Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd love an explanation on how these microtimestamps can be used to unmask people


I'd never heard specifically of Chrome but in general I would imagine if they record the time application was installed down to some microseconds and then are able to see all requests tagged with that timestamp, and one of the requests is linked to you signing in to GMail they can link the two.

Now in general they don't even need it, other browser fingerprints are working pretty well:

https://panopticlick.eff.org/


I tried to run that test in Firefox, but first NoScript mutinied, then uBlock Origin threw out First Party Simulator as malvertising. Does that mean that I'm safe, or do I still have to worry about server-to-server communications?


its been a while since i last visited this site but i noticed the only real thing that makes it easy for them in my case is my language settings. I preferred English language before my native language which must have been so odd that my browser is unique among all they have tested...


One simple example: you browse a bunch of stuff, and they are able to know these were from the same person due to the identifier. Then you log into, say, Gmail. Now they have information to deduce you are that person.

Not saying they necessarily do that, but if they are indeed able to associate the "installation ID" to every request made with the browser, they have the information to do this, if they decide to do so.


In Firefox the requests made to Google's safe browsing are sent using a completely separate cookie jar that is isolated from the rest of the browser, so that even if Google is tracking the requests to its safe browsing service it wouldn't be able to identify you on the basis of the unique cookie alone.


Not alone, but correlated with other traffic from your IP address, browser fingerprinting, etc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: