4 ms·
Looking at their product, I wonder how many of these kind of vulnerabilities are still open and exploited by them. Wouldn't make much sense for them to burn suc
by bronzeage 5y ago
Looking at their product, I wonder how many of these kind of vulnerabilities are still open and exploited by them. Wouldn't make much sense for them to burn such a useful vulnerability which is required for their product unless they had something better.
- grishka 5y agoInteresting to see how their product is open source, too: https://github.com/fingerprintjs/fingerprintjs/ https://github.com/fingerprintjs/fingerprintjs/ It's as if they want browser developers to look at the code and break it as much as possible.
- harikb 5y ago> DISCLAIMER: FingerprintJS does not use this vulnerability in our products and does not provide third-party tracking services
- dathinab 5y agoYou can get a lot of entropy just by fingerprinting things send over HTTP headers and things freely accessible by JS. E.g. user agent, screen dimensions, language, web GL, audio api, etc. Generally wrt. fingerprinting chrome is worse then Firefox as Firefox actively worked to reduce fingerprint-ability if possible, while chrome seems to not care much. Because of this ironically I have a less unique fingerprint on a customized Firefox browser then a "stock" Chrome browser even through much less people use Firefox... The reason (I think) why they make this public is because this can be used for more then "just" fingerprinting. I.e. this can be used by cyber attacks to find a potential attack vector to then pull of either a direct attack or some social engineering attack.
- the_duke 5y agoFirefox also has a lot of settings that mitigate various finger printing techniques. There are some good sample configs on Github. [1] Ironically, many of the settings can make you more unique because they disable a lot of functionality. [1] https://github.com/pyllyukko/user.js https://github.com/pyllyukko/user.js
- KirillPanov 5y agoThis is why the torbrowser/firefox "try to make everybody look the same" approach is doomed. Adding white noise is the only solution: "try to make your fingerprint on each website for each brower-restart look as different as possible (a) from your fingerprint on every other website and (b) from your fingerprint on the same website on a previous browser-restart". That's the best you can do anyways without rejecting first-party cookies. Brave does this, and it is the right way. I just wish Firefox would wake up and clue in to this.