24 ms·
Using a date-modified header to detect unique visitors without using cookies
- DueDilligence 4y ago.. and we're fast on-track of a webkit extension to block this BS.
- cactacea 4y agoWhy block it entirely when you can just feed them garbage data?
- enkrs 4y agoWhats the motivation to block/misinform? This allows site owners get statistics on page views/uniques/bounces without unique identifier cookies or javascript injections. I’m all for blocking any abusive tracking methods, but this looks to me like creative website statistics that works for single domain. What’s the harm by measuring that?
- nkrisc 4y ago> Whats the motivation to block/misinform? What’s the motivation to submit to it?
- yojo 4y agoAllowing websites to get a somewhat accurate count of visitors plus bounce rate helps them to tell how they’re doing. Hopefully, they use that to guide developing a better product/service. If you can allow them to do that without getting tracked, it’s win-win. You get a better experience when they build a better service.
- michaelt 4y agoWhile this particular implementation doesn't track individuals, couldn't your trivially start tracking individuals by sending them unique random times like last-modified: 12 Mar 1978 12:34:56 GMT thereby giving them a ~30 bit unique identifier for as long as the file is cached?
- pwdisswordfish0 4y agoOnly if you disregard the amount of latitude that the semantics of these headers give to UAs that would effectively thwart this method of tracking. If I fetch your /foo.html today in November 2022, and you send me a last-modified from 1978, that gives me and my UA a huge range from which to select a different datetime (anywhere between the 1978 value and now-ish) on my next request. How are you going to correlate my original and subsequent requests if in the latter I ask if you've got a copy that's been modified since 1999?
- marshray 4y agoSure, a UA could do a whole lot of things to resist fingerprinting. But users go to the web with the browser they've been given. Apple, famously, forbids its users to speak HTTP with anything else on iOS.
- pwdisswordfish0 4y agoContext is important. The replied-to comment starts off, "While this particular implementation doesn't track individuals, couldn't your trivially start tracking individuals by[...]" An acceptable response, then (to both you and the original commenter), follows: "While some particular browser version doesn't currently protect individuals from that proposed form of tracking, any browser vendor could trivially start thwarting that form of tracking by exploiting the latitude afforded to UAs by the semantics of these headers." And that's the form that the previous comment takes and how it should be understood. The fact that "users go to the web with the browser they've been given [i.e., today, and which isn't providing this sort of tracking protection]" doesn't change anything; we are explicitly talking about steps that each side _can_ take in the arms race related to the subject of this discussion...
- cpeterso 4y agoSending a garbage Last-Modified time might confuse the server and cause unpredictable problems for the user. Blocking it is safe because the server will just assume this is the first time the user has visited the website.
- yojo 4y agoTo be clear, they’re not generating unique headers. They’re setting them to the day start, so they can tell if the requester has already been to the site today or not. It actually seems pretty reasonable.
- pavon 4y agoThey way they are using it is providing less information than a UID cookie would, but the same amount of information as a boolean "previously visited" cookie. However, now that the technique is known there is nothing stopping people from using the same method to store a UID date, and privacy protecting clients will have difficulty differentiating between the two, so best to eliminate this as a fingerprinting method altogether.
- chipsa 4y agoBut you can't have as many bits in a UID date as for a generic cookie, and a privacy protecting client could just ignore the ones that don't make sense. Does a 1978 date make sense? Probably not. You could scale this up to the millions, probably, but it won't scale infinitely.
- genewitch 4y agoroblox has ~50mm daily users (DAU), and if my math is correct (it probably isn't) you could have hour granularity (only 0-23) timestamps on 6 files, each day, and track 191mm unique users. I used roblox because i knew their DAU off-the-cuff - because roblox requires a login, they know who you are anyhow. But if you do 1 second granularity a mere 2 cache timestamps are enough to fingerprint everyone on the planet, each day. is my math wrong, here?
