4 ms·
It is interesting that the site can fingerprint individual profiles/dir easily: For example chromium-browser --user-data-dir=/tmp/profile_A chromium-browser
by throwaway2056 4y ago
It is interesting that the site can fingerprint individual profiles/dir easily:
For example
chromium-browser --user-data-dir=/tmp/profile_A
chromium-browser --user-data-dir=/tmp/profile_A --incognito
chromium-browser --user-data-dir=/tmp/profile_B
chromium-browser --user-data-dir=/tmp/profile_B --incognito
For each command + its incognito it can detect them as separate profiles.
For ultimate privacy one needs to everytime launch browser with a new profile.
- vesinisa 4y ago... on a new computer, each time ordered from a different brand and reseller, paid with a unique type of cryptocurrency and delivered each time to a new dead drop in a different country.
- throwaway2056 4y agoI tried live boot of ubuntu. Every time it can detect accurately. Looks like the whole privacy thing is OVER. Unless lawmakers do something - (i.e) not going to happen! Atleast they can use this to prevent reCaptcha - and make passwords disappear!
- than3 4y agoUbuntu has a lot of unique information that is readily accessible. Machine-ID in /etc being one, but there's various other items that can be used in the same way from d-bus activation, and something like 20 different other places, another large number in snap.
- throwaway202302 4y agoWebsites can access machine-id?
- ale42 4y agoI guess they can't unless somebody had a great idea in the speficiation osome web API...
- throwaway202302 4y agoThat there are os-level identifiers is I think a different discussion. I wonder why these were cited in context of fingerprint.com discussion.
- than3 4y agoI've heard from people I know to be scary skilled in that area that its possible through the d-bus interface. Mind you this was years ago.
- jb1991 4y agoHow does the fingerprinting know the payment method you used to pay for the computer, is that stored somewhere in the operating system? How would they know it was a dead drop also? Genuinely curious.
- meghan_rain 4y agoIt was a joke lmao
- vesinisa 4y agoIt's just a precaution for when they eventually breach your OS and dig out the machine's serial number from the BIOS. This will allow them to trace you to the reseller you used. But if you ordered to a dead drop in a random country and paid with a different cryptocurrency network each time THEY gain exactly zero information to profile you. That, or the game against pervasive web tracking is lost.
- jb1991 4y agoThis is actually very useful information. I think I know how I’m going to buy my next computer, but I wonder which manufacturers support the drop as a shipping option?
- throwaway202302 4y agoDo these profiles clear their cookies after request? I assume if the service finds a matching cookie, it will prefer it, or at least use as an extra identifier.
- throwaway2056 4y agoTechnically one can create this and launch a new profile everytime. It can still detect the device (there are some failures - if I change the screen resolution/dpi). May be after 3 or 4 times, the server may also detect that a certain ip address is trying the same thing. TEMP_DIR=$(mktemp -d /tmp/chromium.XXXXXXX) ; /usr/bin/chromium-browser --user-data-dir=$TEMP_DIR At the end as other say they use hardware information + IP + other stuff. It is a lost battle.
- throwaway202302 4y agoBut how could it distinguish different profile directories, if they use the same settings. I would assume profile id, directories, or others should not be exposed through the browser. I am not used to chromium-browser (is this chrome? forgive my incompetence), but I wonder what kind of profile-specific static identifiers despite cookies could leak out the browser? Maybe these? https://browserleaks.com/webrtc https://browserleaks.com/webrtc But at least FF in private mode should randomize these IDs on restart.
- throwaway202302 4y agoDid you check amiunique.org as well with these?
- ale42 4y agoIs this _only_ figerprinting then? If the profiles are different, do they manage to extract some UID from the profile (which I would assume is a bug in the browser), or do they store data client-side using persistent storage APIs?
- richthegeek 4y agoChrome does give access to localStorage/sessionStorage in Incognito and this can be used to communicate between tabs on the same domain, but just like cookies and cache this data is wiped if you close the Incognito instance. It's certainly a mystery, because you'd expect any capability fingerprinting (some combo of UA, extensions, CPU/GPU specs, IP etc) to give an identical result between profiles, so it does seem there's some per-profile difference. But I can't think of any browser API that exposes something like an ID...
- throwaway202302 4y agoThen, could not we a get a trace of the properties it uploads to the server by analyzing what is executed in the javascript? Sure it has some sort of submit endpoint where it throws the individual values to.
- throwaway202302 4y agoPOST https://fpa.fingerprint.com/?ci=js/3.8.10&ii=fingerprintjs-pro-react/2.3.0/react/18.2.0&ii=fingerprintjs-pro-spa/0.7.0 https://fpa.fingerprint.com/?ci=js/3.8.10&ii=fingerprintjs-p... It looks like it is using heavy obfuscation.
- throwaway202302 4y agoScrolling a bit through the mess it seems, it is for exampling, trying to detect the used ad-blockers. .... adGuardGerman:[u("LmJhbm5lcml0ZW13ZXJidW5nX2hlYWRfMQ==") .... I see things hat look like font fingerprinting, CSS, Apple pay detection, ... , msPointerEnabled, ..., webkitResolveLocalFileSystemURL, ... cookie settings... ... used mathematical library (sinus, cosinus, ...) serviceworkers, ...RTCPeerConnection, hardwareConcurrency, Maybe we could dissect it and analyze the full list? At some other place, they documented e.g. you can get the light/dark theme information out of the CSS. Doesn't even need JS to do it.