top 50 comments

sorted by: hot top controversial new old
[–] 37 points 2 weeks ago (2 children)

What it got right,

  • My OS. It's in the user agent header, which I hate.
  • I read the page methodically at a human reading pace.
  • I am using a VPN.

What it got wrong,

  • Location.
  • Screen res.
  • Num of CPU cores.

It's good for ppl to think about fingeprinting. So demo pages like this are good. But I'm sure the identity resolution industry is MUCH better at it. They have capabilities like TLS fingerprinting, outside the browser. For most ppl, not the privacy crowd so mcuh but normal ppl, they fingerprint resource fetches to diff geographic servers. They can run 100's of scripts on a single page from every identity broker. They employ the best data scientists, to figure out every possible way.

I'm pretty careful. More than 99.999% will ever do. Can commercial fingerprinters still ID me? IDK. But like Skywalker, I have a bad feeling about it.

  • source
  • hideshow 4 child comments
  • [–] 5 points 2 weeks ago (3 children)

    They can run 100’s of scripts on a single page from every identity broker. They employ the best data scientists, to figure out every possible way.

    The impact of this is probably greatly reduced by anti-JS measures like NoScript. Some sites probably still bundle fingerprinting code into their own scripts, but the really big players contract that out to companies whose entire purpose is data-harvesting, and that's easily defeated by denying scripts from outside domains

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 1 week ago (1 child)

    the really big players contract that out to companies whose entire purpose is data-harvesting

    For sure, blocking those scripts goes a LONG way. But that'll only work until lots of ppl do it. If it ever catches on big, the Identity Brokers will adapt. They'll integrate their shit into sites in ways that are hard or impossible to separate this easily without totally breaking the site you were trying to visit.

    IDK for sure, but I fear we could be living on borrowed time.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (2 replies)
  • [–] 19 points 2 weeks ago (1 child)
  • [–] 7 points 2 weeks ago (3 children)

    Honest question, do you browse without JS enabled? I suppose you could just whitelist sites that you need it for.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 14 points 2 weeks ago* (1 child)

    Some folks browse using Tor or other high-privacy respecting browsers, in which things like NoScript are a default.

    Anyway, yeah, NoScript is still pretty popular and if I recall correctly you can whitelist and regex with it. I just use the same functionality to disable javascript that is in uBlock Origin, personally.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 weeks ago

    On my computers I enable js only for the url I connect to, and then if nothing works, I start enabling it for other urls or skip using the site.

    You get pretty handy with it pretty soon.

    I've used ublock for like +10 years if not more

  • source
  • parent
  • [–] 18 points 2 weeks ago (2 children)

    I loaded the site and went through the stuff and it worked fine. Then I turned on my VPN, and it gave me a new ID.

    Changing my VPN endpoint and refreshing the page didn’t work, it still knew who I was, but closing the window and quitting the browser before changing the VPN again gave me a third ID.

    They seem to know quite a bit about my phone, but it doesn’t seem like there is much that it could differentiate it from another person with the same model of phone.

    This was a fun exercise.

  • source
  • hideshow 4 child comments
  • [–] 4 points 2 weeks ago* (last edited 2 weeks ago)

    It's interesting to me because while it's mostly correct in each instance I tried it (phone, desktop) it actually gets some pertinent information incorrect.

    For one, it only recognized the one monitor I had the browser open on, I have four monitors, so it got the resolution correct for a single monitor, but fails to capture the others, and so technically if I opened it on a different monitor with a different resolution (I had two that have different resolutions), that aspect of the fingerprint should change.

    Secondly, when I went to this link from my cell phone it registered it as me typing the link in by hand while on PC it correctly registered where the link originated from (here on lemmy). Although I was using Jerboa on Android so perhaps it can't read link origin from Jerboa (which is good).

    Finally, it registers my Wayland session as X11, although I'm not sure if that's a current limitation of browsers since Wayland isn't the dominant compositor yet and perhaps hasn't been added to browser user-agent info yet.

  • source
  • parent
  • [–] 12 points 2 weeks ago (2 children)

    Interesting. The only thing that really surprised me was the time zone thing. Can I hide that somehow?

  • source
  • hideshow 4 child comments
  • [–] 2 points 2 weeks ago

    I know IronFox and some other forks have a setting to change your timezone to UTC-0. But you'll have to live with remembering to convert time on most websites unless you log in and your profile sets the timezone. Not a huge deal, but it trips me up more than I'd like to admit. Especially since I avoid sites that require logins. I have heard that you can get a browser plugin to change the time locally, but you'd have to trust the plugin since it will need access to all content on all sites.

  • source
  • parent
  • [–] 8 points 2 weeks ago (1 child)

    A small point but it assumes that your browser's self-declared timezone is "true" to where you live. My timezone is spoofed to UTC+0; my VPN server is in a different country; and my browser language is set to en-us. I feel like if you see a user whose settings are all of the above then you can assume that none of those three data points actually describe the user, unless they coincidentally are a US English speaker or live in UTC+0, but that'd just be them coincidentally living where anti-fingerprinting browsers report you as.

  • source
  • hideshow 2 child comments
  • [–] 12 points 2 weeks ago (2 children)

    Anti-fingerprinting is a fingerprint too.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 2 points 2 weeks ago (1 child)

    I know that...? I'm not sure how this relates to the comment you replied to.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 weeks ago (1 child)

    they are just warning other readers who might read your comment and think "oh I should spoof timezone and language too". To those readers: don't spoof these yourself, find a browser that has fingerprint resistance on by default, like Tor or Mullvad Browser, and don't change the defaults. The goal is to blend into a crowd of users with the same fingerprint

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • Ironfox seems to do its job. Me fingerprint every time. Vanadium as well (though it does disclose more in-depth device data).

  • source
  • [–] 7 points 2 weeks ago (1 child)

    I mean "1 in 122.7 million browsers look like" mine meaning it got me down to one out of about 2% of all internet users globally. I'd say it's still pretty difficult to target anything at that many people and have it be relevant. Just knowing my location and that it's a weekend basically gets down to that many or maybe fewer people on it's own since fewer than that live in my city permanently, and adding tourists/visitors and people who work on weekends, that might be about right for how many devices are online in my city right now. And that was browsing with my less locked down browser on my phone.

    Actually, looking with ironfox, though, actually reduced that to about 112m. I think part of that is that ironfox apparently still seems to enable the "do not track flag" even though it was removed from Firefox because it actually made people more easy to track and no sites who track are ethical so they are not going to obey something like that. So now it's rare and makes for a really good tracking point. Need to figure out how to remove it from ironfox I guess.

  • source
  • hideshow 2 child comments
  • [–] 6 points 2 weeks ago* (last edited 2 weeks ago) (3 children)

    So I tried this in *Privacy Browser, mojeek search engine, with and without .js. Thing is, most websites are designed not to work, without it. I could use some help with settings, if anyone is inclined.

    Also, that made my fingerprint much more unique. It almost seems worse.

  • source
  • hideshow 5 child comments
  • [–] [S] 5 points 2 weeks ago (1 child)

    yeah turning off js means that you can't really use most sites

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 weeks ago (6 children)

    Having a unique fingerprint I swear is just a way to scare people into compliance. Unique doesn't always mean known. Sure, it's unique that they can't track you so well. Oh no...

    I feel if 1 out of 200 people had this unique fingerprint, it'd be hard to distinguish who's actually who. No distinct way to really differentiate with such little data being allowed to be gathered.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 5 points 2 weeks ago (1 child)

    The paradox is that your traffic is so unique that it can be compared to traffic captured from other websites you've visited and be used to build a profile around your commonly visited websites and current interests.

    That fingerprint is then sold to brokers that forward to websites that will serve targeted content to your fingerprint when you do happen to show up. It doesn't necessarily care what your identity is just that you have an identity.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 2 weeks ago (1 child)

    But if you're not running multiple tabs, or in private tab view, and you're not allowing most or any cookies, then they're going to have a harder time following what you do and where you go.

    1. Use a solid VPN
    2. Use Firefox derivative (Waterfox and Libre Wolf, feel free to use multiple to separate tracking)
    3. Use pivate tab mode
    4. Use Privacy Badger (EFF)
    5. Use Port Authority (highly rated port scan blocker to block network port scanning from LexisNexis)
    6. Close unused tabs
    7. Clear cache and cookies on exit
    8. Disable unused network stuff (WiFi and/or data, GPS, BT, NFC, anything that's not required that could be used for location scanning)
    9. On Android 15+ iirc, disabled mic and/or camera permissions until necessary. Most people don't talk on the phone anymore so it's rare you need the mic (unblock for camera)
  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 weeks ago*

    One out of 119k.

    Edit: but yes, I am satisfied. I just need to know how to do settings so .js IS enabled but also not so evil (and I doubt it's possible), as well as just general functionality with privacy, if that's even possible.

  • source
  • parent
  • load more comments (4 replies)
  • load more comments (1 reply)
    [–] 6 points 1 week ago

    This is quite revealing and impressive. But it’s also annoying when people don’t offer any preventative measures.

  • source
  • [–] 5 points 1 week ago* (last edited 1 week ago) (1 child)

    On my Android, Brave gave a different fingerprint both times I visited.

    The site thinks both times was my first visit.

    The site believes I have either a 4 core or 2 core cpu. I have an Octa-core.

    Also, it shows a different display size both times.

    Nearly all sites like this can do nothing without javascript turned on.

    I'm curious to see how Librewolf is, but that will wait until after work.

    Edit: Librewolf does indeed produce a different fingerprint each time. It also didn't give up my location like Brave did on my GrapheneOS phone.

    I have since changed the timezone on my phone to a country to the South within the same timezone so the clock remains accurate.

  • source
  • hideshow 2 child comments
  • [–] 5 points 2 weeks ago (3 children)

    Today all websites that have anti bot protection using pow (proof of work) already use cookies. Which is before they "ask you if you want to agree with cookies" haha. Dammit eu rules.

  • source
  • hideshow 5 child comments
  • [–] 8 points 2 weeks ago (1 child)

    ya the cookie law is outdated and short sighted, the law should instead extend to ability to consent to send any identifying information instead. (Easier to investigate and potentially punish websites that do not respect the setting)

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 1 week ago (1 child)

    A website doesn't need to ask you for consent if the cookie is "strictly necessary". I'm not sure how those anti bot protections work, but I bet they made it fit the definition of a "strictly necessary" cookie.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 1 week ago

    I know. I don't want those stupid cookie banners. Hence my "dammit eu rules".

    I created my own anti bot protection see https://angieguardian.org/. So basically all of them use cookies after you completed a pow or captcha. So next time you load the page it doesn't ask you again. Those cookies may expire within several hours until 1 week depending how the server/anti bot software configure them.

  • source
  • parent
  • load more comments (1 reply)
    [–] 4 points 2 weeks ago (2 children)

    "Remember me on this device"

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 4 points 1 week ago (1 child)

    Cool site, but breaks when you disable JavaScript. I wonder if you could trick it into thinking you're a bot.

  • source
  • hideshow 2 child comments
  • [–] 3 points 1 week ago

    Amazing and terrifying. Thanks for the link. I am not very technical when it comes to the web so this was eye opening.

    I used to have a small Firefox extension that would stagger my key presses to muddy the waters, but it made typing impractical, so I eventually removed it.

    I wonder what else I can do on my end. And most importantly, what browsers can do for all their users, technical and not, by default.

  • source
  • load more comments
    view more: next ›