
A company that makes a browser-fingerprinting library (ostensibly for fraud prevention) claims to have found <https://www.theregister.com/2021/05/14/browser_fingerprinting_flaw/> a (admittedly fiddly and not entirely reliable) way to uniquely fingerprint your machine even though you might be using a range of different browsers. This is done by trying to access custom URL schemes as installed by various custom apps, since the presence of these apps is independent of which browser you might be using. So I tried their schemeflood.com proof-of-concept site, it churned away for a few seconds, with a little extra window flickering at the bottom, then I got a message saying “The clearkey plugin has crashed”. It also showed me the identifier it computed for me, which was “0FVVVV”, based on “0 applications you have installed ... out of 24 applications in our database”. Apparently that’s only been seen 1471 times out of 17496 tests so far, which makes it “91.59% unique”.
participants (1)
-
Lawrence D'Oliveiro