• Dessalines@lemmy.ml
    link
    fedilink
    arrow-up
    98
    arrow-down
    1
    ·
    4 months ago

    This ones my fave: https://amiunique.org/fingerprint

    It shows the percentages of people who use your same browser features (called similarity ratios), and can determine whether you’re unique in their dataset. Can help for tweaking browser settings to try to make yourself not unique.

    • Zach777@lemmy.ml
      link
      fedilink
      arrow-up
      16
      ·
      4 months ago

      Unironically a solid way to block a lot of tracking. Although they can still fingerprint you I think.

      • Brimstone@lemmy.ml
        link
        fedilink
        arrow-up
        38
        ·
        4 months ago

        Nothing makes you more unique than being one of the few people who disable java script

        • Zach777@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          4 months ago

          Honestly I would rather they fingerprint compared to running random code from websites.

  • nixukty@lemmy.zipdeleted by creator
    link
    fedilink
    arrow-up
    50
    arrow-down
    1
    ·
    4 months ago

    Vibe coded af, how has nobody spotted this. The website swears the text was written by a human, and either they have contracted chronic GPT-virus or are an LLM

    edit: this is made by Rise Up Labs which is an ai psychosis company

      • nixukty@lemmy.zipdeleted by creator
        link
        fedilink
        arrow-up
        12
        ·
        4 months ago

        AI is quite good at web design now, but it still has a distinct style. Claude in particular LOVES to mix serif and monospace fonts. This isn’t necessarily a guarantee based on just that, but it did trigger my alarm bells.

        The second biggest thing is the language. LLMs absolutely SPAM slightly vague, short phrases separated by punctuation.

        The language on each data point also is pretty repetitive which implies either sub agents were called or the model was asked individually to write something about it in a specific tone.

        The final nail in the coffin was the company that made it, Rise up labs, which advertised all their AI software on their home page

      • jpeps@lemmy.world
        link
        fedilink
        arrow-up
        9
        ·
        4 months ago

        One clue to me is the “how many times you moved” statement. One actual human “move” is worth hundreds of what the site calls a move. A human would notice that but the reality of it means nothing to an AI.

        Secondly just the language used being quite dramatic but also generic.

        • Bane_Killgrind@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 months ago

          You know it’s just counting the change in acceleration in your phone’s gyroscope chip or whichever it is. If you are typing something the phone “moves” twice with each swipe.

          This page is just putting numbers it’s collecting from your phone into a template paragraph.

  • plz1@lemmy.world
    link
    fedilink
    English
    arrow-up
    34
    ·
    4 months ago

    “We know your IP address”. No kidding, that’s how IPv4 works, even if the browser wasn’t leaking offering it.

    • iglou@programming.dev
      link
      fedilink
      arrow-up
      7
      ·
      4 months ago

      The point is not that they know your IP, but that even your IP already gives away information. That’s why they start with the information, rather than the IP being the source.

      This is not intended to be for people who understand how this works.

      And as someone else said, probably vibe coded.

      • Bane_Killgrind@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        I understand how all of it works. Whether it’s vibe coded or not it, it showed me stuff that I didn’t think about like arbitrary web pages can know my phone tilt, battery level??

        The opsec implications are severe.

        • iglou@programming.dev
          link
          fedilink
          arrow-up
          1
          ·
          4 months ago

          Oh yeah, it’s insane. The only way to truly protect your identity on the internet is by not using the internet. Second best would be tor, I suppose

          • Bane_Killgrind@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 months ago

            Well maybe fingerprint duplication, some secure proxy provides a profile to follow/ plugin to install and all their customers look identical. Still gets your traffic pegged as a customer of that service.

    • mrmisses@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      4 months ago

      Interesting that this one doesn’t detect my battery (says it’s blocked) but the one OP posted can see it

  • Kefla [she/her, they/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    17
    ·
    4 months ago

    Your device carries these typefaces, of the seventeen commonly probed by fingerprinting checks. The specific combination of fonts on your device is nearly unique — like a fingerprint made of letters

    What the fuck why is my browser telling random websites what fonts I have installed? Shouldn’t that be completely irrelevant to everyone except me and my particular device?

    • Dirt_Possum [she/her, undecided]@hexbear.net
      link
      fedilink
      English
      arrow-up
      15
      ·
      4 months ago

      It should be, yes. But browsers like Chrome are literally made by the company that stands to profit from fingerprinting you, so they’re always going to be made to make it easy to do just that. Firefox at least has “resist fingerprinting” option which apparently can limit font visibility to only base system fonts rather than fonts you installed and language-pack fonts. LibreWolf has this on out of the box.

  • Phil Dowson@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    4 months ago

    This post helped me discover that my SurfShark VPN built-in kill switch does not work within the Android app. My home IP was showing.

    I turned kill switch on at the OS level and my IP was correctly showing the VPN IP.

  • magnue@lemmy.world
    link
    fedilink
    arrow-up
    15
    ·
    4 months ago

    I found it interesting that it knows my battery level and current orientation of the phone.

      • slampisko@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        4 months ago

        Potentially to activate battery-saving features? Like AMOLED-black mode if your battery is <15 % or something (and your screen is AMOLED)

        • ☆ Yσɠƚԋσʂ ☆@lemmy.mlOP
          link
          fedilink
          arrow-up
          11
          ·
          4 months ago

          Shouldn’t that be the provenance of the device itself though. My phone already allows me to set a threshold when it should go to night mode for example. The system can tell the browser to switch rendering to night mode. There’s no real reason for the browser then to report to the site.

      • lad@programming.dev
        link
        fedilink
        English
        arrow-up
        4
        ·
        4 months ago

        So that Uber will charge you a higher rate when the battery is low

        I don’t even know it it’s /s anymore

  • tristynalxander@mander.xyzdeleted by creator
    link
    fedilink
    English
    arrow-up
    13
    ·
    4 months ago

    I definitely have misleading information on there, which is great, but I probably need more.

    • colourlessidea@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      Does it matter for fingerprinting if the information is misleading? Unless it’s changing dynamically I guess it’s still helps in identifying a user

      • tristynalxander@mander.xyzdeleted by creator
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        Yeah, I think there are two problems. One issue is that they profile users both for ads and manipulative algorithmic content, and I’d like them to profile me incorrectly in most cases (except like they are less likely to try to sell people on linux things, that’s a great thing I’d like to keep in the profile). The other issue is that they follow individual users using this fingerprinting, again this can be used both to sell things and to manipulate, but it’s a tad creepier since it tracks how you’re unique even compared to people superficially similar to you.

        Ideally, I’d like some extension where I can look at values and either keep them, set them, or randomize them.

  • eureka@aussie.zone
    link
    fedilink
    English
    arrow-up
    11
    ·
    4 months ago

    I’m glad it acknowledges explains the impacts of anti-fingerprinting measures. I’ve seen some others assume that a random canvas is unique rather than one of the many people randomising it the same way, leading to a false “unique” assessment.

    Your browser appears to be returning the viewport in place of the real screen — anti-fingerprinting at work. The substitution is itself distinctive.

    Your browser masked your graphics processor. Firefox and Safari have started returning generic strings — “Mozilla”, “Apple”, “or similar” — instead of the real renderer. The fact that yours did so tells us, with reasonable confidence, which browser you are running. The mask is also a fingerprint.

    • Buddahriffic@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      4 months ago

      I like that they covered all the possibilities for the do not track flag, as I saw it as useless from the very start, as by then I realized the honour system didn’t mean shit and it would just be another piece of data.

  • Anna@lemmy.ml
    link
    fedilink
    arrow-up
    10
    ·
    4 months ago

    Opend it in Tor Browser inside a Whonix dispVM inside Qubes OS it got nothing on me

    • QuietCupcake [any, they/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      6
      ·
      4 months ago

      I tried it with Tor browser on a standard OS, hoping I’d get a similar result to what you got using Tor on Whonix, etc. It fed me a line about how my information was still shared but because javascript is turned off, it can’t tell me what that information is. More like it won’t tell me, because amiunique.org and other sites like this do so just fine. I know I can turn js on and reload, but part of the point would be to see the difference in info shared with it on vs off but this place can’t test that.