Ghostery, Disconnect, FlashBlock, AdBlock, and in some browser profile: NoScript & RequestPolicy. I whitelist trusted sites.
The online ad ecosystem is out of control with surveillance: data collection, tracking, device fingerprinting, aggregation, de-anonymization, etc. (and data volumes).
To prevent those annoying widget buttons, use NoScript or Ghostery. Of course NoScript's white list method is more secure but I like Ghostery's blacklist approach more. It's tiresome to have to constantly click on NoScript to allow Javascript running
You don't need Disconnect if you're using Ghostery. I too was using Disconnect first, but Ghostery (at least the most recent version) does its job and then some.
Regardless of where you are, as long as you have wi-fi on and there's a wi-fi router nearby, even in the absence of street view cars or anything like that, all it takes is one person using a GPS-enabled device near you to geo-compromise your router (and in some cases, your wi-fi client devices). Apple, Google, and others use different databases, but if you are on a Mac, then any one person using GPS on iOS near your wi-fi access point has forever pinpointed it in Apple's databases, and when you use Mac OS X Location Services, it draws on Apple's MAC address-to-geolocation database. Similar for Android devices and Google. Or Microsoft devices and Windows.
Try this: turn off wi-fi on your computer and try again.
This is why I only use wi-fi when necessary, and also generally keep Location Services turned off on every device I own, unless I specifically need location.
This one of the reasons I like dynamic IP and change my IP address regularly. So my IP-geolocation location jumps all over my metro area on a regular basis.
Ghostery and Disconnect are essential privacy tools in Firefox, Safari, or Chrome. Also try ShareNot on Firefox, which is experimental, but has somewhat more extensive blocking coverage than Disconnect.
But more fundamental: don't log in unless you have to, log in only in private browsing windows or separate browsers from your other surfing, and also clear your cookies often to keep your not-logged-in browsing cleaner from a privacy perspective.
Just a note: Neither Ghostery or Disconnect work in Chrome, since Chrome doesn't have any kind of ability to block requests from being made. The experimental webRequest API should help with that, but it hasn't been released yet.
can you clarify? both ghostery and disconnect do install and run in chrome - i have them running now. are you saying that there is some particular functionality that they don't provide?
also, responding to the (grand) parent, someone else mentioned that flash cookies are cross-browser. so if fb uses those you need to also make sure that the fb browser doesn't have flash installed.
They both install and run, but they use beforeRequest and edit the page content. This works in theory, but in practice there is no guarantee that the script will be loaded into the page before the tracker assets are. The ghostery/disconnect addons succeed in blocking trackers sometimes, but not all. Ghostery handles it a bit better than Disconnect does, as it will actually tell you which trackers it was able to block and which it wasn't.
The experimental webRequest API will solve that by providing a synchronous way for scripts to deny/allow connections before any requests are made, but webRequest won't be made available to non-experimental addons for a few months at the minimum.
Another very useful addon in Firefox is the RequestPolicy plugin, which blocks requests to other sites. You have to explicitly allow a site to connect to Facebook or Google analytics.
The only downside is that it is sometimes a hassle on pages that integrate third-party payment solutions which often have a lot of redirects and off-site scripts and iframe content. But then, like in noScript, you can always allow all or some request types from a page permanently.
I use noscript, ghostery and requestpolicy, but so far, I haven't managed to integrate requestpolicy into my daily browsing (I have it set to 'allow all' with a few blacklisted sites) because it's too much effort to figure out exactly what is needed by every single website.
It's hard enough with noscript to randomly guess at what should be allowed for a given site. You take a guess, then slowly expand the number of temp permissions til the site eventually loads properly.
The online ad ecosystem is out of control with surveillance: data collection, tracking, device fingerprinting, aggregation, de-anonymization, etc. (and data volumes).
HTTP_DNT=1