I wrote a blog about Effective Web Tracking Methods that are still widely used in 2026.

  • asbestos@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    Great writeup, I didn’t know about a bunch of these. Oh and how hostile the internet turned out…

  • eldavi@lemmy.ml
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 days ago

    it’s funny that firefox is recommended here, but i’ve learned the hard way that my heavy reliance of firefox has lead me to be tracked server side since i use it on linux and android exclusively – making me easier to finger print… apparently.

    the most surprising part is that it doesn’t matter how many vpn’s, proxy’s, container tabs, private tabs, privacy extensions i use; facebook, instagram, reddit, google are clearly able to track me. instagram doesn’t even bother anymore with 2fa authentication when in private mode; they already know it’s me and just let me log in with a simple password.

    • ArcaneSlime@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      12
      ·
      2 days ago

      I mean, idk, you can resist fingerprinting and tracking all you want, if you log in to a tracker and tell it “yes, I’m me” then it’ll always be able to track you. The fact that you’re logging in with your identity at all seems to be negating all anti-tracking efforts.

      • eldavi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        yes, that seems to be the weak point that the server side tracking keeps leveraging successfully.

        every single anti-tracking practice and extension i use usually works for a while, but – inevitably – they become ineffective at some point and i’m learning that i can’t keep up with this perpetual cat-and-mouse game as i age.

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 day ago

            i don’t, but i’m glad i tried because i made me aware of how ineffectual my privacy practices and technology have become against meta or google or any other entity with virtually unlimited resources like meta.

            • ArcaneSlime@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              1
              ·
              1 day ago

              I mean, no matter how good your opsec is, you logging into your acct is handing them your identity on a silver platter. Like, you go to facebook using Tails with good opsec, the log in page doesn’t know who you are, but then you type “my@email.balls” and “hunter2” and it knows you’re either a hacker or you’re actually you, so they send you an email “blah blah been accessed from such and such IP/IMEI/etc” but unless you say “fuck no it wasn’t” then they’re like “alright, guess it’s him, add this to the list of tracking this guy’s shit.” It’s like, the guy at the liquor store doesn’t “know who you are” but then you pull out your ID and all of a sudden he does, “yeah, because you gave him your ID.”

              You’d need to create a new acct with fake details you haven’t previously used and a fresh email. Or just like, not sign in at all.

              • eldavi@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 day ago

                you misunderstand, i didn’t provide any email or password; it automatically let me log into the account without any credential challenge like i had an active cached session already.

                but it did send me an email saying that i logged in from an unknown location, so go figure.

                • ArcaneSlime@lemmy.dbzer0.com
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  21 hours ago

                  Ah, I see. Had you ever logged in with that device before? Even if you’d reset it, you can’t reset the IMEI number (and apparently there’s a similar tracker on windows).

        • ☂️-@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          tor is the simple answer. same fingerprint as everyone else, different IP every time.

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            i want to use tor 100% of the time, but it is SO SLOW and i’m too burger-ized to put up with it.

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 day ago

            this community has a reflexive habit of seizing on typos and minor imprecision for condescension sake. so i sometimes remember it and to tailor how i write as a result.

    • tumbling4986@lemmy.caOP
      link
      fedilink
      arrow-up
      8
      ·
      2 days ago

      I recommended Hardened Firefox.

      What do you mean by “Firefox lets you get tracked on the server side”? Use that Doh function with any DNS I recommend, like NextDNS, ControlD, or AdGuard, to prevent tracking via the server side. Also, you can use a VPN to hide your IP.

      You use container tabs and private tabs, so how are Facebook and Google going to collect your data? A Firefox container means the entire Google login is limited inside that container only; it has no access to outside what happens. At the same time, you have to use a UBlock Origin or any other content blocker to block other types of tracking scripts outside that container.

      About fingerprinting. You can tweak the config to make your Firefox more resistant to browser fingerprinting or consider using user scripts like Arkenfox, Better Fox, or Phoenix. There are also preconfigured browsers like LibreWolf and Mullvad Browser available if you are okay with constant breaking of functionality on websites. If none of this is enough, there is tor browser.

      • eldavi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        you misunderstand me – firefox is helpful in this respect, but there’s only so much it can do.

        and i engage in anti-tracking practices and extensions when i learn of them and the point of my comment is that the the developers on the server side inevitably keep finding ways to circumvent each iteration eventually.

        i’ll always continue to do my best, but it’s clear they’re the better supplied side in this arms race

        • tumbling4986@lemmy.caOP
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          Actually the implementation of tracking methods and data collection is much more easier than implementing methods to prevent them.

          Can you please point out which service you specifically talking about?

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            1 day ago

            i suspected that @spectre@hexbear.net was up to no good. lol

            edit: whoops, wrong post. lol

            to answer your question: my comment was spurred on my instagram recognizing who i was on a device that i had never used before, on a sim/phone plan that i had never used before, using firefox in private mode.

            i’m best guess so far is that some sort of 3rd party tracker was part of a different service that i had used the device earlier in the day clued in instagram into who i was.

  • leanleft@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    LLM answer:

    
    - Tracking Pixels and Web Beacons
    - Email-Open Tracking
    - Email Link-Click Tracking
    - Advertising Impression Tracking
    - Conversion Tracking
    - Social-Media Pixels
    - Analytics Tags and Tag Managers
    
    - IP Address and Network Tracking
    - IP-Based Geolocation
    - ISP, ASN, and Organization Identification
    - Household and Network-Level Matching
    - VPN, Proxy, and Tor Detection
    - Network Reputation and Fraud Scoring
    
    - URL and Referral Tracking
    - UTM Parameter Tracking
    - Advertising Click-ID Tracking
    - Affiliate and Referral-ID Tracking
    - Email Campaign-ID Tracking
    - Link Decoration
    - Redirect-Chain Tracking
    - Cross-Site Identifier Propagation
    - HTTP Referer Header Tracking
    
    - HTTP Header and Cache Tracking
    - User-Agent Tracking
    - Client Hints Tracking
    - Accept-Language Tracking
    - ETag Tracking
    - Cache-Control and Last-Modified Tracking
    
    - Browser Storage Tracking
    - First-Party Cookies
    - Third-Party Cookies
    - LocalStorage and SessionStorage Tracking
    - IndexedDB Tracking
    - Cache Storage Tracking
    - Shared Storage Tracking
    - Service-Worker Storage Tracking
    - Evercookies and Identifier Respawning
    - Supercookies
    - HSTS Supercookies
    - Favicon Cache Tracking
    - TLS Session-Resumption Tracking
    
    - Browser Fingerprinting
    - Browser, Version, and Operating-System Fingerprinting
    - Screen, Viewport, Color-Depth, and Device-Pixel-Ratio Fingerprinting
    - Time-Zone, Language, Locale, and Keyboard-Layout Fingerprinting
    - Installed-Font and Font-Rendering Fingerprinting
    - Canvas Fingerprinting
    - WebGL and WebGPU Fingerprinting
    - AudioContext Fingerprinting
    - GPU and Graphics-Driver Fingerprinting
    - CPU Core, Device-Memory, and Hardware-Concurrency Fingerprinting
    - Touchscreen, Input, and Device-Capability Fingerprinting
    - Camera, Microphone, and Media-Device Fingerprinting
    - Browser Extension, Plugin, MIME-Type, and PDF-Viewer Fingerprinting
    - CSS Feature and Media-Query Fingerprinting
    - Browser API Availability Fingerprinting
    - WebRTC and Local-IP Exposure
    - Network Information API Fingerprinting
    - TLS, JA3, and JA4 Fingerprinting
    - HTTP/2 and HTTP/3 Protocol Fingerprinting
    - DNS Resolver Fingerprinting
    - Clock-Skew and Performance-Timing Fingerprinting
    - Sensor Fingerprinting
    - Motion, Orientation, and Ambient-Light Sensor Fingerprinting
    - Speech-Synthesis Voice Fingerprinting
    - Emoji and Text-Rendering Fingerprinting
    - Math, Floating-Point, Error, and Exception Fingerprinting
    - Browser Automation and Bot-Detection Fingerprinting
    - Combined and Probabilistic Fingerprinting
    
    - Account and Login-State Tracking
    - Logged-In Account Tracking
    - Login-State Detection
    - Single Sign-On Tracking
    - OAuth and Social-Login Tracking
    - Embedded Social-Widget Tracking
    - Account-Recovery Identifier Matching
    
    - Cross-Device and Identity-Graph Tracking
    - Login-Based Device Linking
    - Hashed Email and Phone-Number Matching
    - Probabilistic Device Matching
    - Data-Broker Identity Resolution
    - Offline-to-Online Data Matching
    - CRM and Customer-Data Matching
    
    - Server-Side Tracking
    - Server-Side Analytics
    - Server-Side Tag Management
    - Server-to-Server Event Tracking
    - Advertising Conversion APIs
    - Purchase, Order, and Lead-Event Sharing
    
    - Behavioral Analytics and Session Replay
    - Mouse-Movement Tracking
    - Scroll-Depth Tracking
    - Click and Hover Tracking
    - Keystroke and Form-Interaction Tracking
    - Heatmap Tracking
    - Rage-Click Detection
    - Dwell-Time and Engagement Tracking
    - Form-Abandonment Tracking
    
    - Push-Notification Tracking
    - Web Push Subscription Identifiers
    - Mobile Push Tokens
    - Notification Engagement Tracking
    
    - Mobile-App Tracking
    - Mobile Advertising IDs
    - App Instance and SDK Identifiers
    - App-Install Attribution
    - Deep-Link Tracking
    - Mobile Device Fingerprinting
    - Mobile Location Tracking
    
    - Location Tracking
    - GPS Location
    - Wi-Fi Network Location
    - Bluetooth Beacon Location
    - Cell-Tower Location
    - Nearby Device and Network Discovery
    
    - Embedded Third-Party Content Tracking
    - Embedded Video Tracking
    - Embedded Map Tracking
    - Comment-Widget Tracking
    - Payment-Widget Tracking
    - CAPTCHA and Anti-Bot Widget Tracking
    - Third-Party JavaScript Tracking
    
    - DNS and Domain Cloaking
    - CNAME Cloaking
    - First-Party Subdomain Tracking
    - Domain Alias Tracking
    - DNS Query Tracking
    - DNS Prefetch Tracking
    
    - Advertising and Attribution Tracking
    - Real-Time Bidding Tracking
    - Ad-Exchange and Demand-Side Platform Identifiers
    - Retargeting and Remarketing
    - Frequency-Capping Identifiers
    - View-Through Attribution
    - Multi-Touch Attribution
    
    
    • Mikelius@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      Note that it doesn’t prevent sso sharing. I was signed into Amazon and a separate Firefox (actually librewolf) tab I had opened looking up a movie star on… IMDb force created an account for me using my Amazon account. No I did not get a prompt to accept it and no I did not click anywhere near the login buttons. Seen that this has happened to a few people but not everyone so it’s almost like they’re slow rolling it.

      I’ve since isolated Amazon into its own profile altogether and added Amazon to unlock on my main browser profile. And of course requested deletion of my sudden imdb account