5 ms·
> One technique to protect against these attacks is browser fingerprinting. This method works by collecting data about a user's browser, which is then used to c
by gernb 4y ago
> One technique to protect against these attacks is browser fingerprinting. This method works by collecting data about a user's browser, which is then used to create a unique fingerprint for differentiating between genuine users and bots.
This seems like it can't work. 50% of users are browsing from an iPhone. Every iPhone of the same model has the same fingerprint except for time of day and language preference. So for every time zone there are literally hundreds of thousands of devices that will have the same fingerprint.
- arkitaip 4y agoYour browser's fingerprint is much more unique than you think: https://amiunique.org/ https://amiunique.org/
- konha 4y agoI just tested my iPhone with the EFF tool [0]. Seems unique-ish. I use an adblocker and safari for browsing with default settings. > Within our dataset of several hundred thousand visitors tested in the past 45 days, only one in 32014.4 browsers have the same fingerprint as yours. [0] https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- ntauthority 4y agoFor me, running the iOS 16.3 developer beta seems to have been what made my iPhone 'unique' among the ones tested on that site.
- saagarjha 4y agoEFF's site is wrong.
- 411111111111111 4y agoWhat makes you confident of that?
- saagarjha 4y agoTake an iPhone on the site and it’ll still call it unique, despite there being basically no identifying information listed in the report it gives you.
- sfe22 4y agoEFF don’t say they know who you are, rather how unique your device appears. This is a problem because if you appear very unique, only if one site knows your identity, everyone can potentially know it.
- saagarjha 4y agoI understand that. An iPhone should should not appear as unique.
- marginalia_nu 4y agoAccording to Apple's marketing. Yet here we are.
- saagarjha 4y agoNo, this is according to the report that EFF generates. Have you tried looking at it? What on that list lets you identify the device?
- counttheforks 4y agoAnd yet... It does. Buy 2 supposedly identical iphones. Take both to the site. Compare their information.
- saagarjha 4y agoWhen you generate a report they tell you which bits of your device were unique. For an iPhone running the latest iOS there is nothing in that list that leaks a significant number of bits.
- jonas-w 4y agoYou could also try creepjs https://abrahamjuliot.github.io/creepjs/ https://abrahamjuliot.github.io/creepjs/.
- gernb 4y agoThe EFF tool is provably false. For one, it doesn't get enough traffic so it's not representative in any way shape or form of a website that would use fingerprinting. But it also doesn't pass the sniff test. It tells me I'm unique. One of 185k. Let's break down that number. I'm in the PST time zone. There ~40 million people in the PST time zone. Divided by 185k is 216. They're basically claiming there are 216 iPhone 13 Pro in all of California + Oregon + Washington + British Columbia. Bullshit! It's basically fake news. The EFF should know better than to exaggerate with hyperbole. It might be true that almost no one visits https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/, but site that actually gets traffic is also a sight where it'd be closer to unique in 1 of 10.
- reset-password 4y agoThey may be referring to JA3 [0] which can be used to fingerprint the connection by examining the order of the ciphers sent by client to server during the TLS handshake. It isn't useful to detect that the user is browsing on an iphone, but rather that the useragent says the user is using an iphone but the JA3 gives it away as something else. It can be defeated by the client sending a specific list of ciphers in a specific order during the TLS handshake but in practice this can be difficult to do as it's typically implemented at a low level. Alternatively, creating a browser extension can also be used to defeat it as the request is running through the browser's code in that case. [0] https://github.com/salesforce/ja3 https://github.com/salesforce/ja3
- jonatron 4y agocurl-impersonate https://github.com/lwthiker/curl-impersonate https://github.com/lwthiker/curl-impersonate is great for avoiding TLS fingerprinting
- reset-password 4y agoThank you. I have not run into this library before and it looks fantastic.
- pifm_guy 4y agoThe goal of fingerprinting in this case is not to uniquely identify users, but merely to differentiate real human users using an actual iPhone from bots that use an emulated iPhone. This fingerprint suffices for that. They use small differences like the size of audio buffers, the exact capabilities of the GPU, etc. Emulate any one of those slightly wrong and the fingerprint will differ and your bot will be revealed.
- nicolaslem 4y ago> They use small differences like the size of audio buffers. Fun fact, on my laptop I can hear websites who use audio APIs for fingerprinting because it causes the audio subsystem to wake up and the speakers make a small pop sound.
- notpachet 4y agoUgh, me too. This is always my cue to close that tab.
- SpaghettiCthulu 4y agoThat works until the bot just overrides the fingerprint
- pifm_guy 4y agoThat's why the fingerprint is taken by obfusticated code running in a VM. And that VM also uses a crypto challenge so you can't just replace the output of the VM