3 ms·
The irony of this is that you'll end up with a fingerprint that is probably more unique than just running standard Chrome at 1920x1080.
by dt2m 4y ago
The irony of this is that you'll end up with a fingerprint that is probably more unique than just running standard Chrome at 1920x1080.
- gruez 4y agoThe flaw with this is that the set of fingerprintable features is far more than just "browser brand you're using" and "monitor resolution". At the very least running without fingerprinting resistance leaks your GPU model. That might be fine 1. you're forgetting about other fingerprintable features. the obvious one would be WEBGL_debug_renderer_info which leaks your gpu model. that might be fine if you're running intel uhd graphics, but for someone with high end discrete graphics it's quite revealing. There's also more[1] 2. what if you don't have a 1920x1080 monitor? if you have a 1440p or 4k monitor, then what? JS APIs allow you to get both the viewport size as well as the monitor size. That's going to make you stick out as well. You can try to mitigate this by running in a VM, but then your GPU model would show up as "VMware SVGA 3D" or "Virtualbox Graphics Adapter", which also makes you stick out like a sore thumb. [1] https://browserleaks.com/javascript https://browserleaks.com/javascript
- moron4hire 4y agoThe overall attack surface of fingerprinting is so huge that even if some fantasy world in which all of WebGL, Canvas, Web Audio, WebRTC, etc., could be permanently removed, you're still fingerprintable. The time of day you visit specific sites is enough to eventually fingerprint you. This data can and is collected on back-ends and then shared across data networks. It doesn't matter what you do in the client, you're fingerprintable.
- gruez 4y ago>The overall attack surface of fingerprinting is so huge that even if some fantasy world in which all of WebGL, Canvas, Web Audio, WebRTC, etc., could be permanently removed, you're still fingerprintable. I guess that's true in the abstract, but the more fingerprinting vectors there are, the easier it is to identify a specific person. The best case scenario is something like the iPhone, where each model behaves identically and there are limited amount of user-configurable settings, such that there are tens of thousands of people in your city alone that have the same model/settings (eg. timezone/dark mode on/off). You can do all the fingerprinting you want, but for a medium traffic site you're probably still going to get hundreds/thousands of users with the same fingerprint. >The time of day you visit specific sites is enough to eventually fingerprint you. How does this even work? If I'm on a VPN (ie. shared IP with hundreds of other users) and have total cookie protection (separate cookie jars for each site), it's effectively impossible to tell whether I'm one user visiting a dozen sites, or a dozen users viewing one site each.