I try to be quite careful about not leaving a digital footprint, so I take some measures (private browsing, Linux, container tabs, delete my cookies, etc). This morning I observed something that tells me my measures didn’t work.
In the morning I searched on amazon on my GrapheneOS phone using the Firefox Focus browser (it runs only in private mode). I had no other tabs open, and I was not logged in. But few hours later, when I opened amazon on my laptop browser (a new Firefox private browsing window, my OS is Fedora Linux) and I logged in I see a box “Pick up where you left off” with the items I was browsing!
This is the first time in my life that I have looked for this item, so it really cannot be information leak from somewhere else. So I’m wondering how did Amazon manage to track me across devices while using private browsing, on a privacy respecting OS in both instances?
Additional thoughts
I recall setting my postcode when I was searching on the phone, but that is a very large area. Now I’m wondering, I’m actually in a different country from that postcode (I was looking for the item for my mom). Is it possible that the rare combination of my foreign IP and my postcode leaked my identity to Amazon?
Amazon probably fingerprinted your browser and associated that fingerprint with you.
Then they can track you by that fingerprint.
A fingerprint as i understand it is a collection of (seemingly random) data from the web browser that uniquely identifies it. They then associate that with your amazon account.
Ive come to find that the only way to be completely private is to buy land in the mountains somewhere, build a cabin, and have no electronic devices at all.
This means :
wood heat - you collect your own wood
large garden - so you have food and trading material for other things like canning supplies, clothes etc.
Minimal contact with others
Etc.
In other words “live like a sasquatch” .
Later it quantifies as “unique among the 309742 tested in the past 45 days”. I guess that’s pretty unique. I need to change my mobile browser it seems.
Unlikely, as fingerprinting heavily depends on things like UserAgent, WebGL, WebRTC, etc. to fingerprint your hardware and setup.
If you use a phone with cookies deleted after every session like you suggest, that phone browser would get a completely different fingerprint, and then they would not be associated with eachother.
If anyhting, my best guess is that you were logged in to Amazon (or something else) on both the phone and on the computer.
Whenever you are logged in, the act of logging in uniquely identifies you, so fingerprints don’t really matter in that situation. If you choose to log in to a site, you have already chosen to uniquely identify yourself simply through the act of logging in.
Thanks! I did not understand this aspect of fingerprinting
I am surprised because I was not logged in on the browser on the phone when I searched. But now that I think of it, I do have prime video installed on this phone (but rarely used). So if the browser has access to that information, it’s possible to associate that session to my account. If I look at App permissions for Firefox Focus, I see only allowed permissions are: Network, Notification, and Sensors.
On my laptop I wasn’t signed in, and I saw the generic landing page. I got the custom “Pick up where you left off” page after I signed in. That’s why it seems the information leak is on the phone, not my laptop.
Phone and laptop on wifi? Or phone on cell service and laptop wifi?
But yes these companies can fingerprint you through so many ways, including location data to the same house. GrapheneOS should have location disabled by default right? The crazy thing is that they can even track you based on how “untrackable” and randomized you are, as so few people do that sort of thing they can profile you based on that.
I have had things like this happen before where I search for something and my GF starts getting ads for it because she is at the same location, and the other way around.
There ya go. Likely when you accessed an amazon domain Prime Video started accessing stuff in the background. You dont have to have permissions enabled for things like Firefox, the phone itself will have data on it that you accessed that site through temporary data and caching and Prime Video app also has file system access and some permissions and will see things like that.
A potential could be previous sign-ins to Amazon on those two systems (the laptop and the phone).
I have no idea if they actually do this, but Amazon could technically store the fingerprint of all the devices you ever use to sign in, such that even if you visit the site with cleared cookies on the same machine at a later date, they know it is you and can associate your activity with your account.
So, if you ever signed in to Amazon on the laptop, it could know that is your laptop, and if you ever signed in with the phone, it could know that is your phone, and then it could make educated guesses to associate your search results with your account and display them on any associated fingerprinted device that you visit with, especially if they see them both visiting from the same external IP address (if IPV4) or IP address range (if IPV6)
These matches would unlikely have a high enough confidence to be used to authenticate you for financial or account reasons, but even a lower confidence is fine if all it is for it nudging you in the direction of things you have previously searched for, and collecting monetizeable user data.
Phone on cell service while I was on the train, laptop on wifi at the office.
Yes, location services are blocked for all apps, and requests my permission before use. I also do not have Google maps installed on the phone, only OSM and a Google maps lite (AFAIU it is a progressive web app, it has to ask for location permission after I open it).
But doesn’t GrapheneOS prevent this kind of cross application storage access? I’ve to admit, I don’t fully understand that feature.
Use Vanadium (default installed browser) instead of Firefox on grapheneOS. It’s more locked down than Firefox (which is getting shittier and shittier as time goes on anyway)
Hmm, this seems most likely to me. Considering my phone is using GrapheneOS (which blocks a lot more than your usual Android). I have signed in from my phone in the past, I think last time was a couple months ago to access a QR code for a shipping label. If the fingerprint from that session matches today’s session and they are logged, it’s very straightforward to match.
Ya, I immediately thought about it after starting this thread. I guess I have to clear the sessions manually after every use, or is there a setting I can toggle?
In my opinion Firefox is not a browser to use if you care about privacy or security. Your threat model may be different.
Edited to add: grapheneOS is only as secure as you let it be. If you install a bunch of apps and google play services then it is no longer secure or private. Sure you can have multiple profiles and sandbox that way but again that depends on your threat model. No google is the only good google in my opinion.
I really like the container tabs feature on Firefox, lets me isolate different sessions. Also I set resistFingerprinting to true. But I guess for some time Mozilla has become untrustoworthy.
Unfortunately I can’t do no Google on GrapheneOS, I need my banking apps to work. In my area, a lot more is done on the app nowadays. I’ll have to rethink some of my choices
Firefox is mainly funded by Google, take that however you like. As for your banking apps some will work natively with grapheneOS (Ally bank for example works fine). If you need to have google play services for a banking app then you should look at the different profiles that can be setup on graphene to further isolate this and only use that google enabled profile for the baking app and nothing else. It can be difficult and an adjustment, but can also be totally worth it.
Corporations and governments employ legions of extremely technically-capable people to de-anonymise folks on the Internet. Taking “some measures” is inadequate defence against them.
If you purchased your ‘smart’-phone in a country that requires you to ID yourself at point-of-sale, or ID’d yourself to activate your SIM, or bought your phone and/or activated your SIM using anything but cash, then you are identifiable and trackable. You don’t need to even use the device to be identified and tracked – just having it in your pocket is sufficient.
Proximity tracking associates your mobile phone with your home router, your desktop and your laptop. Once that’s done, it doesn’t matter where you go or what you use – they know it’s still you.
Anonymity on the Internet is almost entirely a myth, and is unachievable for greater than 99.999% of the population. Those people who are anonymous on the Internet do not use mobile phones, use mobile phones with hardware kill switches for various components (like the second processor in your phone that you have zero control over, which runs even when your phone is ‘off’), keep mobile phones in Faraday pouches, do not have accounts with vendors, do not use traditional financial services at all, etc., etc. They are not ‘normal’ people, and they do not lead ‘normal’ lives.
Unless someone is able and willing to dedicate something like 10 hours a week, each and every week – forever – towards educating themself about security, and keeping up-to-date, they have no hope of being (or remaining) anonymous online. Only a very small segment of the population can justify doing that. You are not in that segment.
Anonymity cannot be obtained by normal people who do normal things online. It requires extreme levels of discipline and sacrifice, and results in an Internet that is barely recognisable as the one you currently enjoy.
There is a lucrative industry of companies and individuals that profit from selling or promoting ‘measures’ that ‘improve’ anonymity (privacy/security). Are some of those measures legitimate? Sure. But improving your anonymity level from 1.3% to 1.4% makes not one iota of difference. You’re still getting tracked.
Amazon has been tracking you across devices for years. The mistake they made this time was making it obvious that they are tracking you. Smarter companies and governments track you and use that information behind the scenes… knowing that if you ever became aware of the tracking that you would change your behaviour. That is undesirable. They want to profile you and use more subtle and indirect methods to manipulate your behaviour to their benefit. The goal is for you to act the way they want, while at the same time thinking that you are the one making the decisions.
Anyway, the point is that since about 2007 you haven’t been anonymous. Your possession and use of a ‘smart’-phone is the primary reason for this. Modest amounts of well-intentioned effort towards privacy lulled you into a false sense of security. It was only a mistake on the part of Amazon that pulled back the curtain on their capabilities – just a little. You have been tracked across devices for years. You have been profiled and manipulated for years.
“Shopping at Amazon” or “using any Google service” are completely incompatible with “anonymity”. There are no amount of videos that you can watch, or measures that you can take, which will let you do the former, without losing the latter. Knowing exactly how they did it this time won’t protect you the next time.
My suggestion: Be realistic. You can’t have your cake and eat it too. If possessing and using a ‘smart’-phone and shopping online are important to you, do those, accept the tracking, and worry less about privacy. Treat the Internet as a public space, instead of a private one. There’s little point in continuing to invest ‘modest’ amounts of effort into privacy when doing so clearly doesn’t work, and all it does is lull you into a false sense of security.
I’ve thought a bit about this in the past as well, and it seems like you would probably have to have a visible presence at least to show that you are “normal,” and cover up your other activity. Even using TOR for instance relies on other folks mixing with your traffic, right?
A user who blocks everything, takes steps to leave no trace but has an ip address or sim card or whatever kind of stands out against the normal user. You could almost fingerprint a user by what they don’t allow.
Agree with all of the above, if someone really wants to know who you are and what you are doing, they can probably find out.
Still, makes sense to resist as much as possible, but being realistic is also true. Do you want Amazon video? Then you probably have to deal with the consequences.
I appreciate the diligence though, sounds like you have a better smoke screen than me!
I think you are blowing my question (and expectation) out of proportion. I’m not Edward Snowden (which is the kind of anonymity you are talking about). But I do not want to be tracked because
ad networks have become a significant risk for various malwares (Wendel also alluded to it in a recent video, IIRC in the unhinged minisforum NAS video) elderly people like my mom are incredibly vulnerable to these,
user profiling driven differentiated pricing that inhibits my ability to get a fair price on my purchases, and lately
being exposed to political propaganda based on some supposed political inclination.
Wanting to avoid any of these is the responsible thing to do. Your conclusion can also be used to justify accepting shitty stuff like Microsoft pushing always online accounts on Windows 11 so that they can push ads into the OS.
In any case, I’m not here to debate the merits of wanting digital privacy. I asked a very specific question for better understanding, and if people have any ideas I could try to achieve my goals. I think there are some good explanations and suggestions already, thanks for those.