21 ms·
Show HN: Your Social Media Fingerprint (maybe NSFW)
- denzil_correa 10y agoApparently. I am not logged into anything. I tried it on Opera (along with the internal ad blocker) and I'm not using Privacy Badger.
- thescriptkiddie 10y agoThis only works of you have third party cookies turned on. I'm not sure about Opera, but I'm pretty sure Firefox has them off by default.
- Tepix 10y agoFirefox has third party cookies enabled by default, PLUS they hide the setting so you have to search for it to disable it. I'm 100% sure that they designed it that way to please Google. The pull requests to change it were ignored. And then they claim to be your partner in keeping your privacy. AFAIK only Safari has 3rd party cookies disabled by default. There are only very few sites that require 3rd party cookies. I use none of them.
- thescriptkiddie 10y agoSorry I was wrong about Firefox, I must have reconfigured mine and forgotten about it. My point was that Privacy Badger alone won't prevent this attack, you have to disable 3rd party cookies.
- icebraining 10y agoI'm 100% sure that they designed it that way to please Google. And why would that be, if their deal with Google ended in 2014?
- bzbarsky 10y ago> AFAIK only Safari has 3rd party cookies disabled by default. Safari's "3rd party cookies disabled" behavior is not the same as the Firefox one. Firefox's blocks third-party cookies (though it's hard to tell whether it just blocks _setting_ or also blocks _sending). Safari does something where they send the in some cases, but I'm having a hard time determining which cases, possibly because they've changed behavior a few times. At one point they blocked third-party cookies, _unless_ the third-party site has previously been visited as a first-party site. What this meant in practice is that Safari wouldn't block third-party cookies for things like Facebook or Google that you probably have visited as a first party. At this point they _may_ be doing double-keying of cookies instead (top domain and third-party domain as key, not just the third-party domain). As I said, it's a bit hard to tell from the documentation out there, which is conflicting and contradictory, and I have no time right now to go read the source. And even then they might only be doing double-keying in the "never visited as first party" case... The point of all of which is, "blocking third party cookies" is not a well-defined thing and different browsers mean quite different things, with different web compat impact and site breakage, when they say they do it.
- fwn 10y agoKeep in mind that it doesn't show up the icons at all if you're using a content blocker and activated Fanboy’s Annoyance List. This is because the critical resource is named "/socialmedia-leak/socialmedia-leak.js".
- adregan 10y agoThanks. I just enabled Fanboy’s Annoyance List in ublock origin. I've haven't spent any time digging through that filter list, but I'm now interested. Any other recommendations or resources?
- fwn 10y agoPersonally I went with EasyList and local EasyList against ads, Fanboy’s Annoyance and Anti-ThirdpartySocial because social media integrations generally annoy me. EasyPrivacy and Fanboy’s Enhanced Tracking List for privacy as well as the Adblock Warning Removal List and this cool thing against the EU cookie failure: https://raw.githubusercontent.com/r4vi/block-the-eu-cookie-shit-list/master/filterlist.txt https://raw.githubusercontent.com/r4vi/block-the-eu-cookie-s... It's not very complete, though.
- Capira 10y agoRenamed it. Does it make any difference?
- 10y ago
- Scirra_Tom 10y agoVery good demonstration thank you. Some interesting (an unethical) potential marketing opportunities here. For example, at the bottom of articles only show share actions for social platforms they are logged into.
- amelius 10y agoNot logged in != doesn't have an account
- pbhjpbhj 10y agoFor sure, but logged in == does have an account.
- Scirra_Tom 10y agoSure, but if you identify they are logged into FB and Reddit, maybe only show those two options. If you can't determine they are logged into any service show them all.
- CoryG89 10y agoMaybe you just use it for prioritization. For example, if they are logged into Reddit and Twitter: show buttons for Reddit and Twitter, then just have a more button that opens a dialog with other supported services.
- pbhjpbhj 10y agoWhy is showing only pertinent share options unethical? Or is it the cross-site circumvention that you found unethical?
- Scirra_Tom 10y agoEthics are subjective, some people may find the fact you're identifying what websites the user is logged into creatively in this way unethical as it divulges what services the user uses without them necessarily consenting/realising you have access to this information.
- dorianm 10y agoSo, loading favicon.ico via a redirect-type parameter: <img onload="alert('logged in to fb')" onerror="alert('not logged in to fb')" src="https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Ffavicon.ico">
- fitzwatermellow 10y agoQuick fix: embed favicon in data-uri ;)
- TazeTSchnitzel 10y ago<meta rel=icon>!
- cs0 10y agoNice, so now by using this I have an NSFW site logged in my workplace's DNS log. Be careful if your employer checks such things.
- thisisandyok 10y agoThe one time I don't check the comments before reading the story...
- SaAtomic 10y agohuh. I didn't think of that.. that's kinda harsh.
- Infinitesimus 10y agoYep I also clicked first. It might need an "NSFW" tag in the title to warn other users. (Let's see how long it takes for Corporate IT to come yell at us)
- brazzledazzle 10y agoI get blocking it but I have to wonder about departments run like that. Do they really have nothing better to do?
- Declanomous 10y agoIt's the "see and be seen" method of working. Nobody knows you exist because everything is working? Better go yell at somebody. Everybody thinks you aren't working because something is broken? Better go yell at somebody.
- jschwartzi 10y agoWell, on the bright side I'll be able to see if our IT guy actually logs this stuff. It'll be fun explaining it.
- 10y ago
- rosalinekarr 10y agoThis 'fingerprint' changes as you login in and log out of various services, so it's not very reliable for uniquely identifying users. Regardless, it could still be used to profile you and then target content accordingly. For example, if you're logged into Hacker News, you're probably a programmer and you're probably more interested in an ad for web hosting than wedding dresses and visa versa for Pinterest.
- Capira 10y agoThis is a more irrevocable persistent fingerprint: http://ubercookie.robinlinus.com/ http://ubercookie.robinlinus.com/ :)
- K0nserv 10y agoI have uBlock Origin in 3rd party deny mode and privacy badger and it still detects me as logged in to HN, Reddit, Slack and Stack Overflow. EDIT: Following diegorbaquero's advice[0] solved it 0: https://news.ycombinator.com/item?id=12692485 https://news.ycombinator.com/item?id=12692485
- speps 10y agoI had that and enabled the "Fanboy Annoyance list" in uBlock Origin and now it says I'm on none of the platforms.
- fwn 10y agoKeep in mind that this is an accidental fix due to a suboptimal naming choice by the website author. A better solution would be to disable third-party cookies in your browser settings. Sending the do not track request generally increases the ability to fingerprint you, as adversaries tend to ignore its purpose anyway.
- diegorbaquero 10y agoIn Chrome: Settings > Privacy > Content Settings > Tick 'Block third-party cookies and site data' Also set 'Send a "Do Not Track" request with your browsing traffic' And install uBlock Origin, ofc.
- JasonSage 10y agoAt a minimum, though, please block third-party cookies and site data. I have pretty minimal customizations and plugins on browsers—very few plugins, no ad-blocking, no security or privacy enhancements. I've had third-party cookies blocked for a long time now and there aren't any sites or logins that break down with them disabled (that I've encountered). On the plus side, though, you don't have to worry about this crap. I'm logged into several of these sites and none of them show as leaked.
- zerognowl 10y agoKeep in mind, uBlock Origin does not block social media widgets by default, and you have to enable it in settings. Widgets like Facebook like buttons, and Tweet buttons have to be blocked manually.
- Retr0spectrum 10y agoPersonally, I don't set the DNT header. You have no way of knowing if any sites are actually going to comply, and it actually provides an extra datapoint to fingerprint you with.
- sp332 10y agoBut isn't it better to at least ask instead of not asking at all?
- Retr0spectrum 10y agoAs I said, simply asking for it will actually reduce your privacy for any service that doesn't comply, by making you more fingerprintable.
- sua_3000 10y agoCan someone explain how this is NSFW? Is it because it's scraping for logins which looks suspicious?
- maket 10y agoI'm guessing from other comments that it checks logins on a wide variety of sites, some of which may be NSFW. Some employers might not like you accessing NSFW sites.
- frederikvs 10y agocorrect, among others it checks youporn. For this check it needs send a request to that domain, which may get flagged in certain corporate IT systems.
- jacquesm 10y agoThat would be a pretty crappy check then. After all any webpage could embed that favicon.
- ghurtado 10y agoAny page could also embed anything else NSFW, such as actual porn videos. The assumption is that these sites are generally NSFW by association. What would you propose instead?
- jacquesm 10y agoIf a filter is set up to not just block access to but also flag based on something as trivial to embed as a URL one would hope the technology would be a little bit more involved than a single hit on a .ico file for a flag.
- ghurtado 10y agoA web filter / proxy does not have any way to tell whether any individual HTTP request was requested as a result of HTML embedding, bookmarking, user entry or clicking on a link.
- cha-cho 10y agoPretty compelling information. Two observations: 1) No LinkedIn. Are they on top of the problem? 2) I had fun results with the Epic Privacy Browser.
- Capira 10y agoCouldn't find a redirect on LinkedIn that redirects without prompting you to log in again... Can you?
- stanislavb 10y agoNice work!
- instakill 10y agoScary. Netflix is showing logged out though, whereas I'm actually still logged in.
- r3bl 10y agoYeah, it kind of shows conflicting results to me too. While it correctly identified me being logged into HN, Medium, and Amazon, it completely missed reddit, GitHub, Twitter, Facebook, etc. I'm assuming it missed them because of me running Privacy Badger, but I'm kind of negatively surprised that Privacy Badger failed to protect me from those three I mentioned.
- anon4711 10y agoAnother false negative: Pinterest.
- eriknstr 10y ago>You are logged in to: >No platform >(or you're using something like Privacy Badger) I'm using uMatrix and uBlock Origin :)
- CapitalistCartr 10y agoWell its good to see its partly wrong for me. It shows HN correctly, but also shows me logged in to Facebook and Tumblr, not correct. And not logged in to gmail, which I am. Still, its a dangerous flaw.
- posterboy 10y agoHow is being showed logged in any good when it's not true? Wasn't there also something about facebook creating accounts for people based on thier 3rd party promotion link ins and what not?
- Retr0spectrum 10y agoI would be interesting to keep track of how common each particular fingerprint is. It could potentially be used to identify an individual user.
- zerognowl 10y agoThis is why I use 'browser isolation', which is a way to separate different types of surfing activity into different buckets. Currently the best way to do this in Firefox is to create multiple profiles, or in Chrome, you can simply add a different user/persona. Having one profile, or even an entire dedicated browser just for Twitter/FB ensures the login is not spilled over into other sites. If you're surfing the web heavily, I would recommend spawning a new private window so cookies, and other artefacts are not bleeding into your session. It sounds like common sense, but many people have cookies and login information persisting for years at a time in their browsing sessions. The Mozilla Firefox team are planning to introduce a feature which makes compartmented surfing sessions a lot more user-friendly by separating sessions into tabs. Currently, the 'profiles' feature of Firefox is not user friendly and requires a bit of tinkering with the filesystem.
- spacemanmatt 10y agoI was horrified to find I'm logged in to FB with my 'common' cookie jar. At least that explains the recently increased accuracy of its targeted ads.
- to3m 10y agoI only ever log in to Facebook in private browsing mode.
- GirlsCanCode 10y agoFacebook is among the worst for stalking you. For the once a quarter I log into Facebook (mostly for an occasional friendly note to highschool/college friends from 30+ years ago), I use a private session. And I have a plugin that blocks facebook tracking.
- tankenmate 10y agoI only ever log into Facebook via a VPN to a remote VPS using a private window on a browser I don't use for anything else. And also... Chain OUTPUT (policy ACCEPT 6309 packets, 599K bytes) pkts bytes target prot opt in out source destination 330 19800 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 match-set block-facebook-ips dst reject-with icmp-port-unreachable I have an ipset that matches FB networks.
- amelius 10y agoShouldn't a browser not send cookies when the request comes from a different domain? That would seem like the most sensible solution to me. Unless somebody can show a caveat of course.
- deleted 10y ago[deleted]
- trendia 10y agoI believe that cross-site scripting [0] can be used to get around domain restrictions. [0] https://en.wikipedia.org/wiki/Cross-site_scripting https://en.wikipedia.org/wiki/Cross-site_scripting [1] (This is not my area of expertise. If I'm not correct... please let me know!)
- alexbecker 10y agoThat requires exploiting an XSS vulnerability in the target domain however. Such vulnerabilities are sadly common, but can be prevented.
- AgentME 10y agoNo, that's not really related. Cross-site scripting's name comes from the vulnerabilities which allow an attacker to insert a <script> tag pointing at a script on another domain (or an inline script). It doesn't have to do with cookies and doesn't get around or really interact with the "block 3rd party cookies" setting.
- luchs 10y agoThis is exactly what the "block third-party cookies" option does. It really should be enabled per default, possibly with a permission prompt for cases where they are useful. The interesting thing here is that third-party cookies usually allow a central site (e.g. an ad server) to track a user across many other sites. It's almost the other way around here: "other sites" can track status on a "central site".
- amelius 10y ago
- spacemanmatt 10y agoTIL YouPorn is considered social media
- pluma 10y agoI heard they have an active comment section.
- sliverstorm 10y agoI go there for the comments?
- pluma 10y agoIt's not YouPorn but there's this gem of a tumblr: http://pornhubcommentsonstockphotos.tumblr.com/ http://pornhubcommentsonstockphotos.tumblr.com/
- joshmanders 10y agoYou'd be surprised how active people are on YouPorn, PornHub, etc. Whole new world. And surprisingly, very civil people.
- eonw 10y agoironic that youporn is included in this list considering they lost in a class action suit for very similar business practices. https://www.scribd.com/doc/44635414/Pitner-Versus-Youporn https://www.scribd.com/doc/44635414/Pitner-Versus-Youporn
- joering2 10y ago+1 very interesting case - company never located on US soil is being sued in California for something of a peanut size comparing to what Facebook does. I know a bit off topic but I can't find how this case ended. Anyone with better Google skills??
- 10y ago
- metastart 10y agoNothing shows up in my Epic Privacy Browser ;-D!!
- mdesq 10y agoUsing uBlock Origin and Privacy Badger defaults, it only showed me as logged into Hacker News.
- eximius 10y agoHm. Doesn't seem to work on Chrome on Android.
- JoeAltmaier 10y agoWorks mostly! I'm logged into HN of course; it says I'm not. Also Steam. It got Facebook, Gmail, Youtube, Dropbox right. Using default browser IE 11 on Win7
- eonw 10y agowhat is happening is not legal in the US and a large porn website was sued for doing it. they were printing hidden links on the page, then checking the color with JS to see if you had visited the destination url or not. judge didn't think it was a fair business practice. maybe these companies are not fixing this because of this legal precedent and figured no one was doing it?
- dimino 10y ago> without your consent Untrue. I have given my consent. Why are these privacy posts always using some kind of nefarious and negative language?
- dhimes 10y agoHmm. This works in Firefox 49, but gets it quite wrong in Google Chrome 53. I'm on Linux Mint 17.2 64 bit.
- EJTH 10y agoVery simple and cool exploit. I wouldn't be surprised if this technique is already in use on various ad platforms. A really simple pitfall I think most of us can confess to having done in the past (redirect attributes are pretty common in the wild).
- deleted 10y ago[deleted]
- alexholehouse 10y agoSo, interestingly, it had me logged in to reddit, but I don't actually have a reddit account at all. Thoughts?
- sdegutis 10y agoWhy not go to reddit.com and see who it says you're logged in as?
- alexholehouse 10y agoNothing, because I literally don't have an account.
- dawnerd 10y agoSame here actually. I haven't logged into my reddit account in like two years now. Also don't have any cookies from reddit so I dunno. The site does show me logged out of everything else so I think it's either broken or something else.
- morinted 10y agoNifty, with Firefox containers each one shows the "mode" I'm in. Hackernews for default container, personal has my Google world + open source + Dropbox, work has my work's Gmail world, and shopping has my Amazon account. It's like a verification that containers work!
- Pxtl 10y agoFYI, it's very NSFW in the back-end. Your browser is sending requests to obvious porn servers when you hit this link so it can test if you're logged in to them.
- throwanem 10y agoYeah, that would've been nice to know ahead of time. Why not, for example, trigger the test when someone clicks a button, rather than taking someone's page visit as permission to try lighting up their organization's content filter?
- ktta 10y agoI think it helps in conveying the fact that it is a vulnerability not a feature. So any website (even your own company's internal one) can check stuff like this. And you can't do anything about it. Other than always using private browsing for anything you don't want your company/anyone else to know about.
- throwanem 10y agoI mean, if somebody is logged into YouPorn from work, that's not a problem I expect the developer of a tool like this to solve. What I expect the developer of a tool like this to do is not create problems by just arbitrarily making HTTP requests to porn sites without a prompt or a chance to opt out. That's a dick move.
- drvdevd 10y agoWhen I first read that it was making these requests here in the comments, my reaction was similar. But then upon reflection, I don't think there's a problem for the author here. Why? Because all I did was click the link. Meaning if I was behind a corporate firewall or the like, this sort of thing could be happening all the time and unless I was always tracing requests in my browser or via MITM or logging DNS, I'd have no way of knowing. Personally I view this as a browser and/or protocol issue (the kind that has trickled down from the origins of the web) and really can't fault the author for it. In fact I think it's appropriate the author left these requests in as it reflects an actual attack scenario better perhaps.
- owenversteeg 10y agoHmm weird, it correctly detected everything except for the false negatives of PayPal, Tumblr, and Spotify. Taking a look at the mechanism I have no idea why this would happen, and opening the relevant links in my browser gives the favicon as it should. Weird.
- pg_is_a_butt 10y agouh... i'm logged into a bunch of those services, no ad block or "privacy badger" or whatever else they are claiming. the website doesn't work. you're all idiots.
- stabbles 10y agoMaybe you could add this leak to your list as well: https://news.ycombinator.com/item?id=12695451 https://news.ycombinator.com/item?id=12695451
- bcheung 10y agoHaha, I like how you added just one porn tube site so that you can add NSFW in the title. Nice click baiting. lol
- nodesocket 10y agoCouldn't this be fixed by instead of using ?next= in the query string storing a cookie. For example: if(!auth) { setCookie('next', '/url-here', 1h); } redirect(login); Login page action: if(cookieExists('next')) { next = getCookie('next'); deleteCookie('next'); redirect(next); } else { redirect('dashboard'); }
- detaro 10y agoCould easily muddle state with multiple tabs though, query string is clearer.
- the8472 10y agoThe firefox and tor devs are cooperating to upstream a tor browser feature that isolates cookie stores and similar things based on the domain shown in the URL bar[0]. Available in nightly by enabling privacy.firstparty.isolate = true in about:config. Additionally they're also also working on a more customizable version of that called contextual identities[1], which eventually will also be manageable by extensions[2] And of course addons that block cookies in cross-origin requests or cross origin requests in general such as µmatrix[3] also plug this hole. [0] https://bugzilla.mozilla.org/show_bug.cgi?id=1260931 https://bugzilla.mozilla.org/show_bug.cgi?id=1260931 [1] https://blog.mozilla.org/tanvi/2016/06/16/contextual-identities-on-the-web/ https://blog.mozilla.org/tanvi/2016/06/16/contextual-identit... [2] https://bugzilla.mozilla.org/show_bug.cgi?id=1302697 https://bugzilla.mozilla.org/show_bug.cgi?id=1302697 [3] https://github.com/gorhill/uMatrix https://github.com/gorhill/uMatrix
- kchoudhu 10y agoWho the hell makes accounts on porn sites?
- bhauer 10y agoThis is the first I had heard of GETs to login pages executing a redirect when the user is already logged in. I wasn't aware that so many did this. Virtually every application I have built will render a simple response saying "You are already logged in" if you GET the login URL with an active session. As I understand the exploit, if a non-image is returned, the script assumes you are not logged in. What value is there in redirecting a GET if you're already logged in? You redirect when the login form is submitted as a POST.
- detaro 10y ago2 tabs open. I log in in one of them, then follow a link in the other that points to the login page with a redirect to something that requires login. or 2 tabs open, I follow links to login page on both. Login in one, F5 the other.
- caoilte 10y agoThat's a fun website to look at through Gorhill's uMatrix plugin.
- rasz_pl 10y agoor ContentBlockHelper
- throwaway049 10y agoIt says I'm not logged into any of its sites. Chrome on Android 6. No special privacy measures. I am logged into a few sites in the browser, including this one.
- edibleEnergy 10y agoRecorded the network requests (from incognito) for fun with BugReplay, (the webapp I've been building for a bit over a year) here: https://app.bugreplay.com/shared/report/acf38fbd-f2e1-41c7-9b23-4031d9317d2b https://app.bugreplay.com/shared/report/acf38fbd-f2e1-41c7-9...
- user5994461 10y agoGood news! It's blocked by uBlock Origin and noscript.
- mp3geek 10y agoNot sure how much false positives this will cause, but its fixed in the Enhanced Tracking list. https://github.com/ryanbr/fanboy-adblock/commit/2385fb0b2b2803db4424ab9eda64370123eef81e https://github.com/ryanbr/fanboy-adblock/commit/2385fb0b2b28...
- Anagmate 10y agofor me, it throws several false alerts (Twitter, Flickr and few others). Is it possible that it's caused by my browser extensions (uBlock Origin, Disconnect)?
- tomvangoethem 10y agoAttaching cookies to third-party requests is the source of many issues. In a similar demonstration [0], I showed that browser-based timing attacks (which can probably be considered as wont-fix as well) can be used to extract more specific information from social networks (e.g. one's political preference based on who they're following). [0]: https://labs.tom.vg/browser-based-timing-attacks/ https://labs.tom.vg/browser-based-timing-attacks/
- a3n 10y agoSo, did I just make all those sites that I'm not logged in to aware of my IP address? And if I didn't have ad blocking, would I then be seeing ads "of interest to" people who visit those sites?
- ge96 10y agoHow does this work? I think I get the basic concept of calling redirects to various sites from the page, probably back-end like with php, CURL maybe? I just don't get how you'd keep track of where it goes after the redirect (trying a link) since you would now be on Facebook's site for example
- proaralyst 10y agoThere's an explanation further down the page, but essentially the redirect they choose is an image. You can tell if an image loaded successfully using JS, so if the redirect succeeds, that JS fires. If it fails (because the login page isn't an image), some other JS runs instead.
- ge96 10y agoOh okay, that makes sense. It's like those tracking/analytics where they know where a person came from previously to follow their "thought pattern" that is something I'm not 100% in either.
- Joof 10y agoCan't get this to work. Turned off ublock origin, but still using https everywhere and blocking third-party cookies (for a recently discovered attack that utilizes cookies).
- im_dario 10y agoUsing Brave Browser it gets wrong Reddit and Flickr for me. I'm not even logged on these. On the other side, it doesn't detect Facebook. Only got Twitter right.
- aswanson 10y agoGoogle is basically omniscient on a user-profile basis with years of search, gmail, and youtube data on users. They should just write and algorithm and let it send out job offers with no human intervention, just like search.
- rasz_pl 10y agoIs this a spoof? it is 100% WRONG for me on Vivaldi browser. Says im logged to FB and nothing more. I dont even have a bookface account, but I do have gmail/YT/github/reddit and few other open in the adjacent tabs and fully logged in.
- deleted 10y ago[deleted]
- mgalka 10y agoInteresting Instagram moved the favicon image but Facebook has not
- chmike 10y agoWhat would be a possible fix to this problem ?
- xerophyte12932 10y agoSo I logged out of facebook and tried this tool again. Apparently it still shows that I am logged into facebook. I tried opening different facebook pages and it detects that I am logged out but the tool still thinks I am logged in. Any guesses why?
- lensi 10y agoBlocking third-party cookies gives you full protection in this and other situations without any major annoyances. Other subcomments here mention it, but every time this comes up it seems most people (including the article) aren't aware that blocking 3rd party cookies is a super easy fix and IMHO should be the default of browsers. I've only ever had issues with this at my banking site because they use a third party to host their solution (Work around is opening the iframe). But I am now going to ask them to fix this (I guess all it requires is a sudomain pointing to the third party?). Please help spread the message and ask trouble web sites to fix their shit or if I'm completely wrong, educate me and let's move things forward.
- smoyer 10y agoAll it told me is that I'm a nerd ... So it was beaten by my wife and kids. "You are logged in to: Github, Hacker News" Interestingly, I have a legitimate use for the hack behind this idea.
- bugmen0t 10y agoTracking like this does not work when you use Firefox with Containers :) See https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers https://wiki.mozilla.org/Security/Contextual_Identity_Projec...
- DanielStraight 10y agoI don't know if anyone will read this at this point, but if you're going to proof-of-concept an exploit, please make that clear in the title or have an opt-in step with an explanation of what it will do like the EFF uses on https://panopticlick.eff.org/ https://panopticlick.eff.org/ I do not appreciate being tricked into running your exploit proof of concept, especially when you put content in it that I otherwise would not have clicked.
- deleted 10y ago[deleted]
- paulddraper 10y agoDoesn't seem to detect being logged in to Netflix. Or at least not for me.
- tofupup 10y agoneat