Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Switching it from passive to active means you can count it towards https://github.com/bslassey/privacy-budget . Yes, sites can ask for all sorts of things, but if they ask for enough that they could plausibly be fingerprinting you then they start seeing their requests denied.

(Disclosure: I work at Google, speaking only for myself)



Is the "privacy budget" an actual feature of chrome or just an idea? I've never heard of it until now.


It's a proposal for how to prevent fingerprinting: https://blog.chromium.org/2019/08/potential-uses-for-privacy...


It prevents others fingerprinting, not Google though. Isn't there that x-Client-Data header than chrome only sends to Google domains?


The X-Client-Data header is documented in https://www.google.com/chrome/privacy/whitepaper.html#variat... and Chrome uses it to run experiments to make the browser better. It's not used for fingerprinting.

(Still speaking only for myself)


So why not still send limitied information by default in the User-Agent header, and if they ask for it, send more information in User-Agent header? (keep everything in one spot?)

Why are we creating redundant headers?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: