Login Register






How Much Do You Know About Browser Fingerprint? filter_list
Author
Message
How Much Do You Know About Browser Fingerprint? #1
1. What is browser fingerprint?
Browser fingerprinting refers to the technology to locate an Internet user precisely through various information of the browser, such as system fonts, screen resolution and browser extensions. It doesn’t need any other technology such as cookies. With browser fingerprint, anonymous activities become impossible even using the privacy window mode of the browser. That is to say, when you visit a certain website, then this website can recognize your identity. Although the web doesn’t know actually who you are, yet you have your own unique  fingerprint which represents your identity. This information can pave the way for series of activities such as advertisement serving or any other marketing campaign that bases on users’ privacy.

2.How does browser fingerprint work?
Firstly, we need to learn a basic concept “Entropy”. Entropy is the average amount of information contained in each received message. The higher the information entropy, the more information can be transmitted. In the similar way, the lower the information entropy, the less information is transmitted.
Browser fingerprint is synthesized from many featured information of the browsers, and the information entropy of these featured information is quite different. Based on the difference, browser fingerprint can be divided into basic fingerprint and advanced fingerprint.
1)Basic Fingerprint:
Basic fingerprint can be easily detected and modified, such as the header of HTTP.
In addition to the fingerprint obtained in HTTP, there are also may other ways that depend the obtainment the characteristic information of the browser, such as:
  • UA in each browser
  • HTTP ACCEPT header sent by the browser
  • Extensions installed in the browser. (Such as Quicktime, Flash, Java or Acrobat, and some other versions of these plugins)
  • Fonts on the computer
  • JavaScript in the browser
  • Whether browser has installed cookies or super cookies
  • Whether the browser has set as “Do Not Track”
  • Whether touching screen is supported
  • System platform (eg Win32, Linux x86)
  • System language (e.g. CN, EN-US)
After getting these values, you can perform some calculations to get the specific information entropy of the browser fingerprint and the UUID (universally unique identifier) of the browser.
2)Advanced Fingerprint:
Basic fingerprint is not enough to distinguish unique individuals. Advanced fingerprint is able to narrow the scope and generate a unique browser identity. All the information used to calculate the browser fingerprint can be ranged by their “weight” and the larger information entropy will have a larger weight.
According to some relevant studies: time zone, screen resolution, color depth, Canvas and webGL information entropy are much weighted in browser fingerprint.

3.How to avoid generating your browser fingerprint?
As a lot of websites use various technologies to "generate" users’ browser fingerprints in order to provide website users with more accurate recommendations which are in line with users' browsing habits, most users are anxious about their “privacy leakage”. So how do we prevent "user fingerprints" from being generated?
Although mix Canvas fingerprint or other fingerprint can solve this problem, yet the process of code setting is very complex and there are quite a lot of repetitive work. We also have some simple methods to prevent user fingerprints from being generated. For example, we can use some anti-detect fingerprint browser such as AdsPower fingerprint browser. It’s an effective anti-detect fingerprint browser that allows to create an isolated browser environment with browser fingerprint test passed.It mimics the authentic login environment and the browser profiles that run on Windows/MacOS can easily pass the test.

[+] 1 user Likes justina-luuu's post
Reply

RE: How Much Do You Know About Browser Fingerprint? #2
Excellent guide.

In terms of user agent strings, here's a couple of sites I use which have an extensive list.

http://useragentstring.com/pages/userage...p?name=All
https://udger.com/resources/ua-list
[Image: AD83g1A.png]

Reply

RE: How Much Do You Know About Browser Fingerprint? #3
It's still just as bad to "fake" or "spoof" a UA. You're not fooling advanced tracking or exploits that seek specific browser knowledge using key data points. You're much better off using a privacy respectful browser such as Tor Browser. You can use many methods to defeat tracking and browser based fingerprints but in the end, it's easier to blend in with the rest of users and block ads and tracking pixels as they come. Easier by orders of magnitude.

All I know for sure is that the process of identification of users or entities by looking at browser based intel is very easy to do unless you use a) a decoy VM that you plan to burn after using it for specific activities or b) a public anonymity platform like TAILS, with built-in protection from advertisers and trackers and a plethora of exploits.
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

[+] 1 user Likes ConcernedCitizen's post
Reply

RE: How Much Do You Know About Browser Fingerprint? #4
(12-16-2021, 11:08 AM)mothered Wrote: Excellent guide.

In terms of user agent strings, here's a couple of sites I use which have an extensive list.

http://useragentstring.com/pages/userage...p?name=All
https://udger.com/resources/ua-list
Thanks!!

