Use uBlock Origin, Multi Account Containers, Privacy Badger, Decentraleyes and CookieAutoDelete with Firefox. Make sure you aggressively clear cache, cookies, etc., periodically (with CookieAutoDelete). You’ll probably load the web servers more and also add more traffic on your network, but it will help protect your privacy since most websites don’t care about that. When websites are user hostile, you have to take protective measures yourself.
Doing this will make it trivially easy to fingerprint and track you on the web, as the set of people who use non-defaults like this list is 0.000001% of the total possible user space for their area, and your IP address probably only changes rarely or never
A better way to protect yourself is to use a browser with tracking protections on by default, and leave the settings alone. You may see a few more ads but you’ll be a lot less tracked as a result.
If personal convenience is the priority, then of course Adblock and so on to your heart’s content, but if not being tracked is the priority, reset your browser settings to default and remove weird addons that your neighbors don’t use.
I don't see how using containers in Firefox or auto-deleting cookies would have any negative effect here.
None of the cache deletion/isolation addons should inject any Javascript into the page or alter headers in any way, so they shouldn't be detectable to sites you visit. So in terms of unique behavior, all that site isolation means is that you're going to hit caches more often and be missing cookies.
I mean, sure, a website can recognize that you don't have any unique cross-site cookies to send them and make some inferences based on that, but the alternative is... having a unique cross-site cookie. So it's not like you're doing any better in that scenario.
I can see an argument against a few of these like DecentralEyes, since they change which resources you fetch at a more micro-level. But uBlock Origin and Multi Account Containers seem like strict privacy/security improvements to me.
UBlock Origin especially -- if you care about privacy, you should have that installed, because outside of very specific scenarios your biggest threat model should be 3rd-party ad-networks, not serverside 1st-party timing attacks/fingerprinting. No one should be running Chrome or Firefox without Ublock Origin installed.
Auto-deleting cookies or other content in a way that doesn't resemble Safari ITP would indicate that a device at your IP address is constantly losing tracking cookies in an uncommon manner, theoretically increasing your trackability.
Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways. If all Firefox 85+ users are partitioning, then any inferences drawn from that behavior do not increase your trackability — and it could well decrease it, as those Firefox 85+ users will be joining the swarm of Safari users whose browser has already done the same sort of partitioning for a couple years.
Multi Account Containers are an oddity, and alone they would not be particularly distinguishable from a multi-user computer (which, at a home residence, could be unusual; many people don't have User Accounts on a shared device). However, when combined with cross-container tracking infection (such as URL parameter tags designed to survive a transition to another container, e.g. fbclid or utm_*), it's possible to identify that a user is using containers, which is a very rare thing and not available by default, thus increasing risk of being tracked.
UBlock Origin allows far too much customization for me to prepare any clear reply there. I imagine it is possible to run UBO with a ruleset that only interferes with requests to third-party adservers, without letting the first-party know that this is occurring. I doubt, however, that a majority of UBO users are running in such a circumspect mode. Adblocking often requires interfering with JavaScript in ways that are easily visible to the first-party (who has a vested interest in preventing ad fraud).
Fingerprinting is a known defense against fraudulent clicks, so there's a lot to puzzle over there. But I definitely don't like to take active steps to make myself stand out from others. I'm annoyed that I'm tracked a little on the web, but I'm indistinguishable from the general pool of "users with default browser settings" today. That's a type of protection that addons can't provide. I'm not wholly certain what I think yet, but happily the browsers continue advancing the front of protection forward, so maybe by the time I decide it won't matter anymore. YMMV.
ps. I'm glad to see your much more nuanced consideration of this balance, and I wish that more took your careful approach here when recommending "privacy" setups to others.
> Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways.
But if the defaults don't block those cookies, then the alternative is that you have unique cross-site cookies, which are an instant game over. Having a site make inferences about you is preferable to having a unique cross-site cookie set that can perfectly identify you across multiple websites.
> [...] and I wish that more took your careful approach here when recommending "privacy" setups to others.
