I loaded the site and went through the stuff and it worked fine. Then I turned on my VPN, and it gave me a new ID.
Changing my VPN endpoint and refreshing the page didn’t work, it still knew who I was, but closing the window and quitting the browser before changing the VPN again gave me a third ID.
They seem to know quite a bit about my phone, but it doesn’t seem like there is much that it could differentiate it from another person with the same model of phone.
This was a fun exercise.
It’s interesting to me because while it’s mostly correct in each instance I tried it (phone, desktop) it actually gets some pertinent information incorrect.
For one, it only recognized the one monitor I had the browser open on, I have four monitors, so it got the resolution correct for a single monitor, but fails to capture the others, and so technically if I opened it on a different monitor with a different resolution (I had two that have different resolutions), that aspect of the fingerprint should change.
Secondly, when I went to this link from my cell phone it registered it as me typing the link in by hand while on PC it correctly registered where the link originated from (here on lemmy). Although I was using Jerboa on Android so perhaps it can’t read link origin from Jerboa (which is good).
Finally, it registers my Wayland session as X11, although I’m not sure if that’s a current limitation of browsers since Wayland isn’t the dominant compositor yet and perhaps hasn’t been added to browser user-agent info yet.
Needed to enable JS.
Honest question, do you browse without JS enabled? I suppose you could just whitelist sites that you need it for.
Some folks browse using Tor or other high-privacy respecting browsers, in which things like NoScript are a default.
Anyway, yeah, NoScript is still pretty popular and if I recall correctly you can whitelist and regex with it. I just use the same functionality to disable javascript that is in uBlock Origin, personally.
Though uBlock doesn’t set javascript.enabled to false, only blocking any kinds of js. Meaning, the
<noscript>tag (with the ever so useless error message) doesn’t get triggered, which results in some sites built in a defective framework just being empty.The
<noscript>messages seem to work for me with uBO.Wha, they do? For me, only in Dillo and the likes. But none of
javascript.flags is touched, so maybe there is a extension API trigger?
On my computers I enable js only for the url I connect to, and then if nothing works, I start enabling it for other urls or skip using the site.
You get pretty handy with it pretty soon.
I’ve used ublock for like +10 years if not more
I’m using uMatrix. I set JS as off by default.
So yeah, more complex whitelisting.
A small point but it assumes that your browser’s self-declared timezone is “true” to where you live. My timezone is spoofed to UTC+0; my VPN server is in a different country; and my browser language is set to en-us. I feel like if you see a user whose settings are all of the above then you can assume that none of those three data points actually describe the user, unless they coincidentally are a US English speaker or live in UTC+0, but that’d just be them coincidentally living where anti-fingerprinting browsers report you as.
Anti-fingerprinting is a fingerprint too.
Only if too few people do it.
I know that…? I’m not sure how this relates to the comment you replied to.
sulfidedisburseangledafternoontipper ( sulfidedisburseangledafternoontipper@piefed.blahaj.zone ) English
5·2 months agoIronfox seems to do its job. Me fingerprint every time. Vanadium as well (though it does disclose more in-depth device data).
Today all websites that have anti bot protection using pow (proof of work) already use cookies. Which is before they “ask you if you want to agree with cookies” haha. Dammit eu rules.
ya the cookie law is outdated and short sighted, the law should instead extend to ability to consent to send any identifying information instead. (Easier to investigate and potentially punish websites that do not respect the setting)
The browser can disable cookies if you want since 1996. So this law was from the beginning outdated. Xd
Rather then removing it. They are extending this law with additional rules and design ideas. 😭😰
❤️
A website doesn’t need to ask you for consent if the cookie is “strictly necessary”. I’m not sure how those anti bot protections work, but I bet they made it fit the definition of a “strictly necessary” cookie.
I know. I don’t want those stupid cookie banners. Hence my “dammit eu rules”.
I created my own anti bot protection see https://angieguardian.org/. So basically all of them use cookies after you completed a pow or captcha. So next time you load the page it doesn’t ask you again. Those cookies may expire within several hours until 1 week depending how the server/anti bot software configure them.
That are technically required cookies, they require explicit consent
I mean “1 in 122.7 million browsers look like” mine meaning it got me down to one out of about 2% of all internet users globally. I’d say it’s still pretty difficult to target anything at that many people and have it be relevant. Just knowing my location and that it’s a weekend basically gets down to that many or maybe fewer people on it’s own since fewer than that live in my city permanently, and adding tourists/visitors and people who work on weekends, that might be about right for how many devices are online in my city right now. And that was browsing with my less locked down browser on my phone.
Actually, looking with ironfox, though, actually reduced that to about 112m. I think part of that is that ironfox apparently still seems to enable the “do not track flag” even though it was removed from Firefox because it actually made people more easy to track and no sites who track are ethical so they are not going to obey something like that. So now it’s rare and makes for a really good tracking point. Need to figure out how to remove it from ironfox I guess.
Your math is not mathing, 100/122,700,000=0.000000814995925% not 2%
Also this seems to be a vibe coded website and probably doesn’t use the most advanced fingerprinting techniques. Most likely your browser is actually unique if you go to https://amiunique.org/ you might get a more accurate answer.
I was doing a little more complex math than just the 1 in 122.7m. That seems to be unique browsers not unique human users. I added some calculations based on how many browsers are used by humans vs bots and various other nonhuman users. It’s extreme rough with a lot of guesstimation and rounding based on some googling. But that’s beside the point.
I was trying to figure out the difference between fingerprinting a Mozilla Firefox browser from the play store and the IronFox browser from Fdroid. I had expected it to be significantly reduced accuracy since it’s explicitly set up to be more resistant to fingerprinting than vanilla Firefox.
When I did some digging and looking at other sites. The biggest factor seems to be the combination of it reporting Firefox as the agent and having the DNT flag and the global privacy flag or whatever it is called. Since only Germany has been able to enforce those legally and only in a single case against LinkedIn, but no cases against the bigger tracking companies that aren’t user facing and thus wouldn’t even care about legal stuff since proving standing with that many layers would be difficult, Mozilla decides to remove those a couple of years ago as many people weren’t setting them and so it made people who were setting them more susceptible to fingerprinting since they were more unique. IronFox has argued that the settings should stay on because it’s legally enforceable in Germany and maybe some day will be I’m other places. But IMHO that doesn’t help people getting fingerprinted now or for the next many years. And now since IronFox is basically the only one doing it, the combination of Firefox agent and that header flag means it narrows you down to IronFox users almost exclusively other than maybe some people using really old versions of Firefox, but you could add some criteria that gibe you the version, too, and how many of those are there in the world. A very small percentage of all internet users. And combine that with UTC offset and if you live somewhere like UTC-1 I bet you’re the only user. LOL.
But even in other less tech savvy areas of the world it would be pretty small and a few more data points could easily get you a unique user. People in places like UTC+2 or mainland US, probably there are a lot more privacy thinking folks using IronFox or any other.
Anyway, I changed those settings manually in about:config based on feedback from the IronFox dev that it was set on purpose. But I haven’t had a chance to see how much less unique it made me yet.
This is quite revealing and impressive. But it’s also annoying when people don’t offer any preventative measures.
Amazing and terrifying. Thanks for the link. I am not very technical when it comes to the web so this was eye opening.
I used to have a small Firefox extension that would stagger my key presses to muddy the waters, but it made typing impractical, so I eventually removed it.
I wonder what else I can do on my end. And most importantly, what browsers can do for all their users, technical and not, by default.








