• Karl@literature.cafe
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    My jaw dropped when I read the what angle my device is being held at, how many times I scrolled and tapped, what my position is!!!

    How is this even legal?!

    I always thought they just took my location, my device name etc. I had no idea it’s this deep.

  • luciferofastora@feddit.org
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    It identified my many-years-old phone with “360x760 pixels rendered at 3x density” screen as “recent, high-end display”. Bitch, this wasn’t even high-end when I bought it. It was small, it was cheap, it was barely “recent” when I bought it.

  • RememberTheApollo_@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    I’m honestly not impressed. Basic IP address that didn’t really provide an accurate location, plus the (no shit sherlock) state and country it was in. Told me it was ios, a browser, and that I’d turned a bunch of stuff off.

    That’s it.

  • Zacryon@feddit.org
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    Well then I am glad that it got most of it wrong. I don’t even put thaat much emphasis on fingerprinting countermeasures. Apparently, using Firefox in a private tab is enough.

  • lobo@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    central europe, maybe its due to architecture the isp has wifi access points around the city and people connect to them

    back when it was starting there wasnt even isolation between clients, we used to send random shit to printers on the network as kids

  • plz1@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    “We know your IP address”. No kidding, that’s how IPv4 works, even if the browser wasn’t leaking offering it.

    • iglou@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      5 months ago

      The point is not that they know your IP, but that even your IP already gives away information. That’s why they start with the information, rather than the IP being the source.

      This is not intended to be for people who understand how this works.

      And as someone else said, probably vibe coded.

      • Bane_Killgrind@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 months ago

        I understand how all of it works. Whether it’s vibe coded or not it, it showed me stuff that I didn’t think about like arbitrary web pages can know my phone tilt, battery level??

        The opsec implications are severe.

        • iglou@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          5 months ago

          Oh yeah, it’s insane. The only way to truly protect your identity on the internet is by not using the internet. Second best would be tor, I suppose

      • Zerush@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        5 months ago

        The public IP is irrelevant, only shows the IP of the server used by your ISP, which can be at the other side of the country. It can maybe identify the ISP, but not the user, less if a dynamic changing IP is used. The public IP is always leaked if you don’t use a VPN or the TOR network.

        • iglou@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          5 months ago

          Absolutely not, the public IP a website sees is your home IP. The resolved location will be inaccurate by design, but the IP definitely identifies you at that time.

          • Zerush@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            5 months ago

            What the website see is the current IP of the used ISP server in this moment. In the last check it was Madrid, several hundreds km from my real home. The public IP isn’t the same as my user IP, which only know my ISP and I (and the police by the ISP, if exist a court order). The public IP don’t show your real location, the website only can use your GPS data if you have it activated or if it appears in your account data (Google, Google Maps).

          • lobo@lemmy.world
            link
            fedilink
            arrow-up
            0
            ·
            5 months ago

            depends on the isp, my router has its own adress on the iternet

            couple of friends have a different isp that layers it users behind multiple nats so half the city would show the same ip on a website

        • Ironfacebuster@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          5 months ago

          Depending on your location it can actually be geolocated into your specific city block, I geolocated an online friend’s IP just for the hell of it (I already knew where they lived) and it spit back out the city block they lived in as well as a lot of other very identifiable information

          Also, if you can ping devices on that network using that IP you can also use that as a way to easily identify users. That’s if they have anything that isn’t firewalled, obviously, but the point stands!

  • Kefla [she/her, they/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    Your device carries these typefaces, of the seventeen commonly probed by fingerprinting checks. The specific combination of fonts on your device is nearly unique — like a fingerprint made of letters

    What the fuck why is my browser telling random websites what fonts I have installed? Shouldn’t that be completely irrelevant to everyone except me and my particular device?

        • Dirt_Possum [she/her, undecided]@hexbear.net
          link
          fedilink
          English
          arrow-up
          0
          ·
          5 months ago

          The site could also be set to display whatever font it wants but also set to list standard fonts that also work which the browser can then choose from on the user’s end if the user doesn’t have the first choice font. That way you the user don’t have to worry about it and there is no way to fingerprint by the browser just handing out an entire list of fonts installed on the user’s system. There are plenty of ways to make things like this work, but the incentive is to keep them as they are or to increase uniqueness so people can be more easily fingerprinted.

    • Dirt_Possum [she/her, undecided]@hexbear.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 months ago

      It should be, yes. But browsers like Chrome are literally made by the company that stands to profit from fingerprinting you, so they’re always going to be made to make it easy to do just that. Firefox at least has “resist fingerprinting” option which apparently can limit font visibility to only base system fonts rather than fonts you installed and language-pack fonts. LibreWolf has this on out of the box.

  • quick_snail@feddit.nl
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    This volume requires JavaScript. That is part of the point — your browser is what is being read.

    Looks like I’m safe

  • Alas Poor Erinaceus@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    How many points of identification are needed to positively ID you? Something like 35 IIRC according to Cover Your Tracks/EFF? Might be remembering wrong 🤔

  • pathief@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    The browser knows and shares way more than this… One of the worst offenders is the list of installed fonts. Pretty sure I stick out so hard just on that.