- not2b 4y agoPeople keep saying in this thread "there is nothing stopping people from using the same method" to do something else! I think that this is an irrelevant criticism. This is a valid attempt to minimize the amount of information collected on visitors and still providing a unique visitors per day count, and the fact that someone could build a similar but different system that looks like a cookie isn't relevant.
- rnhmjoj 4y agoThere probably is one already: this method is so old that the documentation of privoxy shows[1] how to defeat it. I can confirm it works: their example[2] website says I've visited 61996 times. [1]: https://www.privoxy.org/user-manual/actions-file.html#OVERWRITE-LAST-MODIFIED https://www.privoxy.org/user-manual/actions-file.html#OVERWR... [2]: https://lastmodified.normally.com/ https://lastmodified.normally.com/
- bvinc 4y agoWhat’s to stop someone from sending unique last-modified dates to uniquely fingerprint browsers?
- nightpool 4y agoBecause the cache key for the site is partitioned by top-level origin in modern browsers, they wouldn't get any additional information this way that they couldn't get with existing first-party storage techniques, such as service worker caches, session cookies, IndexedDB, etc. See e.g. https://developer.mozilla.org/en-US/docs/Web/Privacy/State_Partitioning#network_partitioning https://developer.mozilla.org/en-US/docs/Web/Privacy/State_P... for example. Opening a new incognito window would trivially defeat this method of "tracking". This is basically just a very small first-party-only cookie.
- SahAssar 4y agoThen why not use a cookie? The laws regarding tracking are not actually about cookies, but about all cookie-like tracking. What does this method gain?
- baggy_trough 4y agoThis article is written like it's a great privacy breakthrough but why is this any different from dropping a user id cookie?
- jagged-chisel 4y agoHow do you get more than 86,400 unique “identifiers” when they only change every second?
- toast0 4y agowho says Last-Modified has to be a current date? you've got the potential for 1669827111 users as of when I was composing this comment without giving your users future dates.
- koliber 4y agoThere are also many timezones and you can encode information in the timezone indicator as well. Also, you can use different days. You can stretch this number into millions. For a website that gets a certain number of unique visitors per year, this may be unique enough.
- tedunangst 4y agoSubdomains. (Not sure why I immediately thought subdomains and not just multiple resources.)
- WirelessGigabit 4y agoYou don't have to. A unique visitor is someone who comes in without a last-modified header. Set the header, that person is no longer unique.
- marshray 4y agoA malicious site can put a different identifier on every resource loaded by the browser. There really is no bottom, is there.
- nine_k 4y agoIt is materially different because it does not track individual users. It's comparable to dropping the same cookie to every visitor on a particular day; a pretty low level of privacy invasion. Also, this allows to not use such things as visitor's IP address to collect meaningful statistics, which is a privacy win for the user, and an accuracy win for the site operator.
- Isinlor 4y agoThis is really no different than a cookie - basically the same mechanism from the view of the server just different semantics.
- ape4 4y agoYes, cookies are a header field sent back by the browser and so is this.
- legitster 4y agoIf anything, this is worse. Cookies have built in browser behavior - they have limited scope, the browser lets you see them, they get cleared out regularly. Abusing metadata is way sketchier.
- eurasiantiger 4y agoChances are they aren’t the first to come up with something like this. How can we detect this kind of metadata abuse?
- fanso99 4y agoperhaps randomize minutes/seconds of the "last-modified" header.
- notpushkin 4y agoOr perhaps just drop minutes/seconds. And maybe don't store the date altogether for files that are small enough?
- pornel 4y agoImportant to note that privacy laws that regulate tracking are not limited to the Cookie header. They apply to tracking and data collection in general, regardless of how technically clever you make it.
- pavon 4y ago
- deleted 4y ago[deleted]
- speedgoose 4y ago> This is great for privacy as we don't need to use cookies, IP addresses, fingerprinting or unique identifiers. In our tests, this method proved durable enough to be the most reliable method of counting unique visitors without using cookies. The differences with a cookie are that the header is named Last-modified instead of Set-Cookie and Cookie, and the value must be a datetime in the RFC2616 format. How is it good for privacy? I think it’s worse because it’s invisible for the user. I would bet tracking visitors using such an hack isn’t compatible with GDPR, that requires an informed consent for tracking. And good luck explaining your hack to the average visitor.
- Etheryte 4y agoYou seem to slightly misunderstand how GDPR works. Tracking in and of itself is not the problem, it's personal data and personally identifying data that is. You can count how many hits your server receives no problem, this is roughly the same idea.
- luckylion 4y agoThis is equivalent to setting a cookie with a hit count. It's still storing & submitting information, it's just not using a unique identifier (Which is pretty privacy-respecting, I'm not saying it's a terrible thing or something). I assume it will be treated as such, too. If you can use a cookie to do this without consent, this is fine too. If you can't then it's not. The same happens for local/session storage: it's cookie-equivalent.
- deleted 4y ago[deleted]
- tobr 4y agoThat’s pretty clever. I think if you really want to keep it privacy respecting, you should stop counting at 1 - so you can distinguish the first vs subsequent visits, but you can’t tell if someone has visited 2 or 200 times.
- AkshatJ27 4y agowhat is the problem with letting a website know how many times I have visited the page? How is it better for a website to only know if I have visited earlier or not?
- xyproto 4y agoMany clients may have visited only one time, but when you reach higher numbers they may be used together with other data to help identify users. Maybe only one user will have over 100 visits, and then you can uniquely identify them.
- barefeg 4y agoMakes sense. I’m not very experienced in privacy but could you explain why uniquely identifying the user is a problem? As in you can tell that there’s one user who visited 100 times but how can you use that information to correlate with an identity?
- _justinfunk 4y agoThis is also my question that all the people wearing their smart lawyer hats seem to be claiming but not explaining.
- xyproto 4y agoMainly for targeting ads, I guess.
- cortesoft 4y agoI am having trouble understanding how knowing someone has visited three times is more privacy invasive than knowing they visited twice. What is so magical about 3?
- bennyp101 4y agoSeems a fairly benign way of counting how many people are visiting your site. Not like its tracking you across domains and services, more a counter for how many people have visited, and either stayed and looked around, or left.
- meowface 4y ago>Not like its tracking you across domains and services The same can be said of first-party cookies.
- a_c 4y agoLooks like a nice middle ground between no tracking at all and needing all tracking to how well your website perform. Seems no fingerprinting is involved so the website visitor is anonymized. Unlike cookies where we can store whatever we like, this method reveal only the unique visit, and its derivatives.
- jahewson 4y agoThe fact that this is being used in an analytics product that claims to be compliant with all privacy laws is horrifying. There’s no way this is compliant and it’s deceptive.
- pyrolistical 4y agoPlease explain why this isn’t compliant?
- bpfrh 4y agoBecause the GDPR isn't about any specific technology, but concerns any processing of personal data: https://gdpr.eu/what-is-gdpr/ https://gdpr.eu/what-is-gdpr/ Edit: Huh, I stand corrected I don't know if this would count as personal data.
- eurasiantiger 4y agoStoring a cache header is not an issue, but if it is used as a unique identifier for user analytics purposes, it is almost certainly personally identifying information, at least after combining with other data. Since they are not disclosing that they store something they use to ID users, it is likely a GDPR violation, at least in spirit, and that spirit is exactly what GDPR seeks to control.
- bonestamp2 4y ago> after combining with other data The post says that they don't combine datapoints because that would negate privacy.
- eurasiantiger 4y agoThey don’t but anyone using their service could.
- ATsch 4y ago
- prpl 4y agoDo people use etag for such purposes?
- cpeterso 4y agoYes. ETag tracking has been a thing for decades: https://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags https://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags
- deleted 4y ago[deleted]
- glenjamin 4y agoI think the comments on this post would probably less hostile if the title said something like "detect the number of unique visitors", which is what I believe it's doing, rather than detecting unique visitors using unique timestamps, which is what many seem to be guessing based on the headline alone.
- michaelbuckbee 4y agoThey're using this to track number of unique visits from a single user to a site.
- Thorrez 4y agoYes, but I think they're not tracking anything else about the user besides number of visits. E.g. they're not tracking ip I don't think. And I think they are only doing it within a single day, not across days. If you know that someone exists who visited your site 500 times today, but know nothing else about the person, is that a privacy problem?
- tedunangst 4y agoYour personal visit count is embedded in the seconds.
- lisper 4y agoYes, but not your identity.
- andix 4y agoIt would be interesting if it is also possible to abuse it. If it is possible to create enough unique timestamps, that browsers still accept them. Can you add milliseconds to the TS, and do browsers store them too? Or do browsers also accept timestamps from months or years back and re-send them? If you can use the whole scale of Unix time (int32), there is a huge pool of entropy available. In this case they don’t do this evil thing, and it probably would still violate the European GDPR, even if it’s not an actual cookie, but somebody has to find it first.
- rkagerer 4y ago...at the cost of caching (or at least a round trip). Is it necessary to know how many visits per day a particular user made? If # of unique visitors per day/week/whatever is sufficiently granular you could retain a corresponding cache window. Also if this is to avoid those cookie warnings that got popular after GDPR, it should be noted you're still storing information on users' computers. i.e. The stuffed metadata is not so different in principle from a cookie. In this case it seems innocuous, but I wouldn't be surprised to see sites exploit your trick to store a unique last-modified date for each user as a method of tracking (if that's not already commonplace).
- not2b 4y agoThe number of unique visits in a day is the number of total visits minus the number of repeat visits from the same users, so they need something like this to get an accurate count. You can't produce the number without information on repeat visitors. I think you are right that this technique could be changed and turned into a way to track individual users. But as implemented, it doesn't do that, and all knowledge is lost after one day. We shouldn't criticize people who are trying to limit the information they collect to the bare minimum by pointing out an altered version of their system might have undesirable properties.
- rkagerer 4y agoThen the server doesn't need to know about repeat-visits that don't hit it, and it would be nice to maintain caching support if the page content is static.
- zagrebian 4y ago> Many privacy-focused analytics services will generate and store a UID on the server instead of saving it in a cookie - based on a hash of your User Agent, IP, Location, Date etc. What location? The Geolocation API? What date? How can a date contribute to a UID? Each visitor sends multiple HTTP requests at different dates.
- legitster 4y agoAm I missing something? Abusing the cache meta-data to store data on the user device seems much worse than a cookie. I would have serious doubts of the longevity of such a trick, let alone some of the technical limitations I am sure the service has.
- o_m 4y agoCookie tracking without consent is illegal in Europe, so it is a clever way to still do some basic web analytics.
- masklinn 4y agoTracking without consent is illegal. This is a clever way to get absolutely reamed, because you’re not only in breach of data protection laws you’re actively trying to obfuscate it.
- andix 4y agoThe obfuscation part is probably irrelevant from a legal perspective.
- roelschroeven 4y agoTracking without consent is illegal in Europe, regardless of the method. Alternative tracking methods are not workarounds to get around the law; they are only workarounds in trying not to be caught.
- atoav 4y agoYeah nice try. Law makers are not that stupid. Any way of storing personal data is subject to this regulation. And before you try the next thing, personal data is everything that can be linked to a specific user, e.g. IP addresses have been ruled to be personal data, some uuid that helps you identify a user as well. People should really read the law, and/or at least literate commentary on it instead of assuming things or repeating what someone else assumed.
- WirelessGigabit 4y agoI wonder how this works with systems like Akamai which by default mess with those headers.
