- cross-posted to:
- technology@lemmy.world
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.world
- technology@lemmy.world
This ones my fave: https://amiunique.org/fingerprint
It shows the percentages of people who use your same browser features (called similarity ratios), and can determine whether you’re unique in their dataset. Can help for tweaking browser settings to try to make yourself not unique.
Yay, I’m completely unique! I won!
Wait a minute
TIL LibreWolf randomizes some fingerprinting targets.
Yes and it will appear unique every time because every visit is using a different combination.
You’ll be unique be less trackable.
Attribute number 1 already says 0%. We’re done here.
They basically asked for your name, birth date, and mother’s maiden name, and your browser just gave it to them and offered even more.
My Mum always said I was unique.
Now I have proof!
Just being in Australia, and setting the timezone correctly gets you to below 0.6%
😒
that’s pretty comprehensive, and similarity ratios show how easy it is to create a unique fingerprint for somebody if you hash a few of these metrics together for example.
The percentage of, normally, privacy-aware people
I like clickclickclick.click
I am a unique signiture but it also got my OS wrong and couldn’t get my time zone
Y’all I think I won privacy
what does “You are unique among the 5119710 fingerprints …” mean?
all trackers hate this one trick

Unironically a solid way to block a lot of tracking. Although they can still fingerprint you I think.
Nothing makes you more unique than being one of the few people who disable java script
Honestly I would rather they fingerprint compared to running random code from websites.
Vibe coded af, how has nobody spotted this. The website swears the text was written by a human, and either they have contracted chronic GPT-virus or are an LLM
edit: this is made by Rise Up Labs which is an ai psychosis company
How can you tell that it was vibe coded? Genuine question.
AI is quite good at web design now, but it still has a distinct style. Claude in particular LOVES to mix serif and monospace fonts. This isn’t necessarily a guarantee based on just that, but it did trigger my alarm bells.
The second biggest thing is the language. LLMs absolutely SPAM slightly vague, short phrases separated by punctuation.
The language on each data point also is pretty repetitive which implies either sub agents were called or the model was asked individually to write something about it in a specific tone.
The final nail in the coffin was the company that made it, Rise up labs, which advertised all their AI software on their home page
One clue to me is the “how many times you moved” statement. One actual human “move” is worth hundreds of what the site calls a move. A human would notice that but the reality of it means nothing to an AI.
Secondly just the language used being quite dramatic but also generic.
Thanks! I’ll have to keep an eye out for those things.
LLMs always write with a very dramatic tone. I really hate that high impact language now.
You know it’s just counting the change in acceleration in your phone’s gyroscope chip or whichever it is. If you are typing something the phone “moves” twice with each swipe.
This page is just putting numbers it’s collecting from your phone into a template paragraph.
“We know your IP address”. No kidding, that’s how IPv4 works, even if the browser wasn’t
leakingoffering it.The point is not that they know your IP, but that even your IP already gives away information. That’s why they start with the information, rather than the IP being the source.
This is not intended to be for people who understand how this works.
And as someone else said, probably vibe coded.
I understand how all of it works. Whether it’s vibe coded or not it, it showed me stuff that I didn’t think about like arbitrary web pages can know my phone tilt, battery level??
The opsec implications are severe.
Oh yeah, it’s insane. The only way to truly protect your identity on the internet is by not using the internet. Second best would be tor, I suppose
Well maybe fingerprint duplication, some secure proxy provides a profile to follow/ plugin to install and all their customers look identical. Still gets your traffic pegged as a customer of that service.
I prefer https://www.deviceinfo.me/
Interesting that this one doesn’t detect my battery (says it’s blocked) but the one OP posted can see it
Well too bad!

🗿
the data is still there tho
Can’t trust vibecoded website tbh cause they’re just saying BS there, as longest the javascripts off, it wouldn’t be able to obtain the obvious data of your devices
That is not true, a lot of it is sent willingly by your browser.
And they could display it if the website was well done
If you’re referring to browser user agent, then yes it’s trackable but other than that it is useless with no JS cause it can’t access timezone, browser plugin, screen size, font or webgl rendering fingerprints.
Also I don’t use “most browser” like chrome, I mostly use firefox focus or safari for my iPhone running lockdown mode; also librewolf in my personal computer.
You can still fingerprint a user based on CSS features.
https://fingerprint.com/blog/disabling-javascript-wont-stop-fingerprinting/#css
You absolute can fingerprint someone without JavaScript enabled. This article explains what signals a website can use when JS is disabled, and those signals include probing what CSS features your browsers supports.
https://fingerprint.com/blog/disabling-javascript-wont-stop-fingerprinting/
Unfortunately it looks like the demo link in their article doesn’t exist anymore. It definitely used to, because I remember testing it few years ago. But the write up is still good.
Looks like the demo is open source: https://github.com/fingerprintjs/blog-nojs-fingerprint-demo
That’s a cool project but most websites are using JavaScript for tracking, and I doubt most website have the afford to even use CSS just to track someone who doesn’t have JS on.
Whoops, I dunno why it’s formatted weirdly
How do I turn off JavaScript?
Your device carries these typefaces, of the seventeen commonly probed by fingerprinting checks. The specific combination of fonts on your device is nearly unique — like a fingerprint made of letters
What the fuck why is my browser telling random websites what fonts I have installed? Shouldn’t that be completely irrelevant to everyone except me and my particular device?
It should be, yes. But browsers like Chrome are literally made by the company that stands to profit from fingerprinting you, so they’re always going to be made to make it easy to do just that. Firefox at least has “resist fingerprinting” option which apparently can limit font visibility to only base system fonts rather than fonts you installed and language-pack fonts. LibreWolf has this on out of the box.
Thats part of how you’re fingerprinted.
This post helped me discover that my SurfShark VPN built-in kill switch does not work within the Android app. My home IP was showing.
I turned kill switch on at the OS level and my IP was correctly showing the VPN IP.
Enable the kill switch in the VPN settings of Android
I found it interesting that it knows my battery level and current orientation of the phone.
I can understand the latter since it might want to render differently, but why does it need to know the battery level?
Potentially to activate battery-saving features? Like AMOLED-black mode if your battery is <15 % or something (and your screen is AMOLED)
Shouldn’t that be the provenance of the device itself though. My phone already allows me to set a threshold when it should go to night mode for example. The system can tell the browser to switch rendering to night mode. There’s no real reason for the browser then to report to the site.
So that Uber will charge you a higher rate when the battery is low
I don’t even know it it’s /s anymore
certainly how making your battery level available to apps is getting used I’m sure
It got my phone’s orientation wrong
Same tbh
Well they tried

I definitely have misleading information on there, which is great, but I probably need more.
Does it matter for fingerprinting if the information is misleading? Unless it’s changing dynamically I guess it’s still helps in identifying a user
Yeah, I think there are two problems. One issue is that they profile users both for ads and manipulative algorithmic content, and I’d like them to profile me incorrectly in most cases (except like they are less likely to try to sell people on linux things, that’s a great thing I’d like to keep in the profile). The other issue is that they follow individual users using this fingerprinting, again this can be used both to sell things and to manipulate, but it’s a tad creepier since it tracks how you’re unique even compared to people superficially similar to you.
Ideally, I’d like some extension where I can look at values and either keep them, set them, or randomize them.
Great news. My VPN is working!
I’m not even on VPN and I was located half a country away in Europe
I’m glad it acknowledges explains the impacts of anti-fingerprinting measures. I’ve seen some others assume that a random canvas is unique rather than one of the many people randomising it the same way, leading to a false “unique” assessment.
Your browser appears to be returning the viewport in place of the real screen — anti-fingerprinting at work. The substitution is itself distinctive.
Your browser masked your graphics processor. Firefox and Safari have started returning generic strings — “Mozilla”, “Apple”, “or similar” — instead of the real renderer. The fact that yours did so tells us, with reasonable confidence, which browser you are running. The mask is also a fingerprint.
I like that they covered all the possibilities for the do not track flag, as I saw it as useless from the very start, as by then I realized the honour system didn’t mean shit and it would just be another piece of data.
Opend it in Tor Browser inside a Whonix dispVM inside Qubes OS it got nothing on me
I tried it with Tor browser on a standard OS, hoping I’d get a similar result to what you got using Tor on Whonix, etc. It fed me a line about how my information was still shared but because javascript is turned off, it can’t tell me what that information is. More like it won’t tell me, because amiunique.org and other sites like this do so just fine. I know I can turn js on and reload, but part of the point would be to see the difference in info shared with it on vs off but this place can’t test that.
why would my browser share a list of fonts?
so the site knows what it can render
I don’t anything about web development, so I assumed websites told browsers: ‘Hey type this text in X font.’ If the machine didn’t have that font the browser would fall back to another font.
that would be a sensible way to do it, but turns out the browser leaks a lot of this information to the site because reasons
Further, why are the fonts unique? Why doesn’t every phone of the same model with the same languages have the same fonts enabled?


















