- 62
- 224 449
The New Oil
United States
เข้าร่วมเมื่อ 29 มี.ค. 2018
The New Oil is a project dedicated to teaching beginners and non-tech-savvy people about digital privacy and cybersecurity.
The Invisible Way You Can Be Tracked Online
One of the most pervasive ways of being tracked online is also the most invisible. VPNs, browsers, extensions, and more all promise to protect you, but can they really?
=============================
➡️ Learn more @ thenewoil.org/
➡️ Support us! Merch, affiliate links, crypto, and more: thenewoil.org/en/support/
=============================
You can also view these videos on other websites:
🎥 PeerTube: apertatube.net/c/thenewoil/videos
🎥 TH-cam: th-cam.com/users/thenewoil
⏰ Timecodes⏰
00:00 Introduction
00:27 What is Fingerprinting?
02:01 How Does Fingerprinting Work?
03:33 What Doesn't Work
04:05 On Third-Party Cookies
06:44 On VPNs
08:03 How to REALLY Avoid Fingerprinting
08:17 Best Defense: The Tor Browser
09:05 Best for Most Situations: Brave
10:15 Best Not-Brave Option: Mullvad Browser
10:50 Extensions and Fingerprinting
11:51 Fingerprinting in Apps and Devices
14:25 Conclusion
✅ Sources
Source 1: signal.org/blog/the-instagram-ads-you-will-never-see/
Source 2: www.nytimes.com/interactive/2019/06/12/opinion/facebook-google-privacy-policies.html
Source 3: coveryourtracks.eff.org/
Source 4: amiunique.org/
Source 5: en.wikipedia.org/wiki/Wikipedia:Unusual_articles
Source 6: usa.kaspersky.com/resource-center/definitions/cookies
Source 7: cookie-script.com/all-you-need-to-know-about-third-party-cookies.html
Source 8: digiday.com/marketing/wtf-googles-privacy-sandbox/
Source 9: seon.io/resources/browser-fingerprinting/
Source 10: ublockorigin.com/
Source 11: www.privacyguides.org/en/dns/
Source 12: www.torproject.org/
Source 13: tor-https.eff.org/
Source 14: apertatube.net/w/84BiWbkzvDFHfv4QkaiTSu; th-cam.com/video/7Z5Y1zmorlc/w-d-xo.html
Source 15: brave.com/
Source 16: thenewoil.org/en/guides/most-important/browser/#brave
Source 17: blog.getsocial.io/share-buttons/
Source 18: mullvad.net/en/browser
Source 19: github.com/gorhill/uBlock/wiki/uBlock-and-others:-Blocking-ads,-trackers,-malwares
Source 20: github.com/gorhill/uBlock/wiki/Blocking-mode
Source 21: thenewoil.org/en/guides/most-important/browser/#extensions
Source 22: support.apple.com/en-us/102420
Source 23: support.google.com/googleplay/android-developer/answer/6048248?hl=en#zippy=%2Creset-your-devices-advertising-id
Source 24: thenewoil.org/en/guides/most-important/mobile-settings/
Source 25: apertatube.net/w/9n5G9HZyxEhbuvAc48Rwdt; th-cam.com/video/Pjy9Dbx7y1g/w-d-xo.html
#fingerprinting #privacy #tracking #TargetedAds #TargetedAdvertising #surveillance #BrowserFingerprinting #DeviceFingerprinting #WebFingerprinting
=============================
➡️ Learn more @ thenewoil.org/
➡️ Support us! Merch, affiliate links, crypto, and more: thenewoil.org/en/support/
=============================
You can also view these videos on other websites:
🎥 PeerTube: apertatube.net/c/thenewoil/videos
🎥 TH-cam: th-cam.com/users/thenewoil
⏰ Timecodes⏰
00:00 Introduction
00:27 What is Fingerprinting?
02:01 How Does Fingerprinting Work?
03:33 What Doesn't Work
04:05 On Third-Party Cookies
06:44 On VPNs
08:03 How to REALLY Avoid Fingerprinting
08:17 Best Defense: The Tor Browser
09:05 Best for Most Situations: Brave
10:15 Best Not-Brave Option: Mullvad Browser
10:50 Extensions and Fingerprinting
11:51 Fingerprinting in Apps and Devices
14:25 Conclusion
✅ Sources
Source 1: signal.org/blog/the-instagram-ads-you-will-never-see/
Source 2: www.nytimes.com/interactive/2019/06/12/opinion/facebook-google-privacy-policies.html
Source 3: coveryourtracks.eff.org/
Source 4: amiunique.org/
Source 5: en.wikipedia.org/wiki/Wikipedia:Unusual_articles
Source 6: usa.kaspersky.com/resource-center/definitions/cookies
Source 7: cookie-script.com/all-you-need-to-know-about-third-party-cookies.html
Source 8: digiday.com/marketing/wtf-googles-privacy-sandbox/
Source 9: seon.io/resources/browser-fingerprinting/
Source 10: ublockorigin.com/
Source 11: www.privacyguides.org/en/dns/
Source 12: www.torproject.org/
Source 13: tor-https.eff.org/
Source 14: apertatube.net/w/84BiWbkzvDFHfv4QkaiTSu; th-cam.com/video/7Z5Y1zmorlc/w-d-xo.html
Source 15: brave.com/
Source 16: thenewoil.org/en/guides/most-important/browser/#brave
Source 17: blog.getsocial.io/share-buttons/
Source 18: mullvad.net/en/browser
Source 19: github.com/gorhill/uBlock/wiki/uBlock-and-others:-Blocking-ads,-trackers,-malwares
Source 20: github.com/gorhill/uBlock/wiki/Blocking-mode
Source 21: thenewoil.org/en/guides/most-important/browser/#extensions
Source 22: support.apple.com/en-us/102420
Source 23: support.google.com/googleplay/android-developer/answer/6048248?hl=en#zippy=%2Creset-your-devices-advertising-id
Source 24: thenewoil.org/en/guides/most-important/mobile-settings/
Source 25: apertatube.net/w/9n5G9HZyxEhbuvAc48Rwdt; th-cam.com/video/Pjy9Dbx7y1g/w-d-xo.html
#fingerprinting #privacy #tracking #TargetedAds #TargetedAdvertising #surveillance #BrowserFingerprinting #DeviceFingerprinting #WebFingerprinting
มุมมอง: 3 501
วีดีโอ
Democracy in the Dark: Protecting Your Digital Rights
มุมมอง 1.2K3 หลายเดือนก่อน
With the elections getting closer, learn how to protect yourself from all the various threats out there. ➡️ Learn more @ thenewoil.org/ ➡️ Support us! Merch, affiliate links, crypto, and more: thenewoil.org/en/support/ You can also view these videos on other websites: 🎥 PeerTube: apertatube.net/c/thenewoil/videos 🎥 TH-cam: th-cam.com/users/thenewoil ⏰ Timestamps 00:00 Introduction 00:37 Disclai...
Is THIS the Future of Mobile Apps?
มุมมอง 7K9 หลายเดือนก่อน
Progressive Web Apps (or PWAs) offer better privacy, use less space, and work cross-platform. But how usable are they really? ➡️ Learn more @ thenewoil.org/ ➡️ Support us! Merch, affiliate links, crypto, and more: thenewoil.org/en/support/ You can also view these videos on other websites. 🎥 PeerTube: apertatube.net/c/thenewoil/videos 🎥 TH-cam: th-cam.com/users/thenewoil ⏰ Timecodes⏰ 00:00 Intro...
This Tool Erases Your Old Posts & Comments!
มุมมอง 3.2K10 หลายเดือนก่อน
Dan Saltman on how Redact can help protect your privacy by curating your outdated content. 🔗 Get 15% off Redact: thenewoil.org/redact 🔗 Non-affiliate link: redact.dev ➡️ Learn more @ thenewoil.org/en/guides/moderately-important/public-protections/ ➡️ Support us! Merch, affiliate links, crypto, and more: thenewoil.org/en/support/ You can also view these videos on other websites. 🎥 PeerTube: aper...
5 Everyday Benefits of Privacy & Security
มุมมอง 1.7K11 หลายเดือนก่อน
5 Everyday Benefits of Privacy & Security
Mullvad VPN and The Tor Project Released a New Browser!
มุมมอง 9Kปีที่แล้ว
Mullvad VPN and The Tor Project Released a New Browser!