Similarly, I appreciate your approach and concerns, and you are correct that browser uniqueness is a valid concern, one that many people don't consider. But I fully stand by my advice. Your first priority as a user who cares about privacy needs to be blocking unique cross-site cookies. If you have them set, it's just game over, it doesn't matter whether or not someone is fingerprinting you somewhere else.
Your priority list should be:
A) block cookies and persistent storage that can track you across sites.
B) block tracking scripts from ever executing at all.
C) keep your browser from standing out.
D) etc...
uBlock Origin is the easiest, simplest way that you can make progress towards addressing A and B. To your overall points about stuff like advertising networks looking to prevent fraud, this is exactly why it's important to block advertising networks; they're the low hanging fruit that's most likely to be trying to fingerprint you at any given moment. To your point about it standing out that you don't have certain query params set, those query params are unique identifiers and referrers. If you don't delete them it's game over, you have been identified. You can't blend into the crowd if you have a tracker attached to you.
There are very few one-size-fits-all approaches to security/privacy, but I fully stand by the belief that virtually every single person running Chrome or Firefox should have uBlock Origin installed. I don't have much nuance or any caveats to add to that statement: block unique identifiers first, worry about fingerprinting second. You don't need to worry as much about your browser standing out if you block the majority of tracking scripts from reaching your browser in the first place, and in most (not all, but most) cases you should be more worried about 3rd-party tracking on the web than 1st-party tracking. That's just where the current incentives are right now, and it's important that we calibrate our threat models accordingly.
The more people that install these, the less unique you become. Also if you are disabling JS execution via uBlock they aren't getting this list. What you are suggesting is essentially security by obscurity and this is failed already since it is highly unlikely my neighbor's browsing stream looks anything like mine.
What these plugins do is make the tracking job more difficult for the adtech guys, and the more complex these systems become, the higher the costs to the tracker and the higher the likelihood they screw up. It's defense in depth.
Or enable private browsing all the time. You'll have to log into your accounts every time you open your browser, but that's not really a big deal with a decent password manager.
Can you be tracked within the private browsing mode though? For instance in Chrome private tabs I know if you log in to something then open a new tab, that tab retains the cookies from the private session until you close all private tabs. Is this the same with Firefox? I'm hesitant to install yet another extension but I'm wondering if this one mentioned elsewhere in this thread will fix it, if it is the case with firefox
Unless you’re clearing cache, local storage, and HSTS, They can still track you. We haven’t got to the other things that can keep state that don’t reside in the browser. Not to mention fingerprinting the device itself, I’ve seen fingerprinting minute differences in CPU since they aren’t all identical.
Any reason to not go all-in and just use Tor? That's what I've been doing lately, although I'm not a web engineer, so I may not be doing the optimal thing.
Oh yes, there are definite downsides. There are plenty of sites that won't show you anything. I've taken the tact that there is more on the net than I could possibly view in a million lifetimes and just move on. I could see some people taking exception here. And yes, I don't bother with google's captcha, since if that shows up, it'll most likely never work, even if you keep trying. Some of the others will let you pass after one successful test. I don't find tor to be too slow though.
Brave doesn't have the features offered by those extensions, it doesn't have anything equivalent to multi account containers, it doesn't have DNS emulation (unless you install Decentraleyes) and it doesn't auto delete cookies (you still need to install Cookie Autodelete). The built in ad blocker is not as advanced as uBlock Origin and that's why I installed the latter as an extension (I turned off the built in one). Anyway IMHO the biggest limitation currently is the lack of containers, because it needs to be built into the browser, there is no 3rd party extension that can give you that.
Firefox’s Tracking Protection blocklist blocks many known fingerprinting scripts by default.
Firefox also has an active fingerprinting protection mode that spoofs the unique values returned from some JavaScript APIs (such as locale, time zone, screen dimensions, WebGL), but this feature flash is currently buried in about:config because it can break websites. How to enable fingerprinting protection anyway: