@p
> Instead, the hack analyzes subtle features of a potential target’s browser activity to determine whether they are logged into an account for an array of services, from YouTube and Dropbox to Twitter, Facebook, TikTok, and more. Plus the attacks work against every major browser, including the anonymity-focused Tor Browser.

It's not a hack, it's called Single-Sign-On :)
And it's been known for years.

Interestingly, BadWolf is effectively immune, new tabs have a separated ephemeral session.

@lanodan @p Firefox has this "containers" that keep cookies and persistent data isolated. Should be immune too if used properly.

@m0xee @p Except not really.

The advertised case is about 5 *permanent* containers, maybe few ephemeral ones, IIRC that's with an extension.

Meanwhile where, the number on the tab easily goes beyond 52 after few days, together with also often cleaning tabs as there is virtually no latency in doing so.

I don't think anyone could do this on firefox without redoing the interface or keybindings, which is probably a pain in the ass.
And if they're anything close to me, their memory usage would be going to the roof because I never clean tabs in firefox except via just creating a new window and closing the old one.

@lanodan @p No, of course they don't isolate each tab, that would be trouble. You can assign which container the tab uses manually. This way if you log in to Facebook in the Facebook container, cookies and persistent data can't get outside. It's like using a different profile, but all within one browser instance. That is why it should be immune only if used properly. If all your tabs use the default container — it's not.

@m0xee @p So in your mind you create a container for each thing you log into?

Are you not aware of things like shadow-accounts? Facebook has been doing this for absolute ages. (Those people probably hate me :D)

And fingerprinting apparently got good enough that some are advertising it as an authentication method, and it probably works well enough.
Follow

@lanodan @p Exactly! For each thing I have to use and I don't trust.
Well, I do a lot more than that. I have Forget Me Not to clean up cookies and persistent data on leaving the domain. I only keep cookies for a few things I need actually.
And I don't have and never had Facebook, Instagram or WhatsApp accounts in the first place. So I think I'm fine 😄

@m0xee @p I guess the difference ends up that I don't trust by default, to the point where I aggressively self-host.

@lanodan @p Self-hosting is great, but takes a lot of time to maintain. I have my own nitter instance, but I'm too lazy to host something like matrix server.

@m0xee @p Matrix is a shitshow, don't even try.

Hosting XMPP? Painless, it's essentially just installing prosody and enabling few plugins in the config, few more things if you care about VoIP and IPv4.

Hosting mumble? Pretty easy.

Hosting IRC? Easy until you have bots.

Hosting email? Also works well, the ones yelling about Google/Microsoft/… online are probably mailing-list hosters, not the same kind of deal at all. And I wouldn't host mailing-lists except very small ones, subscription management is hell, there is better protocols.

@lanodan @p Isn't hosting e-mail a similar shitshow nowadays? I mean configuring sendmail is pain, but at least I did it sometime ago. But all this DKIM-stuff is a fsckery of its own.

@m0xee @p
> sendmail

Are you from the previous millenium?

I would recommend OpenSMTPd.
As for DKIM… I hate this shit but dkim-proxy just works.

@lanodan @p
>Are you from the previous millenium?
Damn! My cover has been blown! 🤣

@m0xee @lanodan You can ignore DKIM if you don't mind GMail usually marking you as spam. (Fine by me.)
@m0xee @lanodan (SPF you can't ignore; a lot of hosts just drop you without even a courtesy notice. SPF should default to "v=spf1 mx -all".)
@p @m0xee I think drop stuff also drops your email if they got it through a mailing-list (I hate this hack, get a real protocol people, usenet/forums/… are a thing).
@p @m0xee I'm not a forum person but to me it's because of their scattered away decentralisation.
But that's typical web stuff, even for the fediverse there is very few things that allow to use multiple accounts at once.
@m0xee @lanodan

> And I don't have and never had Facebook, Instagram or WhatsApp accounts in the first place.

https://en.wikipedia.org/wiki/Shadow_profile
Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml