This is an EFF project that allows you to understand how easy it is to identify and track your browser based on how it appears to websites. Anonymous data will be collected through this site.

  • @jet@hackertalks.com
    link
    fedilink
    English
    172 years ago

    The EFF site is great, it tells you how many bits of information are identifiable.

    If you think you have good protection, go to http://fingerprint.com and see if they can track you across multiple visits. This is a commercial fingerprinting company, on their homepage they have a tracking widget to demonstrate how good they are. So it’s always useful to use fingerprint.com to get an empirical test of if you’re trackable.

      • @varsock@programming.dev
        link
        fedilink
        32 years ago

        7 visits with brave, 7 times identified as the same. I’m using the default options of a fresh brave install

        how did you have such success?

        • @random65837@lemmy.world
          link
          fedilink
          12 years ago

          Not sure honestly, I’m always behind a VPN, which I was changing servers, as if it were actually able to fingerprint me that wouldn’t have mattered so I didn’t want a false positive from making it too easy, I do run GrapheneOS so not sure if the OS is either not sending or randomizing OS info on top of that, that it would normally get. Been a while but the only thing I changed from default in Brave was changing fingerprinting to strict. For the sites I visit its still fine 95% of the time so I leave it that way. I’ve read from others and their browsing habits it breaks a ton of sites. So e YMMV there.

  • @privacybro@lemmy.ninja
    link
    fedilink
    English
    82 years ago

    I have been doing fingerprint research for several years. I’ve done countless builds with various browsers, configurations, extensions, and strategies. (Yes i have too much time for this).

    Here is what I’ve concluded. I hope this helps someone.

    CoverYourTrack is crap, plain and simple. Your best option will always be to randomize. Always. You will not “blend in”. I don’t care if you run Google Chrome on Windows 10 or Safari on iOS, JavaScript exposes way too much info, you will always have a unique fingeprint. Just go play around with fingerprint.com on some normie browser/os setups and you will see what i mean.

    You must randomize all the values that you see on sites like browserleaks.com. canvas, audio context, webgl hash, clientrects, fonts, etc etc. I’d also make sure you are proxifying all your browsers and using random locations. You can do this with Brave somewhat, which has some randomization stuff in it. You can do this with browser extensions as well. Ungoogled chromium also has some randomization for canvas and clientrects i think

    There are only a couple options outside of this that I recommend, in the realm of “generic fingerprint” solutions. TOR browser (they have been on the front lines of this for many years). And also Mullvad browser, which, despite its generic fingerprint goal, seems to also defeat fingerprint.com.

    Tldr, if you want the best experience out of the box that is also very usable, just use Mullvad Browser. They are basically the browser i wished for for like a decade.

  • downpunxx
    link
    fedilink
    82 years ago

    My impression is the thing with modern day ad tracking, selling information to spammers, and hackers is, even if you secure your browser tighter than a drum, any one of your browser extensions, which we’ve given permission to read all site data on every site you visit and interact with, could be keeping extensive logs on your activity and selling that away to the highest bidder. Am I understanding that right?

  • wilberfan
    link
    fedilink
    English
    52 years ago

    Well that’s interesting. I’ve read more than one place the having uBlock Origin is “enough” and that adding Privacy Badger is overkill. I’ve also got AdGuard Home running on a Pi-4. I failed all three tests with Vivaldi Nightly and Arc Browser–both with uBO installed…

    Simply adding Privacy Badger to the existing setup, suddenly I had “strong web protection”.

    • @MonkderZweite@feddit.ch
      link
      fedilink
      12 years ago

      uBlock Origin + Canvas Blocker is it for me. And Total Cookie Protection enabled, wasm disabled, referer trimmed.

      • sendRefererHeader 1
      • referer.trimmingPolicy 2
      • referer.XOriginPolicy 1
      • referer.XOriginTrimmingPolicy 2
  • Karna
    link
    fedilink
    English
    5
    edit-2
    2 years ago

    OS: Ubuntu 23.10 | Browser: Firefox 119 | Add-on: No-Script | Misc: AdGuardHome on Raspberry Pi 4B

    • Karna
      link
      fedilink
      English
      42 years ago

      Same setup, but with Mullvad Browser

  • Melody Fwygon
    link
    fedilink
    English
    4
    edit-2
    2 years ago

    I’ve got really good scores. I’m grading a bit on a curve due to mitigations/spoofs already in place for both browsers that fool the scripts effectively.

    4.45 bits from Firefox. [“System Fonts” is the worst score]

    4.47 bits from LibreWolf. [“AudioContext Fingerprint” is the worst score

    Some Measurements are Ignored; reasons within.

    User Agent - Flawed. This contains no personally identifiable information and spoofing this often causes compatibility and functionality issues. It is OK to spoof for -MORE- functionality if needed.

    WebGL Vendor & Renderer - Spoofed/Blocked Firefox spoofs this via CanvasBlocker and LibreWolf blocks this from being accessed at all. Spoofing allows some websites to feel “satisfied” they have some fingerprint that is otherwise patent nonsense and CanvasBlocker will present the same value to the website/script later if it’s loaded in the same Container/Context.

    Screen Size and Color Depth - Spoofed/Blocked Both Firefox and LibreWolf will spoof/randomize/standardize these viewport values back to scripts to preserve privacy. For functionality reasons my LibreWolf installation is my minimal plugin environment. This allows me to quickly and temporarily load a website I might NEED to use without compromising on Privacy while not being forced to troubleshoot which plugins might be preventing the site from loading in Firefox.

    System Fonts - LibreWolf Only Spoofed/Blocked Value is Randomized

    • @mateomaui@reddthat.com
      link
      fedilink
      English
      4
      edit-2
      2 years ago

      While everyone’s at it, you may want to check for leaks with Mullvad VPN’s service, it picked up a DNS leak for me that got past a few other sites:

      • LostXOR
        link
        fedilink
        02 years ago

        Huh, it says I’m leaking DNS servers and WebRTC IPs, but I don’t have secure DNS enabled, and I’m not really sure why WebRTC leaking my IP is a problem considering I’m already “leaking” my IP just by visiting a website.

        • @mateomaui@reddthat.com
          link
          fedilink
          English
          1
          edit-2
          2 years ago

          In my case I had reset a device and didn’t disable IPv6. Once I fixed that the bottom two tests still say I’m “leaking”, but all three show only one IP each, for my VPN’s servers (maybe different IPs, but one for each.)

          If I were actually leaking, IPs shown would be for a local DNS, or my residence, etc.

  • swayevenly
    link
    fedilink
    42 years ago

    Anyone know how I can get improved fingerprinting results on Firefox Android? Currently its at 16.56 bits and it says I have strong protection against web tracking. NoCanvas isn’t availble on Android devices.

  • @mateomaui@reddthat.com
    link
    fedilink
    English
    4
    edit-2
    2 years ago

    Using Firefox on iPhone

    edit: Nvm previous result, I got the same result OP did with Firefox and Safari, I realized I was testing on my wifi with a pihole… switched to mobile network only and protection dropped to partial.

    edit2: but Firefox Focus still has strong protection:

    https://i.imgur.com/qeeuHKJ.jpg

    • Cyborganism
      link
      fedilink
      22 years ago

      Yeah I got the same result.

      I wonder in the fingerprint is a spoof and the result is a false positive? Because Mozilla says there is fingerprint protection in Firefox.

      • @mateomaui@reddthat.com
        link
        fedilink
        English
        1
        edit-2
        2 years ago

        I seem to get that same result on iPhone for Firefox, Safari and Brave

        edit: see original reply

        Firefox Focus still has “strong” result.

        I get “Partial Protection” on Chrome and two generic named browsers, and a flat-out “No” for Opera Mini

        Before anyone asks “why” about anything listed here, I have to test webpages for compatibility across browsers. Having them installed is the only way to do that.

    • @WarmSoda@lemm.ee
      link
      fedilink
      32 years ago

      I found this looking around the site:

      In order to get this extra level of protection, your browser needs to have a fingerprint which is either:

      so common that a tracker can’t tell you apart from the crowd (as in Tor Browser), or

      randomized so that a tracker can’t tell it’s you from one moment to the next (as in Brave browser).

      Google’s Chrome browser does not provide protection against trackers or fingerprinters in Incognito Mode.

      • TWeaK
        link
        fedilink
        English
        42 years ago

        Is there any way to provide randomised fingerprints in Firefox?

        • @TerraNova@lemmy.ca
          link
          fedilink
          3
          edit-2
          2 years ago

          Use the Canvas blocker extension. It will randomize your fingerprint. So the test will say you have a unique still, but it is random every time.

          • TWeaK
            link
            fedilink
            English
            12 years ago

            It doesn’t suit me personally, I want more extensions. In particular, I use uMatrix, as it gives a little more flexibility than uBlock Origin even in authormode. I’ve been able to bypass paywalls by targeting elements from a domain, rather than the domain itself. But also there are plenty of quality of life extensions I rely on, eg gestures.

            Mullvad is very good out of the box though, I’ll give it that. And I use Mull on Android quite happily (although this does allow more extensions, pretty sure the two aren’t affiliated).

        • 👁️👄👁️
          link
          fedilink
          English
          22 years ago

          Yes, you can do it manually by enabling resistFingerprinting, but the easiest way is to just install LibreWolf browser which is a fork of Firefox. Or Mull which is practically the same thing, but Android.

  • Jeena
    link
    fedilink
    32 years ago

    Our tests indicate that you have strong protection against Web tracking.

    nice