Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My fingerprint varied from session to session to this website. So it's not easily demonstrable.


Did you look at the actual fields that diffed compared to what doesn't?

It's likely only things like referrer and device groupIDs which are easily excluded if the goal is to track a user across browser modes.


I didn't, but if it's trivial to ignore those fields, then why isn't the proof of concept doing that? I think because you don't know, in advance, which fields to ignore. Demonstrating tracking like that is the point of the page, and it failed to do so, so my conclusion is that it's not that straightforward after all.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: