4 ms·
Would you be willing to share this script?
by x775 5y ago
Would you be willing to share this script?
- stevehawk 5y agonice try NSA
- gruez 5y agoDon't bother. It's hard to do it correctly. If you look through the snippets (or the MDN docs[1]), the value is retrieved using the getParameter() function. You might be tempted to override the function by doing something like gl.getParameter = () => "test" but that's easily detectable. If you run gl.getParameter.toString() You get back "() => "test"" whereas the original function you get back "function getParameter() { [native code] }" In general, don't try to fix fingerprinting via content scripts[2]. It's very much detectable. Your best bet is a browser that handles it natively. [1] https://developer.mozilla.org/en-US/docs/Web/API/WEBGL_debug_renderer_info https://developer.mozilla.org/en-US/docs/Web/API/WEBGL_debug... [2] https://palant.info/2020/12/10/how-anti-fingerprinting-extensions-tend-to-make-fingerprinting-easier/ https://palant.info/2020/12/10/how-anti-fingerprinting-exten...
- rasz 5y agogl.getParameter.toString() = () => 'function getParameter() { [native code] }'
- gruez 5y ago-> gl.getParameter.toString.toString() <- "() => 'function getParameter() { [native code] }'" Not to mention the iframe trick mentioned in palant's article.
- rasz 5y agois that Firefox? in Chrome I get gl.getParameter.toString() = () => 'function getParameter() { [native code] }' gl.getParameter.toString() "function getParameter() { [native code] }" gl.getParameter.toString().toString() "function getParameter() { [native code] }" gl.getParameter.toString().toString().toString() "function getParameter() { [native code] }" iframes, worker, sharedworker, serviceWorker are all covered. Good luck timing the difference.
- deathanatos 5y agoYou're running gl.getParameter.toString().toString() what the comment you're replying to is trying to tell you to run is: gl.getParameter.toString.toString() Call toString on the toString fuction, not on its result.
- rasz 5y agoGood point. Rewriting according to https://adtechmadness.wordpress.com/2019/03/23/javascript-tampering-detection-and-stealth/ https://adtechmadness.wordpress.com/2019/03/23/javascript-ta... now
- deleted 5y ago[deleted]
- HWR_14 5y agoSo the issue is that the fingerprinting code can detect the anti-fingerprinting code? Doesn't that mean the best solution is for everyone to override the same functions with the same dummy information?
- Matheus28 5y agoYou can easily hide it by hijacking Function.prototype.toString to see if `this == fake gl.getParemeter or this == fake toString`. Then the js code needs to find a real Function.prototype.toString by creating an iframe, but then you can detect that. Then I'm out of ideas on how to rescue the original toString
- cookiengineer 5y agoThis can be fixed by overriding valueOf() and toString() on the prototype. Just return another native function, like JSON.stringify ;)
- rasz 5y agoSadly there are still things you cant programmatically override/proxy, like storagemanager await navigator.storage.estimate()