Cyber Security MumboJumbo. a.k.a. Instagram Hates Cyborgs. a.k.a. Cyborgs hate Instagram

That’s why highly customised browsers tend to also be customised with some sort of spoofer. XD

half-jokes aside, that’s also why I’m not a big fan of disabling-style protection.
with ads, for example, I tend to prefer an approach that actually runs the ads, just on a dummy user.

This has the pro of actually billing the add runner, polluting it with false data, and avoiding “anti-blocker” scripts.
The con is that your navigation gets a little bit slower.

Also, spoofers.

Yeah that EFF application has a little table that says something along the lines of “Protecting you from fingerprinting?”. This is Firefox with a uBO

I use multiple different systems that I am evaluating ATM. Firefox with uBO + CookieAutodelete + NoScript + Decentraleyes + Multicontainers
ungoogled chromium with uMatrix and some others

1 Like

That’s interesting - I’m running FF with uBO, NoScript, Privacy Badger and https everywhere, and I have a big, nice “yes” in the last field as well :wink: Might have to do with Privacy Badger, dunno…
But Eyeux’ idea sounds fine as well - I’m just a bit too lazy for it :smile:

Any specific ones you have in mind?
For the dummy user and spoofing?

1 Like

@Coma
Hmmm I replicated your exact setup on my end and I get a big fat no.

There has to be something that’s leaking

1 Like

Hmmm, strange…
I took another look into my settings, and that might be obvious… but I have the FF security settings on “strong”, and there is a little indicator that claims this reduces fingerprinting. Maybe it’s that one? :smile:
I honestly have no idea why it works, I’m just happy it does :wink:

I go with my private VPN hosted on raspberries.
It’s a nightmare to set up, though, and slower than it could be on a datafarm. but since I tend to run 20+ tabs, it’s not much of an issue for me. XD

I’m currently using UA Spoofer. trying it out yet, but sounds nice.
Together with the VPN.

Sometimes it’s an addon you have that lets more than you expect. possibly even an addon that does not show you an icon when it’s on…?

I’m up to partial protection now :stuck_out_tongue: some lanugage setting was leaking, I think. But still not a solid yes…
I checked with Brave, and it gives me a “your browser has a randomized fingerprint” - but I suppose that is worse, since it still makes you stick out like a sore thumb

1 Like

I would say that those are the ones you can spoof out. but there are many things which can be used to fingerprint you, a bit beyond the control of your browser and spoofers.

Mainly your hardware.
And this is where you might be sticking out more so than Coma.

Those are things such as… how many cores does your processor has?
how much memory does your graphics card has? and other weird data.

You can (albeit dependant on plugins) tell your browser to not disclose the information about your graphics card…

But a script can be tailored to request some large concurrent background operations, and the response time of these can be used to calculate details such as number of cores… Amongst many other fingerprinting techniques.

If you are using a run of the mill windows hp laptop, all they can discover is that you are using specs Identical to a million other users.

Now think that your computer has 32 cpu cores… That can be calculated and would but you amongst almost 1 out of 20.000 machines.

Then if you are using a very high end, or very old graphics card that is also used by 1 out of 15.000 machines

Combine a couple more of those unusual hardware specs, such as a non-onboard audio card… using SLI…

Add to that another unspoofable metric: Time. (i.e. what time of the day you browse more. This is more reliable to location than IP)… live in a low densely populated area… and we have a fingerprint!

The only way to disable this is completely disabling any scripts. Which isn’t worth in my opinion.
Hence why I like the opposite approach: overfeed them.

I use my unique hardware sigature + spoof to appear like another good thousand users, on different IPS, Systems, browsers.
Sometimes I limit my cores. sometimes I shift my User Agent. Etc…

The one thing I should do, but isn’t so flow friendly, is to change my RAM. it’s quite a red flag… but if I keep running heavy scripts constantly in the background, it messes enough with canvasing and other techniques.

Not having 3D acceleration support on a high end pc, though, is a problem I still need to fix…

Grmbl… hope you’re not assuming I’m using a standard hp laptop! :stuck_out_tongue:
I pride myself to never have bought a predefined computer ever :wink:
Though the components might not be that special by now, that’s true… but still, I chose every single thing myself^^

1 Like

Never!!! :rofl:

That example was unrelated to you! (You already told me you built your own PC)

The comparison to you was just about he being flagged while you are not. But this has more to do with how many people have each individual component than where (prebuilt or custom) they come from. ^^

The HP example was just an anonymity comparison! :yum:

1 Like

So, it has come so far for me as well. Any tips?

1 Like

Regulary test if gmail accepts mails from you.

1 Like

In addition to what @yeka said, the thing to check potentially regularly are blacklists… there’s a few different ones, and idk what they are off the top of my head. Also make sure the server itself is secure - the moment you get hacked / compromised and spam starts being sent is the moment that a blacklist / protection service could begin to block emails.

1 Like

Conversely, @amal, I was looking at my “Off-Facebook activity” Tab on FB (yes, yes, the devils website) and I found Dangerous things there (event type - purchase, with a ID and date). Either Woocomerce or one of the Facebook analytics snitched.

1 Like

DT has tracking scripts. connect.facebook.com loads when you go to the shop.
DT itself snitched.

yeah i recently added a facebook plugin to the shop and the idea was to set up a facebook shop… it’s snitching i guess? boo :frowning:

As an aside, this topic heading reminds me of a quote from two broke girls (never watched it, but that quote appeared in adverts for it…)

“Twitter is stupid, and Instagram is Twitter for people who can’t read.”

2 Likes

That is my first time hearing that, and I love it.

2 Likes