- habibur 4y agoThis can be used like a cookie without using cookies as long as definition of cookie stays "...a cookie is a small file stored on your computer". You have 30 million seconds per year as unique identifier to be used against each individual for tracking. Even though the OP didn't do it. Put an expire time in between 10 years back to today and 300m users tracked.
- superjan 4y agoOn the other hand, now that we know about it is easy to defeat: a privacy conscious browser will just add a random amount of minutes/seconds in the “if modified since” header. The only risk is you sometimes trigger a reload because the resource was modified in that interval.
- Kuinox 4y agoIt's harder, but you still leak bits of informations. If the random function is known, statical analysis can still leak out a bit of information.
- irq-1 4y agoChange 'last-modified' to use a secure hash of the contents, like sha256. Then the browser can detect if a website is giving bad hashes, potentially using them for tracking.
- sdfhbdf 4y agoThats what ETag is for. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ETag https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ET...
- irq-1 4y agoETags can be anything -- they aren't required to be a hash of the content. Thinking about this problem, why does the browser expose any information about what's in the cache? Client-side JavaScript can't tell what's in the cache because it's an obvious security issue. Why let the server know? Browsers should ask for the hashes on a list of content without exposing their cache contents. Then the browser can request anything thats changed.
- jefftk 4y agoThe way If-None-Match is that the browser says "give me the latest if this ETag represents an out-of-date resource, otherwise I'll keep using my copy." It's not clear to me how you're proposing this work instead? (Also, in many cases the server uses a hash of the inputs to generating the resource, which isn't something externally verifiable)
- jefftk 4y agoETag doesn't have any assurance that it's a hash of the page contents: the current protocol doesn't stop the server from embedding arbitrary information in the ETag, and there's no way for the client to tell.
- debugnik 4y agoNeither does Last-Modified, as we just saw. If we were going to alter the meaning of a header for this, it should be ETag. Just agree on ETag formats that browsers can verify are just hashes, and have them throw away any opaque ETags or dates.
- politelemon 4y agoIf the counter is empty for you, disable your adblocker temporarily. The withcabin.com domain might be blocked.
- dahfizz 4y agoThreads like this kinda make me sad about HN. Every single comment is about how this technique might possibly be abused to track users in very specific scenarios (i.e. you may be able to identify your most active user). If a web server wanted to track you, they would just use your IP. This is a clever technical trick to count your number of users without collecting any personal data. I don't understand why that is such a bad thing?
- tinus_hn 4y agoFirst, an IP address is considered personal data in the EU. Second, an IP address is not enough, it may change or be shared. The advertisers ‘need’ to track you forever to serve you relevant ads. So they devise all kinds of tricks to do so.
- rzzzt 4y agoCGNAT complicates matters even further. Sometimes I'm placed way off within <country> if a site tries to go by GeoIP databases, as the provider placed a bunch of households behind a single address.
- aardvarkr 4y ago> First, an IP address is considered personal data in the EU. I don’t believe that’s true. To my knowledge, GDPR only treats IP address as personal data if it is associated with actual identifying information (like name or address). Collecting IP address alone, and not associating it with anything else, is completely fine (otherwise nginx and apache's default configs would violate GDPR), and through them basically every website would violate GDPR.
- jakobdabo 4y agoETag (paired with If-None-Match header sent by the browsers) is another caching header to be aware of. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ETag https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ET...
- doomrobo 4y agoOoh that's kinda evil. A server could give a client a uniquely identifying ETag for a given URL. So whenever the client comes back on the same browser, they're identified. Fortunately this is probably just as detectable as the Last-Modified abuse in the post.
- bawolff 4y agoThere are a lot of things like that. Although browsers changed it recently, you also used to be able to use TLS session tickets. Another one was the favicon cache. Pretty much any state on the browser can be used to track people.
- birdmanjeremy 4y agoThe demo doesn't work in safari on my mac. It sometimes gets to 2, but on refresh goes back to 1. Actually, got it up to 4 one time. Seems like the claims of "Works in any browser and any server" are overstated.
- devmunchies 4y agosame. I got it up to 8 by clicking into the address bar and hitting enter. However, doing a refresh instead caused it to reset (the browser didn't send the if-modified-since header so the server didn't do it's little trick and instead started over)
- jefftk 4y agoI think this is probably illegal in EU countries. The ePrivacy Directive requires consent before storing data on a user's machine that isn't strictly necessary for providing the service the user requested. Analytics isn't "strictly necessary", and ePrivacy doesn't care whether you use the Cookie header or some other method of storage. I do think this is better for privacy than standard id-based approaches, but the law is very strict. More: https://www.jefftk.com/p/why-so-many-cookie-banners https://www.jefftk.com/p/why-so-many-cookie-banners (Not a lawyer)
- Quarrelsome 4y agoI thought GDPR cared mostly about uniquely identifying visitors which this does not do. You still need a cookie banner to state that you will put some data on their machine but you always need one of those.
- jefftk 4y ago> you always need one of those The withcabin.com landing page claims you don't need consent banners to use it.
- t0mas88 4y agoThat claim is false in Europe. You need to ask permission for this approach, because you're storing something on the user's device (the generated date in the cache) that isn't strictly necessarily. The ePrivacy directive says you need permission for that, nowhere does the law specify "cookies" it's about any kind of data stored on the user device.
- jefftk 4y agoUh, yes? That's exactly what I've been saying upthread.
- mgrund 4y agoTrue it does not matter if it’s a cookie, or whatever. You need to look to the ePrivacy directive article 5.3 for which exemption case applies. In the case of timestamps, it would be case A : > when the cookie is used “for the sole purpose of carrying out the transmission of a communication over an electronic communications network” (“Exemption A“) Since the timestamp is no longer used solely for this purpose, you need consent.
- alkonaut 4y agoI very much prefer this to e.g fingerprinting. This is local to one site and basically uniqueness only rather than an identifying id. I don’t feel “tracked” or “targeted” by this.
- kiriberty 4y agoCringe moment, this is abusing the feature where last-modified was created for
- someweirdperson 4y ago"Counting unique visitors"? They are counting repeated requests. The unique count then is "total requests" minus "repeated requests". Wouldn't it be easiser to count the number of times a cached resource is accessed?
- BeefWellington 4y agoTime of last access + a counter of your visits once your hits reach N>2 is probably enough to separate an individual from the crowd here, unless your site is tremendously busy.
- mulhoon 4y agoHi, author of the article here. Just to give a little more background here. Cabin doesn't store a row in a database for each visit. It only stores one row, per day per domain. The attributes for that row are simple tally counts - visits, uniques, bounces etc. So no identifier is stored, and the hits go into the tally. We do not store the fact that a user has visited x amount of times. The demo here is to show how the technique works. Cabin used to detect only the presence of any last-modified date to determine if the visit is unique or not. But extending it to distinguish hits 1,2 and 3 (by adding 1 second to the start of the day) now allows us to count the bounce rates too.
- lolinder 4y agoThanks for sharing! I personally don't have an issue with it, but one thing that might set some of the people here at ease is if you stopped incrementing the timestamp after the second visit. This would give you three possible states anyone could be in: never visited, visited once, and visited more than once. It's less data, but still enough to give you your bounce rate and your total visits while minimizing the number of boxes you're sorting individual visitors into.
- jefftk 4y agoYour landing page says "no cookies or consent banners" and "compliant with all privacy laws", but the timestamp approach stores data on a user's computer in a way that is not "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user". Could you explain how you see your approach as compliant with the ePrivacy directive? Full text: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Guidance: https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio...
- IshKebab 4y agoYeah this is just a cookie by another name. Probably already used by supercookies. The GDPR doesn't single out cookies so you can't get around it by using a different storage device.