A Subjective Comparison of Android and iOS
มุมมอง 2.3Kปีที่แล้ว
A Subjective Comparison of Android and iOS
How to Protect Your Privacy While Finding Love Online
มุมมอง 1.4Kปีที่แล้ว
How to Protect Your Privacy While Finding Love Online
I'm Enabling YouTube Monetization, Here's Why...
มุมมอง 1.1K2 ปีที่แล้ว
I'm Enabling TH-cam Monetization, Here's Why...
Take Your Privacy to the Next Level with Voice-over-IP! (Plus 6 Suggestions)
มุมมอง 24K2 ปีที่แล้ว
Take Your Privacy to the Next Level with Voice-over-IP! (Plus 6 Suggestions)
Is Your Data Posted On The Internet? (Here's How To Remove It!)
มุมมอง 3.4K2 ปีที่แล้ว
Is Your Data Posted On The Internet? (Here's How To Remove It!)
Getting Started with Email Aliasing (and Six Services Compared!)
มุมมอง 41K2 ปีที่แล้ว
Getting Started with Email Aliasing (and Six Services Compared!)
Why You Need An Encrypted Email Inbox (And Five Suggestions)
มุมมอง 4.6K2 ปีที่แล้ว
Why You Need An Encrypted Email Inbox (And Five Suggestions)
Protect Your Devices From Unauthorized Access!
มุมมอง 4K2 ปีที่แล้ว
Protect Your Devices From Unauthorized Access!
Everything You Need To Know About Encryption
มุมมอง 2.3K2 ปีที่แล้ว
Everything You Need To Know About Encryption
Cloaked is a great service. I use it along with a fake address generator to match the number I get from Cloaked for things like grocery store loyalty card or social media sites. 👍🏻👍🏻
You said it’s not the same thing as simply adding a webpage to the Home Screen in iOS. So then how do I add the PWA version? And how do I know whether any given app has a PWA at all? Sorry if these are silly questions …
It's hard to tell on iOS. The way to add a PWA is the same as to add a site to the Home Screen, but the best advice I can give is to check some of the sites I mentioned to see if it's a PWA or not.
✌️ promote your video. This is cool.
Google Voice. Use your carrier phone number to sign up and then never use it again. Just use your GV number. Turn on call screening. It’s great for blocking morons. I’ve used GV for 15 years.
Reincarnated irl Geto
The problem is, people talking about digital privacy keep using false analogies to make you care about this stuff, but these analogies don't actually apply. I mean the only reason you actually care about real-life stalkers, is because real-life stalkers almost certainly want to do something you don't want. But that's not necessarily the case with online tracking, the only thing they want to do, is show you some ads, they don't want to meet you, they don't want your signature, they don't want to snap photos of your private affairs, they don't want to murder your kids. So the actual fundamental reason to care about real-life stalkers don't actually apply to online tracking, therefore you cant' just use the same analogy and imply they are the same, they aren't.
This is objectively untrue. Advertisers want to influence you, and many want to influence you in ways beyond "buy this item." Some of them want to influence the way you vote, your beliefs, or the causes you support. They want to distort what you see in your algorithmic feed and the truths you believe. This can easily be verified with a little research online, looking up things like the Cambridge Analytica scandal, the use of microtargeting in political ads, the rampant spread of "fake news," and more.
What do you think about the option to open sites in "anonymous view" in startpage?
I don't trust Startpage, personally, after the System1 incident (among other things). I think there are better options like SearXNG, Whoogle, Mullvad Leta or better yet someone who does their own indexing like Brave, Mojeek, or Kagi. More info: thenewoil.org/en/guides/less-important/habits/#search-engines
maybe there is a way to block embedded ads in android apps? dns won't help here
I've yet to find a reliable way. A lot of people report success with a Pi-hole, which is basically a self-hosted DNS blocker. Otherwise DNS in apps is hit or miss for me. I wish I had a better solution.
@@TheNewOil amaik the pihole option must be run on rooted android, witch is, well, not for everyone
Can't it run on a Raspberry Pi? Isn't that why it's called a Pihole?
Funny enough this video was recommended to me by TH-cam to farm money with ads.
We're also on PeerTube. No account required, can subscribe via RSS, no ads or trackers.
The literal third party cookies are only blocked by Brave, the rest not counting privacy forks don't do it. Firefox for example you need scrict mode or custom
Then what is Firefox doing out of the box? Does Mozilla just pull a "trust me bro" and call it a day? 🤣
I'm not sold that _session_ cookies are a good thing. Re: "... in some cases this is a good thing they can allow you to log into a website..." I would rather go back to everything host-side so that when someone takes their eye off the ball LTT doesn't get hacked.
i was thinking of this subject not long ago, and literally visisted one of the websites that you mentioned lol i think youre the one spying on me! haha jokes aside, I'd love to know your thoguhts on the LibreWolf browser, because imho it balances anti-fingerprinting with usability relatively well anyway, great video!!
I believe Librewolf has become redundant with Mullvad Browser, to be honest. Mullvad is already pre-hardened, comes with uBlock Origin, has clear instructions how to use it properly to blend in. That said, as you noted, Mullvad does sometimes cause usability issues on certain cites, so there's nothing really wrong with Librewolf, I just think Mullvad is better if you can use it (like how Tor is best if you can use it). Further note: most of those screenshots of me doing fingerprinting tests came from Librewolf.
just a heads-up Vivaldi since the beginning has blocked third party cookies
Thanks for the correction. I can't recall where I sourced my information from for those claims, but Privacy Tests seems to agree with you. Sorry for getting that one wrong.
Not true, do a fresh install and you wont see the option enabled. Its hidden only accessible by chrome://settings
@@TheNewOil Vivaldi are one of the good guys in the browser space
@@ultravio1et don't forget librewolf browser and mullvad browser
Mullvad my beloved.
Better than librewolf?
Thank you! Really good video
Great video, well put together.
How exactly do websites see exactly which extensions you have? I have heard this claim a lot but never seen exactly how it really works. (prompted from points made around 10:50)
There's several possible ways. User agent is one I mentioned, Javascript is - from what I can infer - a popular method, but even CSS can be used, which is why I don't recommend things like user agent spoofing or javascript blocking. There's lots of ways to do it but the most effective way is simply to not have too many extensions.
@@suedoe4316 In Chrome and Firefox the extension ID can be retrieved from the stack trace by invoking errors. A lot of extensions also add stuff to the page or JavaScript scope, all of which can be profiled and used to fingerprint the browser.
👍👍👍👍👍👍👍👍👍👍👍👍👍👍👍👍👍👍!!!
Oh and nice video ofc. Any upload from The New Oil is always a great day
I have 9 extensions, 5 of which are absolutely necessary. I would not use my browser without them. Is there any way to hide which extensions I'm using?
None that I would trust to be effective. We've even seen proofs of concept before that use CSS to detect extensions, and blocking that isn't really feasible.
1) On Vivaldi, you yourself have said in the past to change the defaults. I tell people that if Brave's crypto stuff and Eich's views are dealbreakers but not closed-source components to go ahead and use Vivaldi after changing the defaults. Even though they're conforming with Google's getting rid of Manifest v2, their adblock and tracker block definitions are about the same except one of those checkboxes is an "allow ads from Vivaldi's partners" option so I also tell people to watch out for that (thankfully it's near the top). 2) When I was running stock Android on my Pixels, the option to delete advertising ID was there and it was persistent. I'd go back in after every firmware update and make sure it was still off.
I like this new setup. Is opting out of fingerprinting really a thing? I mean the opting out is itself a fingerprint.
It can be, which is why the best solutions (in my opinion) are one of the two mentioned. Simply blocking scripts individually makes you unique, but trying to blend in or use randomization is far more effective based on the studies I've seen.
@@TheNewOil Good point. I've found blending involves a lot of guesswork without knowledge of the sites traffic. There are ways to do it but it's usually limited to select targets. I work in the industry too and see pretty much everything. Randomization in all forms is basically signaling you are browser x, y, or z, and is always in the 0 - 5% bucket.
Sadly there's not a lot of options out there. You have to pick the one you feel is most effective and roll with it. You have the advantage of insider information and knowing which ones are most effective based on your experience.
With Pwas its nearly impossible to use css to position a row of buttons on the bottom of the screen and always above the keyboard, even when it opens
Hi, could you show me an example of what it looks like or what the problem is?
It's unfair that Premium subscribers still need to endure paid promotion and sponsorship 🙃
Nate I see U and Henry were talking about your phone doing the mission impossible thing. I am currently in the market again and looking for recommendations. I have been seeing some things on the brax3 phone that is new to me. Maybe it's time to dedicate a show on the new state of privacy phones.
