2026-schramm-analyzing-societal-awareness
findings extracted from this paper
-
Fingerprinting acceptance averaged 3.90 for cybersecurity applications, 3.73 for law enforcement, and 3.00 for user experience on a 5-point scale (n=734); privacy-protective behaviors (Privacy Behavior Index, p<0.01) and prior use of Tor or Brave (p<0.01) were the strongest negative predictors of acceptance across all three domains. Privacy concern level (Westin Index) alone did not significantly predict fingerprinting awareness, whereas behavioral privacy practices did.
-
Across 734 participants, fingerprinting awareness (mean 2.4 on a 1–4 scale) was significantly lower than cookie awareness (mean 2.86), confirmed by Wilcoxon signed-rank test at p < 0.001. Only 22% of participants had used a privacy-focused browser (Tor or Brave), and the Spearman correlation between cookie and fingerprinting awareness was only ρ = 0.40, indicating that tracking-technology literacy does not transfer automatically between mechanisms.
-
Among 734 participants, 70.4% were categorized as Privacy Pragmatists willing to trade data for convenience, while only 25.9% were Privacy Fundamentalists; prior use of Tor or Brave (~22% of the sample) and a higher Privacy Behavior Index were the strongest positive predictors of fingerprinting awareness (p<0.01 each), while self-reported privacy concern alone had no significant relationship with awareness. The structural minority of Fundamentalists represents the population disposed to tolerate the usability costs of strong countermeasures.
-
Countermeasures against fingerprinting can paradoxically increase a user's identifiability when deployed by a small population: spoofing-introduced attribute inconsistencies and unusual configurations (e.g., Tor Browser's letterboxing applied to an uncommon monitor size) produce a rarer, higher-entropy fingerprint than baseline. This 'information paradox' means that countermeasure effectiveness is a property of the anonymity set size, not of individual tool configuration.
-
Brave's built-in strict fingerprinting protection was discontinued in January 2024 because of low adoption and frequent web breakages caused by restricting JavaScript APIs; browser vendors are broadly reluctant to implement robust built-in countermeasures for the same compatibility reason. Spoofing-based extensions (HTTP-header spoofers, Canvas Defender) offer only partial protection and can degrade site functionality through overlapping layouts, unreadable fonts, or bot misclassification.