(12-16-2021, 03:25 PM)vittring Wrote: It's still just as bad to "fake" or "spoof" a UA. You're not fooling advanced tracking or exploits that seek specific browser knowledge using key data points. You're much better off using a privacy respectful browser such as Tor Browser. You can use many methods to defeat tracking and browser based fingerprints but in the end, it's easier to blend in with the rest of users and block ads and tracking pixels as they come. Easier by orders of magnitude.

All I know for sure is that the process of identification of users or entities by looking at browser based intel is very easy to do unless you use a) a decoy VM that you plan to burn after using it for specific activities or b) a public anonymity platform like TAILS, with built-in protection from advertisers and trackers and a plethora of exploits.
I think antidetect fingerprint browser can still help to some extent, especially those apply SSL symmetric encryption during data transmission and storage. Actually I'm rather a rookie in this field(lol), so thanks for your advice.
(This post was last modified: 12-23-2021, 07:26 AM by justina-luuu.)

Reply

RE: How Much Do You Know About Browser Fingerprint? #5
(12-23-2021, 07:18 AM)justina-luuu Wrote:
(12-16-2021, 11:08 AM)mothered Wrote: Excellent guide.

In terms of user agent strings, here's a couple of sites I use which have an extensive list.

http://useragentstring.com/pages/userage...p?name=All
https://udger.com/resources/ua-list
Thanks!!
You're welcome, and thank you for a well-crafted In depth guide.
[Image: AD83g1A.png]

Reply

RE: How Much Do You Know About Browser Fingerprint? #6
(12-23-2021, 07:18 AM)justina-luuu Wrote: I think antidetect fingerprint browser can still help to some extent, especially those apply SSL symmetric encryption during data transmission and storage. Actually I'm rather a rookie in this field(lol), so thanks for your advice.

People often use SSL and TLS interchangeably. It is also an obsolete and insecure protocol. Its design error uses nondeterministic Code Block Cipher (CBC) padding, which makes it easier for man-in-the-middle attacks. Any system supporting SSL 3.0, even if it also supports the more recent version of TLS, is vulnerable to encryption attacks, such as the Padding Oracle On Downgrade Legacy (POODLE) attack. Encryption in SSL 3.0 uses either the Rivest Cipher (RC4) stream cipher or a block cipher in CBC mode. RC4 is known to have biases, and the block cipher in CBC mode is vulnerable to the POODLE attack. National Institute of Standards and Technology (NIST) no longer considers the SSL 3.0 protocol as acceptable for protecting data.

CDN extensions never really improved privacy as far as sharing your IP address was concerned and their usage is fingerprintable as this Tor Project developer points out. They are the wrong tool for the job and are not a substitute for a good VPN or Tor. Its worth noting the resources for Decentraleyes are hugely out of date and would not be likely used anyway.

Most of your common extensions for Firefox are outdated and their functions either don't work as intended or are unnecessary with Firefox in 2021: Enhanced Tracking Protection (ETP), enhanced cookie clearing, Fission, etc.

There is also no remaining point in duplicating the efforts of the community Arkenfox project. Mozilla has advanced protection against fingerprinting (RFP is enabled with Arkenfox). Some of those extensions are detectable by websites through JavaScript and CSS methods, particularly those which inject anything into the web content. This includes all extensions that try to change the user agent or other browser behaviour to prevent fingerprinting.

You no longer need to rely on some extensions like HTTPS Everywhere which is deprecated. Also, there's no need for Decentraleyes or Clear URLs, their functionality is detectable and you're wasting time relying on something you shouldn't need. Just get a better browser like Firefox, Tor, Brave, or Bromite (Android).
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: How Much Do You Know About Browser Fingerprint? #7
Thoughts on Librewolf?

I have the current add ons, ublock origin, privacy badger, cookie auto delete, and decentraleyes. I just wonder if these add ons that are "questionable" as you mentioned above are questionable due to the browser itself, or its configuration that which prevents these add ons from doing their job. Or if they are outright, out of date and insecure because further technology has surpassed their capabilities. I would like to know more, and learn how I can best test for myself, to see how and what is working and that which is not.

I have been reading into this topic as well, and wonder how much entropy my configuration has? Probably silly for me to say it like this, but is there a service that can test this for you/me? I have been using browser leaks, DNS leaks, cover your tracks, sites like that. But really have no idea how accurate they are. On my privacy configuration, thing comes back saying Im using windows when I am not. Says I am using Firefox, when I am not (though it is a fork).

How hard would it be to develop a standard protocol that hides all Identifiable packet information, kinda like what TOR does, but one that works on the clear net. (Not requiring Onion Router or specified servers that act as an anonymous proxy chain).

Reply