4 ms·
I'd like to have more control over the Javascript runtime in the browser. Defeating this identification trick is only one of the reasons. Suppose you had a li
by ds9 13y ago
I'd like to have more control over the Javascript runtime in the browser. Defeating this identification trick is only one of the reasons.
Suppose you had a list of options and could selectively disable, for example, monitoring of mouse movements on one site, or ajax on another. And for this in particular, something that would feed the site random values from a particular range for fonts installed, plugins installed, screen size and other such information.
Using that data in development would still work because 99% would keep the default "true" values, and the few geeks who would change them would get what they should/would expect on sites that rely on those values. But everyone should have the power to control what info they're giving out, and what Javascript is allowed to do on their own device.
- WiseWeasel 13y agoThey didn't use any JavaScript to get this information. Most of it is sent by your browser in the request headers, and the font detection used Flash and Java. They could have used JavaScript to detect fonts as a fall-back when Java and Flash are disabled, but it's relatively complicated to do so (requiring you to know the rendered width of a string for each font you're trying to detect), and it was not included in this example. Sending incorrect information for Java or Flash fonts is an interesting idea, and likely would not affect user experience, as non-standard fonts are often served with the animations. Sending the wrong screen size might get you a mobile site served when you were wanting non-mobile or vice-versa. IP address and ISP are valuable bits of identifying information as well, and those are more difficult to address without using a proxy. But I would bet that randomizing your screen size for each request would break most fingerprinting code, since that would be assumed to be static.
- JoeAcchino 13y ago"They didn't use any JavaScript to get this information." The list of installed plugins is retrieved via JS: window.navigator.plugins. Not sure about fonts, though.
- WiseWeasel 13y agoAh, good catch. I guess the JS navigator.plugins list is quite a bit more thorough than the plugin information sent in your request headers (which I believe is limited to Java: yes/no).
- gorhill 13y ago> "They didn't use any JavaScript to get this information" Then what are the five "no javascript" messages I see?
- hipsters_unite 13y agoI have Java/Flash disabled by default and yet it was still able to populate a fonts list for me. Forgive my ignorance, but surely that's not possible?
- deleted 13y ago[deleted]
- userbinator 13y agoI'd like to have more control over my browser in general, and I think many here also share the same thought. The issue is that browser vendors seem to make it harder and harder to customise these sorts of things by removing configuration options etc. And requiring to install an extension/plugin to get this ability just makes it harder for the average user to become aware of and take control of this.