I don't recommend any Brax phones. I've not heard anything good about it from any of the experts I trust. I've talked extensively about phones here (thenewoil.org/en/guides/most-important/mobile/) and in the last two paragraphs here (thenewoil.org/en/guides/moderately-important/mobile-habits/). A phone video is on the roadmap but it will be a while.
Signal: that new piece of code "to fight spam" might be used for other things. Like metadata collection for a 3-letter agency. And what if it is a backdoor?
Wire errata: wire is based in Switzerland, for legal privacy protection reasons, but has its server farm in Germany (just because the internet 2.0 is better there and much faster).
very helpful thanks
Signal is the most important program of the last decade. Honest political discussion will soon be exclusive to nets where it can't be viewed by the public like on political Facebook pages. Largely because a lot of people are so sensitive to disagreement that they'll try to ruin you and say you're a horrible person.....because apparently that's easier than having a conversation.
Alright, you had me until you said you support privacy for people who put pineapple on pizza. 🙄
Imagine charging $30 a month for a tool that is worse than free Python scripts one can get of GitHub.
SimpleX vs Session vs Threema vs Signal would be interesting
Sadly, My SO thinks using different passwords everywhere is paranoia, not a reasonable security precaution.
Signal is great dont get me wrong but it's major flaw is the phone number and contact access
Session Private Messenger! No competition.
At 2:53, it is claimed that wiki saw a decrease in views due to the Snowden leaks. However, outside forensic examination by Dr. Alan Salzberg, in Court, refuted that claim.
This is my first time hearing about this claim being refuted. Thanks for the tip, I'll be sure to look into it!
I had to laugh at 5:08, all the election signage... instantly recognized the signage from Alberta, Canada. We're a little more lax about that stuff in the great white north, neighbours will have signs from opposing parties on their lawns up here and still get along noicely over a coffee at Tim Hortons. "I don't care if you vote wrong, how's the fishing last week?" We actually care more about how Americans vote in your elections where it's actually consequential than how we vote here because our Left and Right have basically the same policies... that and the head of state is not elected. The Governor of Canada, functionally ceremonial, is appointed and is an arm of the British rule. But he or she can technically decide who runs the country. It's an electoral college of one.
God bless you. God bless America
Well, I watch you over at Survaliance Report, and over here, and I've gotta say that this was an enjoyable, good humoured and informative 'rant' on the state of online privacy which deserves to be seen! Bravo👍👏
It's genially just disgusting that political violence, politically motivated attacks against people, etc even exist. I am moderate right, and I used to work for a local restaurant, they somehow caught word of my views. And I would constantly have a bias against me, where if I do something that is slightly wrong I would get punished more than others. I ended up being fired because of my political beliefs, luckily I found a new job that does not care. People used to be accepting of others opinions but the extreme of both sides (though more towards the left) have become more and more intolerant of others with the "wrong opinion". Also not helped by people being stuck in echo chambers, only hearing one side, which only gets more and more extreme. Also you can use online aliases if you want to talk about your politics in a more secret manner. Separating it from Online and real life.
Be sure to use an unrelated email address and don't give them your phone number
Absolutely outstanding advice! This one is a reference-quality video I'm also putting to my "Watch Later" folder so I don't forget it! Well, done, Nate!
Nate: "Practice minimalism. Detach yourself from social media." Also Nate: "Listen to a new podcast." Podcasts are no different than a TH-camr spouting off their opinions in a video. People should be doing their own research, not relying on the "trust me bro" mentality that's rampant among content creators.
I guess I'm first 🙃 Here from techlore .
hurray! A new upload :D
To what extent, can one customize the domain name in aliased email addresses?
🎈✨️🎈
So basically we need Molly without phone and decentralized?
I have a PWA with lots of access to hardware like GPS, notifications, etc., and it works great. It really just depends on how you develop it. The only issue with them is that they don’t pay app stores, and that's why they want to get rid of them
I don't quite understand your answer. I've seen that the payment method on the webapp is Stripe within the webapp.
16:05 signal app has option for bio/pin lock. an attacker with your unlocked phone cannot necessarily get into signal
It's already been proven that the government has already gotten around encryption by scanning your phone or tablet before encryption happens.