They’re really playing up the ominous tone.
“We know this because your IP address — xxx.xxx.xxx.xxx — was the first thing your device sent us. We know the rest of it. We chose not to display it. Most pages would not have made that choice. We did not ask for your location. Your address arrived before you did.”
Uh, yeah. That’s how IP addresses work.
Compare this to Google’s homepage, which is clean, wholesome, friendly, and inviting.
(I don’t mind sites that try to scare the user straight, but this one definitely has the unmistakable tinge of AI-generated wording. Make a sense if you click through the links at the bottom to see who created it.)
It really looks ai-generated. It even contains mistakes like saying that my 5yo phone model with low resolution is a high end device. All the text is pretty “generic” and sloppy
It doesn’t look AI generated. It’s more likely that they wrote different text templates for different resolution ranges.
Yes. You can either give them your real one, or not. That’s the point being made. Actually the point of the whole page is that just loading a website tells a huge amount about you, even if you are behind a vpn and extensions to minimize your fingerprint. You are a product for sale.
Well yes, but most people don’t even know that part. I guess it’s not the worst thing to tell them?
I am pretty sure 90% of the people using the Internet don’t know what an IP address is.
Obvious, the address of where you pee.
127.0.0.1
Yeah, a bit overly ominous. But my mom doesn’t know that’s how IP addresses work. And if it scares a bit more privacy mindedness into her, good.
Language and dark mode setting are also funny. Yes, I literally want to share those preferences so you don’t serve me a blinding white website in hebrew. What a hacker you are.
Laughing my ass off reading through this. The sanctimonious and passive aggressive threatening tone is perfect for how much info it got wrong just because I use Firefox and an adblock. YOUR BROWSER DIDN’T TELL US ANYTHING ABOUT THIS, LIKELY BECAUSE ITS FIREFOX. BUT THAT MEANS WE KNOW YOU USE FIREFOX AND WE ARE CHOOSING TO BE SAFE WITH THAT INFO, YOURE WELCOME, PWNED!!!11!1111!1
Teaching people about fingerprinting and how important understanding it is for personal privacy is good, but acting like a 4chan script kiddy group and making bizarre empty threats like you’re mr robot ain’t it, dawg.
From other comments this is likely some AI slop to sell a product, but if they’re serious they come off like they just slept through sec+ and think they’re shadow brokers now lmao
Similar results with NoScript.
This volume requires JavaScript. That is part of the point — your browser is what is being read.
With JavaScript off, the page cannot tell you what your browser disclosed. The data is still there. The disclosure still happened. Only the telling of it stops.
The fact that they’re stopped from “the telling” says a lot about their abilities, but not much about “the disclosure”.
I imagine it was just stuff collected in most server logs: IP Address, user agent string… I’m not too concerned, really.
Looks like they don’t have a dedicated backend dev. A similar presentation could be done by making it a dynamically generated page, with some CSS animations.
Even bog standard ios hides some stuff they claim to have.
WHAT RENDERS YOUR WORLD
Apple GPU
Your graphics processor identified itself as Apple GPU. This tells us the manufacturer, the generation, and roughly the price of your machine. Combined with your screen size and font list, this string alone can distinguish your device from most others on the internet. The technique is called WebGL fingerprinting. No permission is required.
Uh sure, that string tells you the generation and price.
Didn’t realize my phone sent it’s rotation data without promoting, everything else is kind of needed to send me info.
My IP
My screen size
My interactions with the page
deleted by creator
Now instead of cutting it off send fake data so it looks like your phone is in a blender.
Weird, this user’s gyro says the phone is angled at the entire Doom source code
I find it weird that the web operator decided to make it so rotation data only is publicly shown if your phone is actually laying down. Because if you’re holding it in the standard position, it doesn’t even announce that it collects it.
I wasn’t aware about the thing with fonts.
Your finger moved 273 times. You tapped 14 times.
I’m sorry what?
Since they went into the effort to make this sound so ominous, it’d be cool to see some actual inferences from the data points. For example it would be pretty easy to tell you are behind a VPN and your real location is probably xyz.