- mikem170 4y agoTheir demo counter [0] didn't work in my browser, maybe because I normally have javascript disabled. In the demo it seems they have XMLHttpRequest code calling ping.withcabin.com/cache for this trick of theirs. Can this method of counting be made to work without javascript? [0] https://lastmodified.normally.com/ https://lastmodified.normally.com/
- notpushkin 4y agoIf it’s anonymous and doesn’t collect any user data, why do we need it at all? Would using a cookie for the same purpose (just a counter of visits, resetting every day) trigger the GDPR laws somehow? It would work in literally same way except being transparent to the user instead of utilizing some shady technique.
- deleted 4y ago[deleted]
- layer8 4y agoIf this becomes widespread, browers will probably start fudging the timestamps.
- Jabdoa2 4y agoI guess according to GDPR this counts as tracking nontheless. GDPR does not specifically mention cookies or anything technical. An identifier is enough (does not have to be a uuid). IP, location, browser etc already counts. This probably would count as storing something like a cookie on the client.
- zzo38computer 4y agoIt should be able to detect that the date is not valid (and that their precision is wrong), and avoid sending a "If-Modified-Since" header. (The same would be true if they were assigned at random rather than sequential like this; it still should be able to detect that they are not valid and have wrong precision.)
- schoen 4y agoMartin Pool discovered pretty much this technique back in 2000: https://catless.ncl.ac.uk/Risks/20.86.html#subj10.1 https://catless.ncl.ac.uk/Risks/20.86.html#subj10.1
- alexmolas 4y agoWhat if during a day I visit the website more than 86400 times? ;)
- josephscott 4y agoThis reminded me of something I haven't thought about in awhile: evercookie - https://github.com/samyk/evercookie https://github.com/samyk/evercookie
- jesprenj 4y agoWhat's the reason for not storing a cookie? It's not like browsers that don't support cookies are targeted, right? Cookies can also be "great for privacy", if their power is not abused server-side ...
- 1vuio0pswjnm7 4y agoWhat happens if the user disables Javascript. The page lastmodified.normally.com claims "Works in any browser or any server". What if the browser has no Javascript engine. In this case I tried the demo with a browser that has a JS engine, with JS enabled, and the demo still did not work. That is because "ping.withcabin.com" was not disclosed to the user. The OP suggests that users access "lastmodified.normally.com". It says nothing about accessing "ping.withcabin.com". As such, the proxy does not contain any address info for that domain. The user (me) never typed it. Instead of a browser, I use a localhost-bound forward proxy to control requests and responses, including HTTP headers. The proxy contains all of the domain-to-IP address mappings I need in memory. Why should I add an IP address for "ping.withcabin.com". The request returns no content. 1. For example, something like acl cabin hdr(host) -m str ping.withcabin.com http-request del-header If-Modified-Since if cabin http-response del-header Cache-Control if cabin http-response del-header Last-Modified if cabin
- yunruse 4y agoHm, on Safari 16.1 it seems reloading twice clears the cache and therefore the counter (but eg cmd-W cmd-Z cmd-R will safely increase it). Either way, I think I would prefer this behaviour to be some sort of cookie that the law okays, because as everyone else has said, I'm quite browsers will fuzz these data. (I would probably go for a Gaussian fuzzer each visit, just because it adds the off chance that it's quite a way away from any attempted ID, making it a little bit more difficult to cast a wider net and get a few bits of entropy)
- userbinator 4y agoTurning off caching will easily defeat this.
- mrfumier 4y agoThere are hundreds of parameters you can collect to detect unique visitors without cookies. Check out a list here: https://amiunique.org/fp https://amiunique.org/fp
- rasz 4y agoGET https://ping.withcabin.com/cache https://ping.withcabin.com/cache net::ERR_BLOCKED_BY_CLIENT ubo killed the demo?