shit." It's like, the guy at the liquor store doesn't "know who you are" but then you pull out your ID and all of a sudden he does, "yeah, because you gave him your ID."
You'd need to create a new acct with fake details you haven't previously used and a fresh email. Or just like, not sign in at all.
you misunderstand, i didn't provide any email or password; it automatically let me log into the account without any credential challenge like i had an active cached session already.
but it did send me an email saying that i logged in from an unknown location, so go figure.
Ah, I see. Had you ever logged in with that device before? Even if you'd reset it, you can't reset the IMEI number (and apparently there's a similar tracker on windows).
Is there another kind?
this community has a reflexive habit of seizing on typos and minor imprecision for condescension sake. so i sometimes remember it and to tailor how i write as a result.
tor is the simple answer. same fingerprint as everyone else, different IP every time.
i want to use tor 100% of the time, but it is SO SLOW and i'm too burger-ized to put up with it.
I recommended Hardened Firefox.
What do you mean by "Firefox lets you get tracked on the server side"? Use that Doh function with any DNS I recommend, like NextDNS, ControlD, or AdGuard, to prevent tracking via the server side. Also, you can use a VPN to hide your IP.
You use container tabs and private tabs, so how are Facebook and Google going to collect your data? A Firefox container means the entire Google login is limited inside that container only; it has no access to outside what happens. At the same time, you have to use a UBlock Origin or any other content blocker to block other types of tracking scripts outside that container.
About fingerprinting. You can tweak the config to make your Firefox more resistant to browser fingerprinting or consider using user scripts like Arkenfox, Better Fox, or Phoenix. There are also preconfigured browsers like LibreWolf and Mullvad Browser available if you are okay with constant breaking of functionality on websites. If none of this is enough, there is tor browser.
you misunderstand me -- firefox is helpful in this respect, but there's only so much it can do.
and i engage in anti-tracking practices and extensions when i learn of them and the point of my comment is that the the developers on the server side inevitably keep finding ways to circumvent each iteration eventually.
i'll always continue to do my best, but it's clear they're the better supplied side in this arms race
Actually the implementation of tracking methods and data collection is much more easier than implementing methods to prevent them.
Can you please point out which service you specifically talking about?
i suspected that @[email protected] was up to no good. loledit: whoops, wrong post. lol
to answer your question: my comment was spurred on my instagram recognizing who i was on a device that i had never used before, on a sim/phone plan that i had never used before, using firefox in private mode.
i'm best guess so far is that some sort of 3rd party tracker was part of a different service that i had used the device earlier in the day clued in instagram into who i was.
First of all, avoid giving your mobile number on instagram. It is a very unique identity to identify you. Firefox private browsing mode alone won't help you but browser/profile isolation can be a better solution.
keep in mind that your privacy is not only in your control but other people who saved your number on their phone with real name, other services you used before or the isp iself can sell this data to data brokers. If you used whatsapp with this same number, then that's too a reason behind this.
Furthermore, device fingerprinting, browser fingerprinting, network fingerprinting, etc. pose significant drawbacks in privacy on platforms like instagram.
What would one use if they were sailin the sea's watchin stuff?
Use Librewolf + uBlock Origin (already pre-installed) + NextDNS via in-built DOH settings.
A well-trusted VPN service like Mullvad, Proton (which has unlimited free bandwidth with free servers), IVPN or Windscribe is also recommended.
Additionally, add these recommended filter lists to uBlock Origin.
https://github.com/yokoffing/filterlists
Thank you!!
LLM answer:
Is firefox multicontainer effective solution?
Note that it doesn't prevent sso sharing. I was signed into Amazon and a separate Firefox (actually librewolf) tab I had opened looking up a movie star on... IMDb force created an account for me using my Amazon account. No I did not get a prompt to accept it and no I did not click anywhere near the login buttons. Seen that this has happened to a few people but not everyone so it's almost like they're slow rolling it.
I've since isolated Amazon into its own profile altogether and added Amazon to unlock on my main browser profile. And of course requested deletion of my sudden imdb account
Yes, and it depends upon your threat model.