They knew i was on a vpn and the time zone, your phone just gives that shit up
Dont even get me started on “experimental” browser flags that come default on some browsers
This is lame as shit. The tone of the writing is going to get non-tech people feeling quite dismissive, or scared enough to seek out surface level info, which just rolls back into feeling dismissive. It’s actually really stupid because they’re clearly driving fear, but hardly touch the real thing to be scared of. Fingerprinting is barely mentioned, it’s only really addressed once, in the font identification section. The issue with all these data points is how they can be collected and correlated across the web - it basically means fuck-all if it’s only from one page.
edit: On top of that, each data point is presented as some sort of horrible catastrophe, when some are completely benign. Barely addressing why some points actually matter, or not at all. (Like click/touch data, it’s needed for site functionality, but it gets creepy when that data is used for things like psychological profiling)
Even more disappointing because the formatting/appearance is more than clean enough to share with basically anyone. Yet the tone and focus makes that out of the question. What a waste of time to make this.
The location is off by about fifty miles. It didn’t get my GPU or battery level. Everything else is stuff that doesn’t matter. Firefox browser, English, android device. I am not terribly impressed.
You’re right, and same for me, but what if you’d never considered any of this before and are new to the idea of privacy? I expect it would then give you pause for thought.
Sure, it’s a gimmick site. But it serves a useful purpose for those who don’t know about the topic. Which is probably the majority of users.
Despite my own experience: TIL the tilt angle of my phone is available to websites.
I guess I was mostly put off by the sensationalism. Everything is saturated with it these days.
You made an interesting point though, about people being new to this. I’m an old man. The internet wasn’t even a thing until I was in my early teens. It was sort of a Wild West situation for a while there and guarding personal info was the norm. But these days information gathering is built into every device, website, app, etc. To people growing up with this now it probably seems like it’s just the way things are done and nothing to worry about. I can see it being useful for pointing that out. I think it would be more useful though if it focused more on showing how to counteract these things, rather than just being scary.
Now try it with chrome
Try Deviceinfo.me
Now that one goes after a whole lot more info than the other. I was pretty happy to see the amount of “unknown” and “permission not granted or denied” responses though.
That’s not necessarily great either though, because that “unknown” becomes your unique fingerprint that almost no one else has. Ideally you to have spoofed information with the most common parameters, or even better, randomized ones.
Heheh, a whole lot of mocking in this thread, but I don’t mind the site / its display.
Yeah, it’s overly melodramatic in its setup, and a bunch of the information doomerism is silly in terms of the info basically being required to provide data comms etc. It also tends to get things a bit wrong in a few categories – like for me, it said I was in a totally different city (still the right country at least - Canada), then it said my time zone was in iceland, which is kinda… no.
But the general message of the site, and the awareness its trying to raise in regards to how much data gets shared for basic comms establishment, and how that information gets used to fingerprint people, is worthwhile.
It got the country wrong for me. I didn’t use a VPN or anything. So that’s good I guess.
Hm, wonder why that’d be – it implies heavily that it bases the country on the IP address, which in theory is done by looking at what company the address is registered to, for the most part. Like I’m guessing it got my city wrong, because it used an address that the ISP provides for the IP range, which isn’t the same as the city I’m in, because the ISP uses it to cover numerous cities around the broader region. I reckon if you’re using something like Starlink, or other similar international-ish provider that may be very loose in how they associated addresses, it’d fail most times.
I was on mobile data, who knows where the mobile network gets their connection from
Ah, makes some sense. The mobile networks are even more erratic with how they assign IPs – though I’d still be a little surprised if it was the wrong country entirely. It’d imply the provider is using IPs from a single range in multiple legal jurisdictions, which’d inherently make things like geofencing more difficult. Sorta like VPN functionality to access foreign data regions, as a result of sloppy configuration and negligence by the ISP. Wonder if it could also be something to do with IPV6 – I think that’s more common to see amongst mobile networks, and I’m honestly not too sure how well that can get mapped to geo locations – I’d doubt the site, how its put together, would be tryin too hard to sort that out.
deleted by creator
Does librewolf have a vpn built in?
It doesn’t appear to from what I can find. It must be using some other method.
It got my location wrong. It got my GPU wrong. It said I never left the tab, even though I left it to start this comment. It said I moved my cursor 111 times in 74 seconds, which is absolutely false.
