I have written about finger printing before, it is quite a complex issue. It is good to raise awareness I suppose. This website does miss the mark a little bit in my opinion and is leaning a...
I have written about finger printing before, it is quite a complex issue. It is good to raise awareness I suppose. This website does miss the mark a little bit in my opinion and is leaning a little bit too much on the "spooky" part.
You came from tildes.net.
Seems spooky, but is normal referral behavior. Under normal circumstances is nice for websites to know where visitors are linked from.
Your User-Agent says Linux, but your installed fonts are Windows's. One of those is lying, and it isn't the fonts.
...
The User-Agent string is trivial to fake, so we corroborate it. Certain fonts only ship on certain operating systems, and yours are Windows's, not the Linux your User-Agent claims.
Yeah no, I just have windows fonts installed on my Linux machine.
You've got LaTeX's fonts installed. Academic papers, or a maths-heavy day job.
Not really, but okay ;)
First time here? I'll remember you now, no cookie required. Come back and I'll prove it.
Okay, sure
I've seen you before, you first showed up earlier today.
...
On your first visit I stored a random tag, not in a cookie, but across localStorage, IndexedDB, the Cache API and window.name at once. I never learned your name; I just recognised the tag, and counted.
So half of those are still "cookies" as far as I am concerned. I'd be more interested if they could recognize me without storing anything on my side as I can clear all of those.
I am not saying that fingerprinting is not a real thing. It very much is. I am just not really vibing with this specific websites overall presentation and conclusions.
It sounds like you're kind of missing the point: Like, I get it, the guy is overstepping a bit, but the point is that it's fingerprinting you, not that it's getting your information right. It...
It sounds like you're kind of missing the point:
PS: some of what you just read may be flat-out wrong. That helps less than you'd think, fingerprinting doesn't need to be accurate, it needs to be consistent. If your browser gets something wrong the same way on every site, the mistake itself becomes part of your fingerprint. And this is the hobbled, no-cookie version: a site that does set cookies can patch the bad guesses over time, and anywhere you log in or pay never had to guess at all.
Like, I get it, the guy is overstepping a bit, but the point is that it's fingerprinting you, not that it's getting your information right. It doesn't need to know that it was wrong; it just has to tell the servers what it read, and then it can combine that with what it gets from the same fingerprint on other sites.
And even if it's tracking the wrong person because it's coincidental that they have the same device, etc, ehh, you're clearly interested in similar things. That's good enough to figure out which ads to serve.
So it's not as spooky as the site makes it sound, but it's still something valuable to understand.
For sure :) I specifically mention awareness in one of my first sentences and also close with something similar. I just don't vibe with the presentation style myself. It is possible that the...
but it's still something valuable to understand.
For sure :) I specifically mention awareness in one of my first sentences and also close with something similar. I just don't vibe with the presentation style myself. It is possible that the spooky shocking approach is what helps in making some people more aware. I just don't entirely agree with that, even more so as it really is a complex issue where a bunch of stuff used for fingerprinting also genuinely is very useful for many other reasons.
So while I get what you mean by this, I've always felt that was an instant failure of the web to start with from a privacy boundary standpoint. Sooo much of "well this is standard" for the web has...
Under normal circumstances is nice for websites to know where visitors are linked from.
So while I get what you mean by this, I've always felt that was an instant failure of the web to start with from a privacy boundary standpoint. Sooo much of "well this is standard" for the web has been problematic over the years, and it generally takes some huge screwup/abuse before it becomes apparent that maybe it shouldn't have been.
I get why knowing where someone comes from has value to a developer, but it's got a lot more value to people who aren't likely to do anything you want with it.
I was more thinking about it from experience modding communities. Having a sudden influx of s specific type of users, specifically those acting in bad faith but also those having wildly different...
I was more thinking about it from experience modding communities. Having a sudden influx of s specific type of users, specifically those acting in bad faith but also those having wildly different expectations is made much easier to handle if you have an idea where they are coming from.
Knowing you are being brigaded helps you shape your response. Knowing that there is some misinformation next to a link also helps if you know where that is and you can ask a website owner to change it.
In the same sense, knowing why a specific static resource is eating up significantly more bandwidth is also helped by knowing where it might be linked or embeded. It also is afaik how hotlink protection works if I remember correctly.
To be clear, I do think that browsers these day provide too much information in general. But some of them have more overal value for various reasons than others and the linked website just throws them on one pile.
And while fingerprinting to an individual level is something I don't support for the majority of reasons (having dealth with trolls dedicated to circumventing bans they would be one exception) I honestly do believe the more general meta fingerprinting, as I hope I have clarified, are there for fairly good historical reasons.
As I said before, it is a complex issue. I don't support fingerprinting for advertising and data brokering reasons. But I do believe in giving website owners the tools to deal with what the internet can throw against them.
Overall cool site, but this particular statistical error bugs me. You can only get this result if you assume these groups aren't correlated, which they absolutely are. That's not to say the...
How rare that makes you
Each thing on its own is common. Watch how fast they multiply.
Overall cool site, but this particular statistical error bugs me. You can only get this result if you assume these groups aren't correlated, which they absolutely are.
That's not to say the premise of browser fingerprinting isn't real, it's just that their suggested uniqueness score is going to be off by a couple orders of magnitude.
Imagine how vague OS, browser, language, time zone, and screen resolution would be somewhere like China. You'd basically just be IDing everyone with the same phone.
Imagine how vague OS, browser, language, time zone, and screen resolution would be somewhere like China. You'd basically just be IDing everyone with the same phone.
On the other hand, consider things like the iphone. A particular iphone version provides huge swaths of users with identical hardware and software which makes fingerprinting significantly more...
On the other hand, consider things like the iphone. A particular iphone version provides huge swaths of users with identical hardware and software which makes fingerprinting significantly more challenging.
The reason browser fingerprinting is useful at all is that the primary use case (outside of fraud/bot prevention) is advertising targeting, which doesn't need to be anywhere near perfect to be profitable.
Though I was aware of most of this, the demonstration was really nicely put together. If you didn't know, it may make you feel paranoid, but it's not paranoia if they really are out to get you....
Though I was aware of most of this, the demonstration was really nicely put together. If you didn't know, it may make you feel paranoid, but it's not paranoia if they really are out to get you.
Thing is, for me, I don't know what alternatives I have except to just stay off the web.
I'm curious if anyone has used Mullvad browser on it yet, besides me? It seems like it's not the case because it said I was the first and second visit, and basically all the data Mullvad gives it...
I'm curious if anyone has used Mullvad browser on it yet, besides me? It seems like it's not the case because it said I was the first and second visit, and basically all the data Mullvad gives it is spoofed. I thought all Mullvad browsers were supposed to present the same spoofed details though to make it hard to track off unique fingerprints. As far as I know it's the only browser that intentionally is set up to make it more difficult to have unique fingerprints.
Even with my normal Firefox browser, not Mullvad, it didn't have all details so at least some of it was obscured, but almost surely it would have a unique fingerprint that in theory could track me across sites that share the information. To me that's the key element, even if Firefox obscures some of the info, if there's some browser fingerprint database that companies sell this data to, then they can still create a profile of sites I visit, interests etc.
Funny enough, visiting the site with a default TOR instance still read out my correct screen resolution. I thought the entire point of leaving the TOR browser window in it's default state and not...
Funny enough, visiting the site with a default TOR instance still read out my correct screen resolution. I thought the entire point of leaving the TOR browser window in it's default state and not moving/resizing it was to spoof screen resolution tracking? Everything else was as I expected it to be.
I honestly think that anything that exists to expand the domain of the browser sandbox is probably an API that shouldn't exist. The fact that a browser can access USB and serial devices, for...
I honestly think that anything that exists to expand the domain of the browser sandbox is probably an API that shouldn't exist. The fact that a browser can access USB and serial devices, for instance, is nifty and all that, but it's also another potential attack vector regardless of how many security mitigations get put into place, makes it harder to make a compatible browser if you are not riding on Chrome's coattails (further increasing Google's influence across the tech industry at the same time), and frankly are just unnecessary.
I'd be curious whether it's checking if http://localhost:5432 is reachable (the default postgresql port) or if it's actually doing more rigorous checks that it really is postgresql (and other...
I'd be curious whether it's checking if http://localhost:5432 is reachable (the default postgresql port) or if it's actually doing more rigorous checks that it really is postgresql (and other services?). And not just some other local server that happens to be running on port 5432.
When I went to the website it got quite a number of things flat out wrong.
At least on an iPhone, all it seems to have been to able to infer is that I’m on an iPhone. Luckily for them, iPhones are famously rare devices that very few people have.
Nice machine, by the way. an iPhone.
4 CPU cores that it admits to and a 1179×2556 display. All the bells and whistles.
Wasn't that extremely expensive?
Anyway. Let me show you the rest of what I already know about you.
WHAT YOU ARE USING
Your operating system is Macos.how?
Your CPU is ARM-family.how?
WHAT YOU ARE USING IT ON
You have a camera and a microphone attached.how?
WHAT YOU HAVE INSTALLED
Your system has 68 text-to-speech voices installed, the exact set is a strong fingerprint.how?
You have a payment card set up in Apple Pay on this device.how?
At least on an iPhone, all it seems to have been to able to infer is that I’m on an iPhone.
Luckily for them, iPhones are famously rare devices that very few people have.
I wonder if I should just build a "be an iphone" extension for Firefox with a whitelist button to disable it if I absolutely need to. Better to hide as something very common rather than become...
I wonder if I should just build a "be an iphone" extension for Firefox with a whitelist button to disable it if I absolutely need to. Better to hide as something very common rather than become fairly unique based on running various blockers etc.
I will note here that the directive which mandates "cookie banners" in the EU is technology neutral in this respect, despite people commonly referring to cookies specifically in the context of...
So we decline the cookie banners. We hunt for the reject all button. We feel a little safer.
I have some bad news.
Modern browsers don't really need the cookie anymore.
I will note here that the directive which mandates "cookie banners" in the EU is technology neutral in this respect, despite people commonly referring to cookies specifically in the context of GDPR. Insofar they comply with EU law, these banners concern the use of any information stored on the user's terminal.
(24) Terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users. The use of such devices should be allowed only for legitimate purposes, with the knowledge of the users concerned.
Got this, quite funny that the site only goes as far as reading user agent string before crashing. I have to look into obscuring CPU core count, didn't know browser leak that
Got this, quite funny that the site only goes as far as reading user agent string before crashing. I have to look into obscuring CPU core count, didn't know browser leak that
Something broke while reading you. Ironically, that's the private outcome.
TypeError: can't access property "length", e is undefined
The page got a whole lot of things wrong about my machine, but that tends to happen when you have every possible fingerprinting prevention technique turned on in Firefox, including the...
The page got a whole lot of things wrong about my machine, but that tends to happen when you have every possible fingerprinting prevention technique turned on in Firefox, including the experimental ones.
I'm not gonna be worried about this though. The only thing this reveals is that if someone really, really wants to track you, they can. Obscurity only works when there's sufficient disinterest, and that's not news. If we want greater privacy today, I don't think it'll happen by improving anti-fingerprinting tech — doing that without changing the incentives will probably just result in new fingerprinting techniques being developed.
(I also take little stock in this page because it was developed by someone who appears significantly too bought-in on AI, and I trust their work very little as a result. But that's secondary to the above.)
Tried it on both Vanadium/GrapheneOS and Safari/iOS. It got more out of me on Safari/iOS but on GOS, the biggest outlier in identification seems to be the do not track thing, as well as timezone...
Tried it on both Vanadium/GrapheneOS and Safari/iOS.
It got more out of me on Safari/iOS but on GOS, the biggest outlier in identification seems to be the do not track thing, as well as timezone information.
Or sure. I just found it funny that it even thought I was hunting and pecking. I'm somewhat curious what rhythm i have that triggered that, or if it's because i'm on a custom keyboard with some...
Or sure. I just found it funny that it even thought I was hunting and pecking. I'm somewhat curious what rhythm i have that triggered that, or if it's because i'm on a custom keyboard with some nonstandard keys.
It thought I was touch-typing, describing me as "steady and practised", even though I'm actually a hunt-and-pecker. (Really just a pecker at this point. I can type just fine on an unlabeled...
It thought I was touch-typing, describing me as "steady and practised", even though I'm actually a hunt-and-pecker. (Really just a pecker at this point. I can type just fine on an unlabeled keyboard.)
My speed's a lot lower than yours, though, at 79 wpm. I think it must be over-emphasizing rhythm (mine was 0.4) and under-emphasizing speed.
I tried this with a fairly stock Firefox and a fairly stock Chrome. I denied any extra permission popups. Unsurprisingly, Chrome gives away more, and more specifics. CPU: FF gave a family (X, or...
I tried this with a fairly stock Firefox and a fairly stock Chrome. I denied any extra permission popups.
Unsurprisingly, Chrome gives away more, and more specifics.
CPU: FF gave a family (X, or similar) while Chrome gave an exact model
Chrome included battery percent and that a second display was attached, while FF did not
FF Do Not Track was off, while Chrome was on
FF and Chrome reported a different number of text-to-speech voices, though both reported a lot.
Chrome provides "Idle Detection and Compute Pressure APIs" to detect when you've stopped touching your device, an API that apple and FF have explicitly declined because of the surveilance it enables.
Overall: FF 1 in 135.3 million | Chrome 1 in 146.8 million
No one likes tracking technology. No one likes registering an account at various sites. No one likes the forced age verification being foisted on various websites. What if we combine all these...
No one likes tracking technology. No one likes registering an account at various sites. No one likes the forced age verification being foisted on various websites. What if we combine all these things? Something horrible or something potentially amazing?
Imagine a site where your browser fingerprint along with your site interactions become your identity score for the things you post? It could be presented as the likelyhood of the author being the same as the author of other posts. Essentially you'd get a network of disparate posts with a degree of confidence that they were made by the same person/entity. You could weave in multiple fingerprinting techniques, various browser based JS checks, text analysis for style, interaction history (tracked client side and sever side with timings ought to be very unique).
I imagine this probably wouldn't be immune to age verification laws, but an accountless service seems like a nice possible use of this tech. I imagine stopping spam messages might be the hard problem here though.
Nice machine, by the way. a Linux box (of course it is). 8 CPU cores that it admits to and a 3440×1440 display. A perfectly capable setup. Anyway. Let me show you the rest of what I already know...
Nice machine, by the way. a Linux box (of course it is). 8 CPU cores that it admits to and a 3440×1440 display. A perfectly capable setup. Anyway. Let me show you the rest of what I already know about you. What you are using Your operating system is Windows. Your CPU is x86-family.
Heh.
Though it's correct about one thing (that I was already quite aware of): I'm easily identifiable due my "eccentric" customization.
I have written about finger printing before, it is quite a complex issue. It is good to raise awareness I suppose. This website does miss the mark a little bit in my opinion and is leaning a little bit too much on the "spooky" part.
Seems spooky, but is normal referral behavior. Under normal circumstances is nice for websites to know where visitors are linked from.
Yeah no, I just have windows fonts installed on my Linux machine.
Not really, but okay ;)
Okay, sure
So half of those are still "cookies" as far as I am concerned. I'd be more interested if they could recognize me without storing anything on my side as I can clear all of those.
I am not saying that fingerprinting is not a real thing. It very much is. I am just not really vibing with this specific websites overall presentation and conclusions.
It sounds like you're kind of missing the point:
Like, I get it, the guy is overstepping a bit, but the point is that it's fingerprinting you, not that it's getting your information right. It doesn't need to know that it was wrong; it just has to tell the servers what it read, and then it can combine that with what it gets from the same fingerprint on other sites.
And even if it's tracking the wrong person because it's coincidental that they have the same device, etc, ehh, you're clearly interested in similar things. That's good enough to figure out which ads to serve.
So it's not as spooky as the site makes it sound, but it's still something valuable to understand.
For sure :) I specifically mention awareness in one of my first sentences and also close with something similar. I just don't vibe with the presentation style myself. It is possible that the spooky shocking approach is what helps in making some people more aware. I just don't entirely agree with that, even more so as it really is a complex issue where a bunch of stuff used for fingerprinting also genuinely is very useful for many other reasons.
Possibly the reason you don't vibe with it is that the whole project, including most of the prose, is vibe generated.
So while I get what you mean by this, I've always felt that was an instant failure of the web to start with from a privacy boundary standpoint. Sooo much of "well this is standard" for the web has been problematic over the years, and it generally takes some huge screwup/abuse before it becomes apparent that maybe it shouldn't have been.
I get why knowing where someone comes from has value to a developer, but it's got a lot more value to people who aren't likely to do anything you want with it.
I was more thinking about it from experience modding communities. Having a sudden influx of s specific type of users, specifically those acting in bad faith but also those having wildly different expectations is made much easier to handle if you have an idea where they are coming from.
Knowing you are being brigaded helps you shape your response. Knowing that there is some misinformation next to a link also helps if you know where that is and you can ask a website owner to change it.
In the same sense, knowing why a specific static resource is eating up significantly more bandwidth is also helped by knowing where it might be linked or embeded. It also is afaik how hotlink protection works if I remember correctly.
To be clear, I do think that browsers these day provide too much information in general. But some of them have more overal value for various reasons than others and the linked website just throws them on one pile.
And while fingerprinting to an individual level is something I don't support for the majority of reasons (having dealth with trolls dedicated to circumventing bans they would be one exception) I honestly do believe the more general meta fingerprinting, as I hope I have clarified, are there for fairly good historical reasons.
As I said before, it is a complex issue. I don't support fingerprinting for advertising and data brokering reasons. But I do believe in giving website owners the tools to deal with what the internet can throw against them.
Overall cool site, but this particular statistical error bugs me. You can only get this result if you assume these groups aren't correlated, which they absolutely are.
That's not to say the premise of browser fingerprinting isn't real, it's just that their suggested uniqueness score is going to be off by a couple orders of magnitude.
Imagine how vague OS, browser, language, time zone, and screen resolution would be somewhere like China. You'd basically just be IDing everyone with the same phone.
You'd be surprised at how much you can do with that, and how much granularity there is in things like OS/Browser versions.
On the other hand, consider things like the iphone. A particular iphone version provides huge swaths of users with identical hardware and software which makes fingerprinting significantly more challenging.
The reason browser fingerprinting is useful at all is that the primary use case (outside of fraud/bot prevention) is advertising targeting, which doesn't need to be anywhere near perfect to be profitable.
Though I was aware of most of this, the demonstration was really nicely put together. If you didn't know, it may make you feel paranoid, but it's not paranoia if they really are out to get you.
Thing is, for me, I don't know what alternatives I have except to just stay off the web.
If you use Firefox, some of your data will be spoofed and slightly wrong, making you slightly less identifiable.
I'm curious if anyone has used Mullvad browser on it yet, besides me? It seems like it's not the case because it said I was the first and second visit, and basically all the data Mullvad gives it is spoofed. I thought all Mullvad browsers were supposed to present the same spoofed details though to make it hard to track off unique fingerprints. As far as I know it's the only browser that intentionally is set up to make it more difficult to have unique fingerprints.
Even with my normal Firefox browser, not Mullvad, it didn't have all details so at least some of it was obscured, but almost surely it would have a unique fingerprint that in theory could track me across sites that share the information. To me that's the key element, even if Firefox obscures some of the info, if there's some browser fingerprint database that companies sell this data to, then they can still create a profile of sites I visit, interests etc.
Funny enough, visiting the site with a default TOR instance still read out my correct screen resolution. I thought the entire point of leaving the TOR browser window in it's default state and not moving/resizing it was to spoof screen resolution tracking? Everything else was as I expected it to be.
"There's a PostgreSQL database running on your machine."
Holy shit.
The page checking your localhost address which expose this, same technique Facebook use to broadcast from app so it can track in browser in Android.
I'll take "APIs that shouldn't exist" for 1000 Alex.
I honestly think that anything that exists to expand the domain of the browser sandbox is probably an API that shouldn't exist. The fact that a browser can access USB and serial devices, for instance, is nifty and all that, but it's also another potential attack vector regardless of how many security mitigations get put into place, makes it harder to make a compatible browser if you are not riding on Chrome's coattails (further increasing Google's influence across the tech industry at the same time), and frankly are just unnecessary.
Platforms like MakeCode are super cool, but are also easily replaced with an open source QT app.
