#fingerprinting — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #fingerprinting, aggregated by home.social.
-
Мы измерили платный антидетект‑браузер: canvas совпадал с чистой машиной байт в байт. Потом сделали свой, открытый
Антидетект‑браузеры — инструмент, которым агентства ведут десятки рекламных кабинетов и аккаунтов маркетплейсов с одной машины: у каждого профиля свой отпечаток, свой прокси, свои cookies. Стоят они $30–150 в месяц на команду, и все до одного закрытые. В интерфейсе — зелёные галочки «canvas: защищён», «WebGL: защищён». Что на самом деле уходит сайту — не знает никто, включая, как выяснилось, пользователей. Мы взяли один из популярных продуктов, поставили рядом с настоящим Chrome на одном Mac и сравнили ~250 значений отпечатка. Результат стал причиной написать свой. Ниже — методика, которую можно повторить на любом антидетекте за десять минут, что она показала, и как в итоге устроен Fury — открытый форк Chromium, где подмена делается в C++ у источника значения, а не инжектом JS. Продукт я называть не буду. Не потому, что боюсь, а потому что это не главное: методика ниже воспроизводима, и каждый может прогнать её сам против того, за что платит.
https://habr.com/ru/articles/1081984/
#антидетект #fingerprinting #chromium #canvas #open_source #rust
-
Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣
Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).
The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.
Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.
Domains samples:
qqc10c[.]cyou
51wang11c[.]cyou#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan
-
Автоматизация рутины на hh.ru: Как мы учили Headless Chrome притворяться живым человеком (RPA против Anti-Fraud)
С инженерной точки зрения поиск работы — это процесс с низкой энтропией. Есть входящий поток данных (JSON с вакансиями) и есть необходимость отправить ответный сигнал (POST-запрос с откликом). Задача кажется тривиальной для автоматизации: написал парсер, настроил cron, пошел пить кофе. Однако, если вы попробуете автоматизировать отклики на крупных job-board платформах (особенно на hh.ru ) в 2026 году, вы столкнетесь с серьезным противодействием. WAF (Web Application Firewall), анализ TLS-отпечатков, поведенческая биометрия и теневые баны — это реальность, которая убивает скрипты на requests за пару часов. В этой статье разберем архитектуру решения, которое позволяет автоматизировать процесс отклика, используя подходы RPA (Robotic Process Automation), мимикрию под поведение пользователя (Human Mimicry) и LLM для обхода смысловых фильтров. (Дисклеймер: Статья носит исследовательский характер. Мы не призываем нарушать правила площадок, а разбираем технические методы эмуляции браузера).
https://habr.com/ru/articles/983318/
#Искусственный_интеллект #RPA #Playwright #Selenium #Парсинг #AntiFraud #Fingerprinting #Web_Scraping #LLM #Автоматизация_рутины
-
It's easy to assume a VPN keeps you private, but they're not effective against the most prevalent form of cross-site tracking: Browser Fingerprinting.
Our latest video covers what browser fingerprinting is in detail and what you can do to protect yourself from trackers, plus we spoke with @ruihildt from @mullvadnet for more info on what the top privacy browsers are doing about this problem.
https://www.privacyguides.org/videos/2025/09/12/what-is-browser-fingerprinting-and-how-to-stop-it/
:youtube: https://www.youtube.com/watch?v=v_50cBtSjyQ
:peertube: https://neat.tube/w/2TQztsQGZ6ZPiJVSUtSDHa#BrowserFingerprinting #MullvadBrowser #TorBrowser #BrowserFingerprint #AmIUnique #Fingerprinting #Privacy #Chrome #Firefox #PrivacyGuides #Video
-
Ever heard of the device motion API in web browsers? No? It lets websites access the position and movements of your phone or tablet.
Here is a demo:
https://www.audero.it/demo/device-orientation-api-demo.html
Very useful for some specific applications, like augmented reality. But other than that, not particularly useful for websites.Well, except advertisers of course. I couldn't find any up-to-date research, but this one from 2018 shows there's a minority of trackers that do access this information and send it to a server, for who knows what purposes exactly:
https://sensor-js.xyz/I think this should have been an opt-in feature. While device orientation and motion is not nearly as sensitive as a camera or microphone, very few websites actually need this information and just providing it to every website seems like a totally unnecessary privacy violation to me.
-
@jon Regulation can work while simultaneously building permissionless #freedomtech that defeats surveillance techniques like #fingerprinting. I love the work #HydraVeil and #Nym are doing in this regard.
#HydraVeilVPN #NymVPN #surveillance #dataprivacy #browserfingerprinting #privacy #webtracking #SurveillanceCapitalism #permissionlesstech #foss #freesoftware #VPN
-
Scientific study finds that #adtech IS using browser #fingerprinting to track people and so it no longer matters so much how good you are at blocking #cookies and #trackers 😒
https://engineering.tamu.edu/news/2025/06/websites-are-tracking-you-via-browser-fingerprinting.html
They call on browser makers to do more. @jon is your team putting effort into this area?
@johnnyryan I suggest this area is added to your investigations since it is linked to the #RTB system and #databrokers 🙏
-
→ Fingerprinting: Critics say Google rules put profits over privacy
https://www.bbc.com/news/articles/cm21g0052dno“[O]pponents to the change say fingerprinting and IP address collection are a blow to privacy”
“"The same tracking techniques that Google claims are essential for online #advertising also expose individuals' sensitive information to data #brokers, #surveillance companies, and law enforcement," [Lena Cohen, staff technologist at the EFF] added.”
-
Audio Fingerprinting Skips a Show’s Intro, Reliably - Lacking a DVD drive, [jg] was watching a TV series in the form of a bunch of .avi video files. Of co... - https://hackaday.com/2020/11/25/audio-fingerprinting-skips-a-shows-intro-reliably/ #audiofingerprinting #fingerprinting #softwarehacks #chapterskip #videohacks #mkvmerge #ffmpeg #video