That site is just pointless. Pretty much the only things it got right were my time zone and my browser.
It also says I have Azerbaijani on my phone somewhere. I have no idea where that came from.
That’s actually usually a sign of malware…
That’s a good point. Thanks for that. Any tips on how to narrow down on that?
You can download Hypatia. It’s a malware scanner. There’s an official fork that kept it alive after the original dev stopped maintaining.
Otherwise, you’d have to narrow it down further. Any non mainstream apps you have would be the first to check
Awesome. Thanks.
In my case it was incredibly accurate, except for one detail; the wire said I moved my finger over 600 times which… Seems hyperbolic.
Ridiculously accurate forme, tried across multiple browsers.
Gyro, screensize, battery are all causes for concern. I have firefox with ublock and ss and it was able to see all except the gpu and battery.
It says I’m on Chrome, I’m not.
Also, so what if you know my IP, that isn’t sensitive information.
It’s good to bring attention to this stuff but at the same time there’s no point getting too worried about it.
What are you using? Firefox?
Fingerprinting is real and we know it. Not because of the site but because every software dev I know who works in a net startup tells me that they do the basics and more. They won’t talk about the more.
Lol it says I have a “recent, high end device”… It’s a Samsung that’s old enough to be in the third grade.
Only thing that’s missing is a bunch of threats with a Bitcoin address at the bottom.
I’m guessing it has inferred that (wrongly) from your screen size and resolution.
That’s not a great datapoint, if that’s the case, there’s 2015 phones that are unnecessarily 4K (right when 4K TVs were becoming popular)
Time zone has no info about where I actually am. Sure, I’m in a particular vertical slice of the earth. I have the JP keyboard downloaded, but you’re wrong, that doesn’t mean I speak Japanese. In fact, I speak French but your cookie reading didn’t pick that up.
It is genuinely interesting what info gets passed to websites but the doomy tone is rather silly and will unnecessarily worry people who don’t know much about computers/Internet, which is the majority of users.
Assuming it’s tz database timezones then they can be relatively specific. Since the slices are based around laws governing current time, there’s hundreds of slices rather than just a couple dozen. https://en.wikipedia.org/wiki/List_of_tz_database_time_zones Alongside things like keyboard downloaded it means you can be uniquely fingerprinted (or close to unique) pretty easily, which means they can then associate all sorts of other information with you
My time zone is quite specific and has only about 500,000 people in it
It got my timezone and location pretty spot on, though.
There are multiple sites like this, for example clickclickclick.click has been around for 10 years (not optimized for mobile)
Your browser accepts cookies. Websites can write small files to your device that persist after you leave — files that identify you when you return, that follow you across sites, that remember what you looked at, what you almost bought, and how long you hesitated. We have not written one. Your browser would let this page write up to 10 GB to your device — a private room, ours alone, like the one given to every site you visit.
Hol up … 10 GB?
I think that refers to localStorage not cookies.
Very useful site. Thanks for posting this.
Seems to be making a lot out of “you send your user agent and screen resolution”.
There is a looot more than that lol. Usually enough to allow them to uniquely fingerprint every device on earth.
There were a couple of things on that page that were novel to me. “Only a couple” made it worthwhile though:
- There’s a free tier to a service that gives you geolocation data from an IP address
- This site counts the number of times you move to a different tab
I didnt mean this site specifically just in general.
See this site for something more technical. Takes a while to process everything give it a minute.
I opened it in Firefox and Librewolf just to see how the information sent was different. Librewolf obfuscated the following which Firefox disclosed:
Time zone
Monitor resolution
GPU used
Also, the Firefox one said I moved my cursor such-and-such times, while the Librewolf one said my finger moved such-and-such times. Must be related to hiding what screen I’m using. I’m on desktop.
Firefox on mobile obscured GPU.
“Your browser masked your graphics processor. Firefox and Safari have started returning generic strings — “Mozilla”, “Apple”, “or similar” — instead of the real renderer. The fact that yours did so tells us, with reasonable confidence, which browser you are running. The mask is also a fingerprint.”
Is this just lack of dedicated GPU on mobile?
Uh no, my mobile phone, its just hidden what SoC I have










