Damn... I guess the next idea is going offline for good
Browser Fingerprinting And Why VPNs Won’t Make You Anonymous
https://hackaday.com/2025/11/19/browser-fingerprinting-and-why-vpns-wont-make-you-anonymous/
https://hackaday.com/2025/11/19/browser-fingerprinting-and-why-vpns-wont-make-you-anonymous/
Damn... I guess the next idea is going offline for good
30 Comments
Mikelius@lemmy.ml · 35 pts · 260d
I disagree.
There seems to constantly be two sides of the privacy discussion with public VPN options and they're both wrong on their own. It's correct that using a VPN on its own is not enough to keep you private online, fingerprinting being one example to why. However, not using a VPN but having no identifiable browser fingerprint doesn't either, since your IP is still a fingerprint too.
I like to give the following analogies:
If the goal is to be private, remember that a VPN is only one tool in a very large tool belt.
Tatar_Nobility@lemmy.ml · 10 pts · 260d
I think TOR would be more suitable than a VPN
Mikelius@lemmy.ml · 13 pts · 260d
Tor is definitely another option. For my personal use however, I have my entire network covered by a VPN so all outgoing traffic uses it.
I'm sure I could setup Tor to do the same, but I imagine my family and I would get blocked more heavily on sites, as well as get our bank accounts and such flagged or something.
Like many things, it obviously depends on your threat model.
Auli@lemmy.ca · 0 pts · 259d
They do more then fingerpring your browser.
a_non_monotonic_function@lemmy.world · 1 pts · 258d
Wait, did they put them on our hands?
eager_eagle@lemmy.world · 21 pts · 260d
no shit
I use VPN because of the ISP and the network, not to become anonymous to the websites I visit.
bountygiver@lemmy.ml · 4 pts · 259d
unless it's about geo restrictions.
SteveCC@lemmy.world · 17 pts · 260d
Back in the day there were apps that generated phony web searches to obfuscate your real searches. Seems like there could be tools to mess around and change browser fingerprints periodically. No?
jimi_henrik@lemmy.world · 9 pts · 260d
It could be done on the browser level (maybe it's something browsers like LibreWolf do), however, it would break sites that require the fingerprints to be the same for "security reasons" which may or may not be a legitimate claim.
You could say "well, I'm not going to use that particular website then", but the problem is that there are less and less websites that don't require these technologies to function properly.
PowerCrazy@lemmy.ml · 3 pts · 260d
Can you give an example of one of those websites?
jimi_henrik@lemmy.world · 1 pts · 258d
Off the top of my head, no. What I do remember is that I couldn't use Librewolf as my daily browser because I had trouble using every other website. Might be an exaggeration, and it could have been due to other factors, not just resisting fingerprinting.
I've just come across this article: https://kevinboone.me/fingerprinting.html
The author describes the situation pretty well:
brucethemoose@lemmy.world · 7 pts · 260d
Already done, see: https://github.com/uazo/cromite
When I go to the fingerprint test, a bunch of the values like canvas resolution and timezone are randomized.
...Not everything, though.
PiraHxCx@lemmy.ml · 5 pts · 260d
brucethemoose@lemmy.world · 5 pts · 260d
Yeah, exactly.
Cromite's explicit focus is, literally, antifingerprinting. With the goal of breaking cross site tracking I guess.
A more accurate goal for Tor/Mullvad is anonymizing, e.g. “blending in with the crowd.”
It’s like radically changing your clothes every day vs wearing super incognito stuff. Different means, each more optimal for different aspects of security/privacy.
RheumatoidArthritis@mander.xyz · 3 pts · 260d
There's this but it blocks only one of the many methods voyeurs use.
https://addons.mozilla.org/en-US/firefox/addon/no-canvas-fingerprinting/
MonkderVierte@lemmy.zip · 4 pts · 260d
And Canvas Blocker (which only optionally blocks but randomizes them). But Firefox has that built-in now; canvas fingerprinting should be pretty much useless there.
pumpkin_spice@lemmy.today · 1 pts · 260d
There is a browser extension called Chameleon that will spoof a fair amount of data, but after testing it against one of those fingerprint test sites, it looks like it doesn't/can't spoof everything.