I'd be curious whether it's checking if
http://localhost:5432is reachable (the default postgresql port) or if it's actually doing more rigorous checks that it really is postgresql (and other services?). And not just some other local server that happens to be running on port 5432.When I went to the website it got quite a number of things flat out wrong.
I think the TCP handshake succeeds then errors.
Yeah this is an approach I didn't think about before. I wonder if jitter on the refusal would help obfuscate this?
At least on an iPhone, all it seems to have been to able to infer is that I’m on an iPhone.
Luckily for them, iPhones are famously rare devices that very few people have.
I wonder if I should just build a "be an iphone" extension for Firefox with a whitelist button to disable it if I absolutely need to. Better to hide as something very common rather than become fairly unique based on running various blockers etc.
Lol, it kind of negged me for having an android.
Maybe they have a bug?
Not bad. About 60% accurate. But I also take active measures and I left them on to see how good it would do.
I will note here that the directive which mandates "cookie banners" in the EU is technology neutral in this respect, despite people commonly referring to cookies specifically in the context of GDPR. Insofar they comply with EU law, these banners concern the use of any information stored on the user's terminal.
From the ePrivacy directive:
Got this, quite funny that the site only goes as far as reading user agent string before crashing. I have to look into obscuring CPU core count, didn't know browser leak that
Where can I submit my fingerprint to an ad auction for a few dollars and see my ad profile?
The page got a whole lot of things wrong about my machine, but that tends to happen when you have every possible fingerprinting prevention technique turned on in Firefox, including the experimental ones.
I'm not gonna be worried about this though. The only thing this reveals is that if someone really, really wants to track you, they can. Obscurity only works when there's sufficient disinterest, and that's not news. If we want greater privacy today, I don't think it'll happen by improving anti-fingerprinting tech — doing that without changing the incentives will probably just result in new fingerprinting techniques being developed.
(I also take little stock in this page because it was developed by someone who appears significantly too bought-in on AI, and I trust their work very little as a result. But that's secondary to the above.)
Tried it on both Vanadium/GrapheneOS and Safari/iOS.
It got more out of me on Safari/iOS but on GOS, the biggest outlier in identification seems to be the do not track thing, as well as timezone information.
Would like a noscript variant of the page, just to see how far it gets
I would love to see someone hunt and peck at 108.
To be fair, it was a catch-all written by (presumably) a comp sci student using an "or" statement.
Or sure. I just found it funny that it even thought I was hunting and pecking. I'm somewhat curious what rhythm i have that triggered that, or if it's because i'm on a custom keyboard with some nonstandard keys.
It said that for me as well, I tried it multiple times and every time it said I typed uneven and every time I was over 105wpm.
It thought I was touch-typing, describing me as "steady and practised", even though I'm actually a hunt-and-pecker. (Really just a pecker at this point. I can type just fine on an unlabeled keyboard.)
My speed's a lot lower than yours, though, at 79 wpm. I think it must be over-emphasizing rhythm (mine was 0.4) and under-emphasizing speed.
I tried this with a fairly stock Firefox and a fairly stock Chrome. I denied any extra permission popups.
Unsurprisingly, Chrome gives away more, and more specifics.
Overall: FF 1 in 135.3 million | Chrome 1 in 146.8 million
No one likes tracking technology. No one likes registering an account at various sites. No one likes the forced age verification being foisted on various websites. What if we combine all these things? Something horrible or something potentially amazing?
Imagine a site where your browser fingerprint along with your site interactions become your identity score for the things you post? It could be presented as the likelyhood of the author being the same as the author of other posts. Essentially you'd get a network of disparate posts with a degree of confidence that they were made by the same person/entity. You could weave in multiple fingerprinting techniques, various browser based JS checks, text analysis for style, interaction history (tracked client side and sever side with timings ought to be very unique).
I imagine this probably wouldn't be immune to age verification laws, but an accountless service seems like a nice possible use of this tech. I imagine stopping spam messages might be the hard problem here though.
Nice machine, by the way. a Linux box (of course it is). 8 CPU cores that it admits to and a 3440×1440 display. A perfectly capable setup. Anyway. Let me show you the rest of what I already know about you. What you are using Your operating system is Windows. Your CPU is x86-family.Heh.
Though it's correct about one thing (that I was already quite aware of): I'm easily identifiable due my "eccentric" customization.