this post was submitted on 02 Apr 2025
864 points (97.4% liked)

Technology

68567 readers
3546 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

It garbles advertisers' data as a result, but you must disable uBlock Origin to run it; they can't work simultaneously. I recently moved to it and, so far, am never looking back!

you are viewing a single comment's thread
view the rest of the comments
[–] morphballganon@mtgzone.com 35 points 1 week ago (2 children)

Good start. Now make a version that clicks each ad a random number of times from randomly generated IP addresses.

[–] Tja@programming.dev 63 points 1 week ago (7 children)

That's not how IP addresses work.

[–] Landless2029@lemmy.world 3 points 6 days ago (1 children)

It does if it reports the URL to click home somewhere and users can opt in to pull the list to auto click.

It would DDoS the ad servers. Muwhahahaa

[–] theherk@lemmy.world 7 points 6 days ago (1 children)

Yes. That’s just what I want. An extension sending all ads served to me to a central location, so my fingerprint can be very easily indexed and stored on a definitely never hacked, leaked, or sold database.

[–] Landless2029@lemmy.world 2 points 6 days ago

And it would totally never get abused or hit a false positive.

[–] FiskFisk33@startrek.website 2 points 6 days ago* (last edited 6 days ago)

Totally doable if this was a distributed service.

ok not randomly generated, but you know

[–] yarr@feddit.nl 24 points 1 week ago (2 children)

What if we use a Visual Basic UI to hack the IP address by netmask?

[–] GenosseFlosse@feddit.org 10 points 1 week ago (1 children)

Yes, but this only works if you connect your VPN via 3 block chain proxies.

[–] madcaesar@lemmy.world 4 points 6 days ago

Make sure you're behind a 54mghz ram modem firewall

[–] umbrella@lemmy.ml 15 points 1 week ago (2 children)

maybe we can setup a botnet to poison advertiser data.

click all the ads, all over the planet!

[–] randamumaki@lemmy.blahaj.zone 6 points 1 week ago

Feed it SQL injections?

[–] Evil_incarnate@lemm.ee 11 points 1 week ago (2 children)

Have it form connections to all the other browsers using the extension and they all send a click.

[–] Lifter@discuss.tchncs.de 1 points 1 week ago

It just changes the user agent instead...

[–] pebbles@sh.itjust.works 4 points 1 week ago* (last edited 1 week ago) (2 children)

You can fake your IP. There isnt really any authentication at the IP level. Just make a packet and overwite the IP field.

Edit: I was corrected. The TCP handshake requires you to have a valid IP you can respond from. So even though you can fake your IP, you can't use that to talk to most websites.

[–] Tja@programming.dev 18 points 1 week ago (1 children)

You need a TCP handshake prior to sending any http payload.

[–] pebbles@sh.itjust.works 6 points 1 week ago

Oh yeah. Forgot about that.

[–] ILikeBoobies@lemmy.ca 4 points 1 week ago (1 children)

Nothing is random

In bot cases like this you would have a proxy list that it “randomly” picks from

[–] GenosseFlosse@feddit.org 18 points 1 week ago (1 children)

Ad Networks use browser fingerprinting to detect duplicate clicks, which is tied to your hardware, system locale, installed fonts etc.

[–] morphballganon@mtgzone.com 19 points 1 week ago (2 children)

Sounds like a solvable problem

[–] viking@infosec.pub 26 points 1 week ago

Chameleon add-on for Firefox, randomly rotates your browser, OS, screen size, timezone, device type, language, and other customizable parameters every x minutes.

I've set it to do so every 5 minutes, and to omit desktop & tablet as device types (else some websites display the respective page) and timezones (messed up 2FA).

I also disabled blackberry and windows phone from the manufacturer ID, that would have the opposite effect from obscuring me.

For the rest of it, it's working great.

[–] Psythik@lemm.ee 5 points 1 week ago (3 children)

Tell me how, then, because I don't know how to get around the font thing. Everybody's computer has a different set of fonts, and blocking browsers from seeing what fonts you have installed would help identify you even more.

[–] morphballganon@mtgzone.com 12 points 1 week ago

A browser extension that limits webpages to default Windows fonts only would eliminate that factor from contributing to identification without flagging it as suspicious. A slightly more robust version could frequently cycle between multiple subsets of default Windows fonts. Say Windows comes with 100 fonts. So you could have thousands of configurations with different subsets of those.

[–] bss03@infosec.pub 4 points 1 week ago (1 children)

"Just" remove a random 2.5% of the fonts, a different random set per request (context).

[–] FauxLiving@lemmy.world 4 points 6 days ago (2 children)

Just have everyone agree on a set of fonts to report and report those.

[–] morphballganon@mtgzone.com 2 points 6 days ago

That would solve the anonymity problem but not the "obscure when requests are duplicates" problem

[–] bss03@infosec.pub 1 points 5 days ago

I think that reveals you aren't a "normal" request. Since "normal" user requests don't have that exact list of fonts. I'm anonymous, but aberrant.

[–] Cryophilia@lemmy.world 3 points 1 week ago (1 children)

That one browser which everyone hates despite it being the best adblocker and anti-surveillance browser out there randomizes your fingerprint.