• FineCoatMummy@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    26
    ·
    1 month ago

    What it got right,

    • My OS. It’s in the user agent header, which I hate.
    • I read the page methodically at a human reading pace.
    • I am using a VPN.

    What it got wrong,

    • Location.
    • Screen res.
    • Num of CPU cores.

    It’s good for ppl to think about fingeprinting. So demo pages like this are good. But I’m sure the identity resolution industry is MUCH better at it. They have capabilities like TLS fingerprinting, outside the browser. For most ppl, not the privacy crowd so mcuh but normal ppl, they fingerprint resource fetches to diff geographic servers. They can run 100’s of scripts on a single page from every identity broker. They employ the best data scientists, to figure out every possible way.

    I’m pretty careful. More than 99.999% will ever do. Can commercial fingerprinters still ID me? IDK. But like Skywalker, I have a bad feeling about it.

    • GaumBeist@lemmy.ml
      link
      fedilink
      arrow-up
      5
      ·
      1 month ago

      They can run 100’s of scripts on a single page from every identity broker. They employ the best data scientists, to figure out every possible way.

      The impact of this is probably greatly reduced by anti-JS measures like NoScript. Some sites probably still bundle fingerprinting code into their own scripts, but the really big players contract that out to companies whose entire purpose is data-harvesting, and that’s easily defeated by denying scripts from outside domains

      • FineCoatMummy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        the really big players contract that out to companies whose entire purpose is data-harvesting

        For sure, blocking those scripts goes a LONG way. But that’ll only work until lots of ppl do it. If it ever catches on big, the Identity Brokers will adapt. They’ll integrate their shit into sites in ways that are hard or impossible to separate this easily without totally breaking the site you were trying to visit.

        IDK for sure, but I fear we could be living on borrowed time.

        • GaumBeist@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          1 month ago

          As long as there’s an incentive to violate privacy, it will always be an arms race. The upside is that we’ll get better and keep adapting just as they do.

      • Daefsdeda@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        1 month ago

        I liked the idea of noscript but, it just wasn’t practical to adjust it to every site which scripts should run and which shouldn’t

        • GaumBeist@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          1 month ago

          Yeah, it definitely makes browsing a lot more hands-on, and the lack of cross-device syncing means that you’re constantly duplicating work. There’s probably a way to export settings and diff/patch and sync the settings files for each device, but I just haven’t bothered; seems like a lot of time investment to automate something that takes me seconds to do manually.

          On the other hand, there were two big shifts for me after I started using it. One was when I got the sites I use frequently all set up after a few weeks, it became a lot smoother sailing after that. The other was when I finally took the minute to find the setting to default (temporarily) allow, but only for the current domain (after like a year or two on default deny everything).

          It’s now rare that I visit sites where I feel like I’m missing out without the added scripts. The only times that has really changed is when everything started implementing anti-scraper measures, and sites along the high seas that have trouble streaming videos from other servers.

    • iglou@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      1 month ago

      It doesn’t really matter if they got it right or wrong, as long as it’s consistent. The goal isn’t to know your location, screen res, or cpu core count, it’s to track you across websites.

      • FineCoatMummy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Yah. I agree. Which is why I think, it is often better to randomize the fingerprint every time, than TBB’s approach. Tor is still good for the onion routing, ofc. But I’d like a semi random return on screen res, timezones, and w/e.

  • SmoothLiquidation@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    12
    ·
    1 month ago

    I loaded the site and went through the stuff and it worked fine. Then I turned on my VPN, and it gave me a new ID.

    Changing my VPN endpoint and refreshing the page didn’t work, it still knew who I was, but closing the window and quitting the browser before changing the VPN again gave me a third ID.

    They seem to know quite a bit about my phone, but it doesn’t seem like there is much that it could differentiate it from another person with the same model of phone.

    This was a fun exercise.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      1 month ago

      It’s interesting to me because while it’s mostly correct in each instance I tried it (phone, desktop) it actually gets some pertinent information incorrect.

      For one, it only recognized the one monitor I had the browser open on, I have four monitors, so it got the resolution correct for a single monitor, but fails to capture the others, and so technically if I opened it on a different monitor with a different resolution (I had two that have different resolutions), that aspect of the fingerprint should change.

      Secondly, when I went to this link from my cell phone it registered it as me typing the link in by hand while on PC it correctly registered where the link originated from (here on lemmy). Although I was using Jerboa on Android so perhaps it can’t read link origin from Jerboa (which is good).

      Finally, it registers my Wayland session as X11, although I’m not sure if that’s a current limitation of browsers since Wayland isn’t the dominant compositor yet and perhaps hasn’t been added to browser user-agent info yet.

  • communism@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    1 month ago

    A small point but it assumes that your browser’s self-declared timezone is “true” to where you live. My timezone is spoofed to UTC+0; my VPN server is in a different country; and my browser language is set to en-us. I feel like if you see a user whose settings are all of the above then you can assume that none of those three data points actually describe the user, unless they coincidentally are a US English speaker or live in UTC+0, but that’d just be them coincidentally living where anti-fingerprinting browsers report you as.

  • Maeve @lemmygrad.ml
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    1 month ago

    So I tried this in *Privacy Browser, mojeek search engine, with and without .js. Thing is, most websites are designed not to work, without it. I could use some help with settings, if anyone is inclined.

    Also, that made my fingerprint much more unique. It almost seems worse.

  • On my Android, Brave gave a different fingerprint both times I visited.

    The site thinks both times was my first visit.

    The site believes I have either a 4 core or 2 core cpu. I have an Octa-core.

    Also, it shows a different display size both times.

    Nearly all sites like this can do nothing without javascript turned on.

    I’m curious to see how Librewolf is, but that will wait until after work.

    Edit: Librewolf does indeed produce a different fingerprint each time. It also didn’t give up my location like Brave did on my GrapheneOS phone.

    I have since changed the timezone on my phone to a country to the South within the same timezone so the clock remains accurate.

    • graynk@discuss.tchncs.de
      link
      fedilink
      arrow-up
      4
      ·
      1 month ago

      Visited it with LibreWolf (javascript turned on). The only thing that it got right was that I am on Linux, that I have an x86 processor and that I have LaTeX fonts installed.

      I refreshed the page, the data shown was the same, but the fingerprint was different.

  • AstroLightz@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    1 month ago

    Cool site, but breaks when you disable JavaScript. I wonder if you could trick it into thinking you’re a bot.