PiraHxCx@lemmy.ml · 9 pts · 260d
primalmotion@lemmy.ml · 11 pts · 260d
PiraHxCx@lemmy.ml · 1 pts · 260d
Twongo@lemmy.ml · 8 pts · 260d
Here are some extra tips for increased privacy:
OR: Use Chameleon and set yourself to the most common combo. Get lost in the noise.
AsoFiafia@lemmy.zip · 4 pts · 260d
Twongo@lemmy.ml · 2 pts · 260d
look at my reply on the other comment :)
AsoFiafia@lemmy.zip · 5 pts · 260d
BeatTakeshi@lemmy.world · 3 pts · 260d
What's the issue with full screen?
Twongo@lemmy.ml · 4 pts · 260d
randomlzing your window size shows trackers different resolutions.
depending on which OS you use it won't show 1920x1080, as taskbars and other extras take off a few pixels.
example: if your browser is fullscreen and only shows a resolution of 1920x1075 it could most likely mean you use macos (randomly chosen)
Xylight@feddit.online · 2 pts · 258d
Librewolf has letterboxing which locks your website's intrinsic size to specific resolutions (like 1600x1000) to combat this
jnod4@lemmy.ca · 2 pts · 259d
Oh shit
Steve@communick.news · 7 pts · 260d
But VPNs aren't supposed to make you anonymous.
They secure your data while in transit to/from the exit node. Maybe that's your job so you can access their LAN. Or it's a public VPN that secures your dada from the local WiFi or ISP you're directly connected to. That's all it's built for.
Auli@lemmy.ca · 0 pts · 259d
And what do you thing HTTPS does exactly? Whe the web was HTTP sure VPN's had a point as people on public wifi could sniff your trafic. Now they can't.
Steve@communick.news · 2 pts · 259d
It only encrypts the data within the HTTPS packet. But where that packet is going is still transparent.
It also doesn't do anything for non web traffic. Email through SMTP or IMAP, FTP, lots of things don't use HTTP at all.
Tenderizer78@lemmy.ml · 4 pts · 260d
Just use Tor or Mullvad browser (you don't need to use the Tor Network or Mullvad VPN, you can bring your own).
That said the wasted screen real-estate is a dealbreaker for me. So if I'm not gonna log in then I'll go with a fully separate installation.
partygap@programming.dev · 3 pts · 258d
don’t browse the web and actually get some work done
WEB IS HARMFUL!!!
Shamot@jlai.lu · 2 pts · 258d
I just tried the Am I Unique site and I'm surprised by the amount of information the sites can have. Why do they know if I'm connected using 4G or 5G for example? Even using a privacy browser
FriendBesto@lemmy.ml · 2 pts · 250d
This is a bit of a misnomer. No one PC can be fully anonymized or fully private, even if the PC provided fake data points, they will still be technically fingerprinted. Having said that, having a browser that tries to spoof stuff like LibreWolf, Tor or IronFox is decent.
The gains in using a VPN, among other best practices is that helps --assuming people do not log on to something like Google-- is to minimize the fingerprint of the PC to you, as a user. Assuming one trust their VPN provider, helps.
Tor leverages the point of having all users look and be fingerprinted mostly as the same, so you get lost in the shuffle and crowd.
Zerush@lemmy.ml · 1 pts · 258d
Fingerprinting isn't allways synonym of the lack of privacy. But there are differences between fingerprinting for tracking and profiling reasons, which certainly is needed to block or to spoof, and tecnically data needed to show correctly the content of a page, eg the first public IP numbers to show the content in your lenguage, the fonts used, screen resolution, OS, browser engine...., all data which are the same for millon other users. We can block por complete the fingerprinting, but than we'll see that half of the pages are not shown correctly or don't even work. It's always an commitment to set the fingerprint blocking. VPNs add an privacy layer, but dont avoid fingerprintings, used as extension can't avoid that the browser connect first to the ISP before the VPN can create the tunnel, with which it may serve to skip country restrictions, but you are still seen by your ISP. It don't also blocking the fingerprinting, except the IP. To stay private depends more on other measures, DNScrypt, not to use apps, search engines and services which logs/share our activity, using ad/trackerblocker.... and the most important, common sense, not a tin foil hat. PEBCAK