i have an issue where google tracks me even using very private browsers and linux distros like tails and qubes and anti fingerprint

someone said it might be because of framework

how do i fix (is there a cheap option i dont care about inconveince or spending a lot of time it just has to work)

  • SteveTech@aussie.zone
    link
    fedilink
    arrow-up
    14
    ·
    2 days ago

    i have an issue where google tracks me

    How did you confirm that?

    My immediate thought is they’re just tracking your IP address, though Tor should’ve mitigated that I believe.

    I don’t see how a Framework laptop would be any different to any other.

    You can try some fingerprinting tests, and see what they find: https://coveryourtracks.eff.org/

    • lemmingsareawesome@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      3
      ·
      2 days ago

      invidious (private frontend for youtube) shows me videos related to things i watched before even if i delete my cookies/cache/use a new idenity. i tested it to be sure by watching videos i didnt care about. got recommeded the exact same channel and still have been getting it even on other devices that i didnt use but google knows theyre mine (normal guy ios with safari) ive tried anti fingerprinting stuff the websites say im generic but i look at invidious and nothing has improved (i dont log in to invidious or youtube)

      someone said framework had a backdoor (i didnt confirm) and ive tried to be private but nothing else is working so its one of the last things i can try

      thanks for the comment it boosts this post

      • rhymepurple@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        Invidious is more private than using YouTube directly or even most other 3rd party services, but it may not completely prevent Google from tracking you depending on it’s hosting, configuration, and usage.

        • Are you running the Invidious instance yourself?
          • If so, are you running it on a VPN?
        • Are you the only user on this Invidious instance?
        • Is Invidious proxying all activity?
        • Is the Invidious instance outdated, customized, or noticeably different from most other instances?
        • Do you click on links from comments or video descriptions?
        • Do you first obtain YouTube links or video IDs and then convert them to an Invidious link?
        • Are you watching videos with little traffic or videos that are private?

        There is also the possibility that Invidious makes the recommendations itself, independently of YouTube. Clearing Invidious cookies and all site data should mitigate this, but if you are signing into Invidious then doing that won’t accomplish much.

        Additionally, Invidious may make the recommendations based on all its users’ activity. If you’re using an instance with little activity then the recommendations may be more heavily skewed to your activity. There’s also the possibility that other users of your Invidous instance share interests with you.

        Lastly, it is also possible that YouTube’s recommendations are based on unrelated factors.

        • YouTube may be recommending videos because they are genuinely popular or are trending in your area.
        • YouTube may be recommending videos based on other users’ YouTube activity on your IP address.
        • YouTube may be recommending videos based on other internet traffic YouTube/Google/Alphabet has associated with your account, fingerprint, or IP address.

        All of this, including several other possibilities not mentioned, is far more likely than Framework shipping a hardware/firmware backdoor that hasn’t been caught yet which allows Framework to monitor your Invidious acitivity so Framework can sell/share your data back to YouTube. This is a very niche use case that would be extremely expensive, difficult, and risky for Framework (or any other computer manufacturer) to accomplish. Any money Framework makes from this would likely not even cover the cost to do this.

        The Framework “backdoor” that you heard about is likely the data breach that recently impacted Framework. This data breach occurred due to a phishing attack on an employee of the accounting firm contracted by Framework.

        • lemmingsareawesome@sh.itjust.worksOP
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          i use invidious offisical instances (trusted by invidious themselves) i clear all my site data and change my ip and tor should make my fingerprint generic

          thanks for clairfyign the backdoor issue though

          • rhymepurple@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            There are no “official” or “trusted” instances. The instances listed on Invidious’ site meet (or should meet) a certain set of criteria. Several of those items could be considered bare minimum for hosting any website over 10 years ago (eg: be served via https, must have a domain) or are about other availability metrics. I’m not saying you shouldn’t trust any of those instances, but just want to clarify that it doesn’t necessarily mean that the instances are endorsed or trusted by the Invidious team. Instead, it is just a directory of instances that meet some minimum criteria.

            I didn’t check all of the instances currently on the list, but instances that were previously on the list did not proxy all traffic from YouTube. Since this is not an requirement to be included on Invidious’ list of instances, I assume that there are likely one or more instance that is not proxying the YouTube traffic.

            If the traffic is not proxies, then your browser will interact directly with YouTube’s servers for some content (typically the actual video content). While this prevents you from interacting with YouTube’s frontend (and all the tracking that comes with that), it does not prevent YouTube from identifying which videos were served to your IP address, which parts of the video were requested, or other identifying information.

              • rhymepurple@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 days ago

                I assume you mean the settings within the instance (or more accurately, your session) of Invidious states that it proxies the activity. However, if you’re just referring to Invidious itself, this is a setting that can be enabled/disabled for the entire Invidious instance. The instance’s default setting could also be disabled even if the instance supports proxying. Regardless, you could verify Invidious is proxying everything by reviewing the networking tab of your browser’s developer tools to confirm that all traffic is with your Invidious instance.

                Given everything you said, it sounds like any recommendations you receive within Invidious is most likely due to the collective activity of all users on that Invidious instance. Additionally, any recommendations you receive directly on YouTube is likely from other information YouTube collected about you (not your Invidious activity).

                While I cannot definitely confirm that this has absolutely nothing to do with Framework, I cannot imagine anyone knowledgeable about this arguing in good faith that Framework is complicity and secretly acting to violate your privacy.

                • lemmingsareawesome@sh.itjust.worksOP
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  2 days ago

                  i dont believe framework is intentionally trying to violate my privacy. much less me very specifically.

                  if the recommendations are collective id imagine id see videos other people are interested in. Ill have to test this later on someone elses device

  • Hanrahan@slrpnk.net
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    perhaps via the MAC of the laptop and the Google AP you are using. Try hot spotting of your phone as test ?