11 ms·
Since Chromium 148, Math.tanh is now fingerprintable to link underlying OS
- dmitrygr 3mo agoInteresting reporting, marred by obvious llm-slop-sounding writing. "You are not building..., you are ..."
- netsharc 3mo agoWhy "slop-sounding"? It's definitely LLM slop. Man, why the fuck don't they just make a powerpoint with bullet points if all the sentences are like that.
- joahnn_s 3mo agoWe noticed Chromium Math.tanh since v148 returned a different result, so we dig it - it's now a fingerprintable surface to retrieve the OS Chromium run on
- sjrd 3mo agoI guess that's one more good reason to push for correctly rounded transcendental functions. I recently learned that they're basically solved now. [1] [1] https://arith2026.org/program.html https://arith2026.org/program.html (2nd keynote)
- Retr0id 3mo agoTangential, but wow do they really register a new domain for each year and renew it in perpetuity?
- yzydserd 3mo agoarith2027.org taken, arith2028.org available.
- Retr0id 3mo agoWell, there's an arbitrage opportunity if I ever saw one
- voxl 3mo agoThey would just choose a different domain name, it's not that important and the previous years tend to forward link anyway.
- pclmulqdq 3mo agoI go to the conference frequently and know the organizing committee. It depends on the year (2025 and 2026 did it, but not 2024). And if someone decides to register arith20xx.org, I doubt the conference would buy it.
- torginus 3mo agoI never understood why fixed precision, and integer math isn't more popular. In engineering, we used fixed point all the time, it ran on much simpler hardware and the error is mathematically easy to model. IEEE 754 floats are not only suspect when it comes to theory, but are often outperformed with integers smaller than the mantissa (so less than 24 bits of int can beat a 32 bit float), when it comes to things like loss of precision.
- AlotOfReading 3mo agoI recommend pretty much everyone avoid fixed point and other float alternatives, barring exceptional cases after you've done your own numerical analysis, or you lack floating point hardware (rare these days). Yes, fixed point can use simpler hardware. That's also a completely irrelevant consideration for software. The vast majority of processors are optimized for floats now and some operations (e.g. division) are actually faster. The precision argument also falls apart. Any float with mantissa >= X+Y can get exactly the same results as a QX.Y fixed point. The float will actually perform better across the same range because you have to round it to perform like the fixed point. That means more precision, lower error, automatic normalization, better overflow behavior, a larger working range, etc. And it'll probably be just as fast, unless you're bottlenecked on memory bandwidth of inputs (unlikely). When you inevitably want an exp() or another special function, it's a heck of a lot easier to call libm than implement your own and it will perform better. Floats are also much easier to get right for your coworkers that aren't numerical analysts.
- hilariously 3mo agofixed-point provides uniform precision, exact integer-scaled arithmetic, is deterministic whereas floating point is more convenient but its not a panacea
- AlotOfReading 3mo agoAs I said, floats can provide results that are no worse than a specified fixed point type. So if you want uniform absolute precision, just round down to the required precision. Floating point is generally deterministic in practice with a fairly minor amount of effort, the major remaining issue being library rounding. I actually wrote a library that guarantees this for arbitrary code, with some small, obvious caveats like standard library precision. And the conference talks linked above note, the standard library issues are an increasingly solved problem for modern toolchains. The remaining cases are mostly things you won't do in fixed point. Let me know if you're aware of anyone computing erfc in fixed point for determinism though. I'm not saying there aren't any situations where other systems are justified, but you probably won't know if you fall into any of them without the kind of numerical analysis that most codebases will never receive.
- anematode 3mo agoAgreed, correctly rounded libm functions are great, as long as they don't have miserable worse case behavior (as was famously the case with glibc's pow at one point). One thing I was thinking of doing is manually SLP-vectorizing the high-precision fallbacks that they use when they're close to a rounding boundary, so that you can get better worst-case behavior – but obviously it's good enough already for most purposes. I'm honestly surprised though that JS engines don't just keep using fdlibm though. The ECMAScript spec explicitly encourages it iirc. And if Math.tanh is on your hot path in JavaScript then you're doing something quite bizarre...
- lifthrasiir 3mo ago> as was famously the case with glibc's pow at one point Pow is famously hard anyway because it's bivariate and there is no currently known way to work around the table-maker's dilemma (TMD). CORE-MATH even crashes upon a new required precision record, because it intentionally avoids Ziv's rounding.
- nish__ 3mo agoAt what point are we going to realize that computers will never work for floating point math. If your numbers are not exact there will always be a better solution for what you are doing that does not involve a computer.
- pix128 3mo agoRepresentations other than the standard IEEE-754 can store floats in arbitrary precision.
- mananaysiempre 3mo agoI was a bit puzzled by your second sentence, so I searched around a bit and... do I have this right? - There’s a well-known way (“Ziv’s rounding”) to get (among other things) a correctly rounded double-precision pow(), but in bad cases it can get slow, meaning really quite slow in practice and we’ve got no idea how slow in the worst case (nobody knows what the worst case is). - There’s a recent, guaranteed-correct way[1] to get (specifically) a correctly rounded double-precision pow(), but the last step requires “enough” precision and we’ve got no idea how much that actually is, so CORE-MATH uses 256 bits of mantissa and crashes if that turns out not to be enough (no such cases are currently known). - (Bonus) For most special functions [not just the bivariate ugly duckling of pow()], there’s essentially no hope of getting a correctly rounded quad-precision version anytime soon. [1] https://inria.hal.science/hal-04159652v2 https://inria.hal.science/hal-04159652v2
- Retr0id 3mo agoThanks for the writeup, claude
- _alternator_ 3mo agoYeah, interesting finding in the headline, the rest is just Claude.
- userbinator 3mo ago[flagged]
- ddtaylor 3mo ago[flagged]
- Retr0id 3mo agoAnd the other half of the community seems fixated on upvoting AI slop.
- ddtaylor 3mo agoSounds needlessly divisive. Why not criticize the content instead of the source or medium?
- queenkjuul 3mo ago"The content is AI slop and not worth reading"
- fragmede 3mo agoWe all want signal and no noise, but complaining about whether or not it's noise is just more noise.
- 3mo ago
- drnick1 3mo agoThis is interesting, but even without relying on JS, most users are already fingerprintable by the combination of IP + user agent.
- Aurornis 3mo ago> One tanh call on the right input is a per-OS signature. Claim macOS, return Linux math bits, and you have contradicted your own User-Agent. They (or rather the LLM that wrote this) missed that this is possibly fingerprintable to browser version range, which is slightly more interesting. Most users aren't spoofing their user agent headers to be a different operating system. Most fingerprinting solutions aren't trying to infer your operating system, they only care about semi-unique things that show up. It's an interesting finding. I wish they had taken some time to have a real person write it up. This is too heavily LLM written to ignore.
- jeroenhd 3mo ago> Most users aren't spoofing their user agent headers to be a different operating system. The people behind the LLM behind this blog post are. They're trying to pretend their robots are people to sell other websites' data to their customer. It's easier to pass bot detection gates if you pretend to be a physical machine running Windows or macOS than if you honestly admit you're using Linux on a VM.
- reactordev 3mo agoThe Internet is a cesspool of scams now
- d1ss0nanz 3mo agoAlways was.
- pocksuppet 3mo agoscraping, however, is not intrinsically a scam.
- mplewis 3mo agoIt is when you're doing it like the LLM companies are: at scale, to the degree that you're taking down my site, without my consent by masking your user-agent, for the purpose of stealing data I didn't authorize you to have.
- jeroenhd 3mo agoKind of a smart move by this company: write up an AI analysis of all fingerprinting techniques in hopes they get fixed after outrage so their scraping company can make more money. If it weren't for companies like this, fingerprinting wouldn't be so ubiquitous and the internet would be a better place in general. I prefer articles like this coming from the other side of the battle (fingerprint.js and friends) because at least their motives are clear.
- codedokode 3mo agoI disagree, fingerprinting is necessary to track humans and it will be used regardless of scrapers being there or not.
- coldbrewed 3mo agoI work at a CDN that provides bot detection services. I agree that there's baseline necessity in terms of fraud detection, and if not necessity then definitely financial motivation to fingerprint. But these days, abusive scraping is far and way the the main driver for fingerprinting. We don't fingerprint for ad purposes, and we destroy PII for humans as fast as we can because PII should be treated as radioactive. But we see customers that are constantly burned by abusive scrapers and the scrapers aren't slowing down. The current approach to scraping is strip mining the Internet and is having the corresponding pollution effects that you'd expect. I'm fine with individuals doing whatever weird automation they want, more power to you, but it's this industrial scale crawling and extraction that's degrading the Internet from all angles.
- tormeh 3mo agoDo you think this could drive a shift towards more efficient web tech? I.e. more static websites, or websites served by faster software?
- deleted 3mo ago[deleted]
- 3mo ago
- a-dub 3mo agohow hardened are modern browsers with respect to detecting underlying os? seems like there would be loads of gaps?
- majorchord 3mo agoThere are boatloads of gaps.
- rafeuddaraj 3mo ago[flagged]
- amelius 3mo agoCan't we make fingerprinting illegal, as in, jailtime illegal? Would not solve everything but still help a lot.
- chaboud 3mo agoI'd rather penalize the application than the technique. Windows was rumored to long have "quirks" that would do better things for apps that had bugs that the OS ended up fixing instead of the app. Javascript systems have long had polyfills for varied browser feature comparability gaps. Whether you agree with these, making probing detection via fingerprinting illegal would take away this lever. Making surreptitious tracking via fingerprinting illegal? Even for state actors? Yeah, that's probably reasonable. If someone is going to wear a tracking collar in exchange for "free" services, a little disclosure makes sense.
- Terr_ 3mo agoYeah, the problem is how the data is kept and abused afterwards.
- akersten 3mo agoWhy should it be illegal for me to recognize the way you walk into my store, even though you're wearing a mask and a trenchcoat? Some vague sense of indignation? Yeah, tracking bad, I get it, but are whatever damages that kind of legislation would prevent (probably nothing measurable) really more important than fixing the easy, in our face social problems that politicians could instead be focusing on?
- altcognito 3mo agoBecause you don't have a right to know everything about me, follow me to my home, my purchasing preferences, and so on and so forth.
- simondotau 3mo agoHoly slippery slope, Batman. Just because you don't have a right to know everything about you, follow you home, and see what you bought elsewhere, doesn't mean I'm not allowed to observe how your [thing claiming to be a browser] behaves when it connects to my website. If you want to make it harder to guess whether you're human or a malicious bot, you're going to find yourself clicking on more than just traffic lights and bicycles in the near future.
- deleted 3mo ago[deleted]
- mrsssnake 3mo agoJavaScript was a mistake.
- qurren 3mo agojust inject this with your favorite JS injection plugin let oldTanh = Math.tanh; Math.tanh = x => oldTanh(x) + Math.random()/10000000;
- sanxiyn 3mo agoThe article addresses this: search for "No noise".
- deleted 3mo ago[deleted]
- chjj 3mo agoit's elegant, but i prefer: Math.tanh = Math.random;
- cozzyd 3mo agosince tanh is probably being used as a sigmoid, it's probably better to replace with just randomly changing the sign.
- gruez 3mo agoGreat, now you'll be outed as "hides fingerprint", which is probably more identifying than if you returned a normal value.
- hahahaa 3mo agohttps://xkcd.com/1105/ https://xkcd.com/1105/
- Klonoar 3mo agoMultiple anti-bot vendors will detect that replacement and use it as part of their fingerprinting process.
- bakugo 3mo agoIf this becomes common, it's trivially detectable with good ol' toString().
- torginus 3mo agoWhat I don't get is that Chrome is hundreds of megabytes of just executable code, I assumed they statically linked half the userland. Also, I though tanh isn't a function, but an intrinsic emitted by the JS JIt that uses CPU instructions - which might be fingerprintable as well, but it's weird that for a math operation, you need to branch to a 'dlsym()' function.
- pocksuppet 3mo agoThe x87 FPU implemented transcendental functions in microcode. Most instruction sets don't implement them. Mmicrocode is actually slower than software, since it doesn't get the benefit of things like branch prediction.
- mmis1000 3mo agoChrome is the only browser that preserve unused bit in value NaN through non JITed mode as far as I remember. And that bit become 0 when code get JITed.
- coppsilgold 3mo agoEven Tor Browser (/mullvad-browser) gave up trying to obscure the operating system though arguably they shouldn't have. There appear to be too many fingerprinting vectors.
- ranger_danger 3mo agoTor Browser straight up does not even modify navigator.platform at all, so it's incredibly easy to see when you're not using e.g. Windows.
- coppsilgold 3mo agoI believe they used to make the user-agent appear to belong to Windows but then they stopped doing it with the excuse that there are other ways to tell anyway. The OS doesn't really matter, the amount of entropy it contains is very low. As long as the anonymity set of browser-users is large it's all good. And I believe Tor Browser accomplishes this objective.
- chjj 3mo agoI think they made the right call on that. It's unclear to me whether hiding the OS is even possible. There's just too much OS-specific behavior that happens inside (and outside) a web browser. It's hard to account for all of it. OS rendering differences can likely betray you even when canvas extraction is blocked/noised. At least one tor-browser dev has publicly confirmed that you can't even hide the difference between X11 and Wayland[1], nevermind two entirely different OSes. [1] https://forum.torproject.org/t/linux-is-it-alright-to-run-the-tor-browser-on-wayland/15201/6 https://forum.torproject.org/t/linux-is-it-alright-to-run-th...
- coppsilgold 3mo agoIt's not surprising that JS would out you, what I am wondering if whether or not volunteering OS information is foolish when it may not be possible to determine without JS. Why give up information when you don't have to? Some people disable JS at least some of the time.
- andai 3mo agoI am not the NSA, but on an unrelated note, this delights me!
- fweimer 3mo agoRecent glibc uses the correctly rounded tanh from CORE-MATH, so it returns different values than what's quoted in the article. It's unclear today if it's possible to achieve reasonable performance for other transcendental functions with correct rounding, so other functions have their own unique fingerprints.
- WarOnPrivacy 3mo ago[dead]
- IvanK_net 3mo agoI think the screen resolution is also fingerprintable. That is why a browser should resize your window to a random size each time you visit a website.
- mmis1000 3mo agobrowser report where your browser window (not position in tab) is even page itself never need to use it. https://developer.mozilla.org/zh-CN/docs/Web/API/Window/screenLeft https://developer.mozilla.org/zh-CN/docs/Web/API/Window/scre...
- jmward01 3mo agoIs this even a fight that is possible to win here? Run enough functions and between timing comparisons (x takes 2.5 y) and rounding (things like this) and I suspect you can nail os/exact machine and possibly even other tasks running on that machine. I'm not sure there is a viable way to stop this. At best just make it a little harder? Society and legislation need to catch up here. It is like a lock on my door. Locks don't stop people. They just deter a few people and delay a couple more but a determined person can (likely very easily) break into my house. That is why we need society to call it out that it isn't right (people avoiding buying things they think are stolen, shunning those that do it, etc etc) and laws that step in (it is a crime to break into my house. real resource dedicated to tracking down and stopping people that do it, etc). A similar approach needs to happen here. It should be illegal to track a person like this and people that get hired at a place using the gains of it should shun those companies and society should shun those companies.
- nradov 3mo agoSure, except that in cyberspace a lot of the people who are doing things that are — or should be — illegal are located in jurisdictions where no enforcement is possible. Places like Russia, Myanmar, and North Korea have no concept of the rule of law and criminals who scam foreigners are actively protected by local authorities. So analogies to door locks completely break down there.
- RunSet 3mo agoOne could browse with javascript disabled. It may be that downloading and executing arbitrary code with each page load is naive- even in a sandbox developed by the world's largest advertising corporation.
- omoikane 3mo agoI hope this eventually ends up in https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ so I can see how unique my math functions are relative to a larger population.
- twelve40 3mo agothis is really something. They claim (no idea if true) to have patched 4,000+ signals in 550+ C++ files in Chromium. coveryourtracks.eff.org uses like what, 25 signals?
- luciana1u 3mo ago[flagged]
- tomjakubowski 3mo agoHopefully it takes much less than a millisecond to render a single emoji. Ca. 2018 I wrote some bad OpenGL code which could render a swarm of millions of poop emoji on a rather large display at 60 fps, so that was less than ~16e-6 ms per emoji.
- eschaton 3mo agoSounds almost like allowing web pages to run scripts was a mistake.
- hotsalad 3mo agoRan Math.tanh(0.8) on Firefox on Windows and got the value that the article says is associated with Linux. Wonder why they only ran this on one browser.
- simondotau 3mo agoThis is AI slop, written for a company that is contributing to the enshittification of the web.
- zombot 3mo ago> Scrapium is Scrapfly’s scraping browser That's what this article is about, their scraping browser fakes the math functions of other browsers depending on host OS, so they can disguise the fact that they're only here for the scraping. The internet would be better without them.
- cute_boi 3mo agoIf you want ppl like me to read your article, please stop writing like 80% of text on AI. Use it to correct grammar, typos, and similar issues, but please do not use it to write the whole article. However, thank you for the information.
- deleted 3mo ago[deleted]
- barbolo 3mo agoIt seems fixed. I've tested some Math ops that were previously failing and now are consistent on Chrome 150.0.7871.128 for linux and 150.0.7871.129 for macOS.