Hacker Newsnew | past | comments | ask | show | jobs | submit | DavidD's commentslogin

If it changes every load, that's your browser farbling canvas/audio per-read (Brave or Firefox), which means the anti-fingerprinting is working. We missed crediting that in v1, so it should read lower now if you reload.


then youre straight up lying in your tool. thats not "something we(you+claude) missed".


That panel reconstructs what a pixel would send from your own browser values, locally, and never makes the request. NextDNS seeing nothing is the tool working exactly as designed.


what?


They're saying that the site simulates what would be sent to Facebook without actually sending the request to Facebook.

(I'm not sure if that's true, but I hope so)


A VPN or Tor swaps it out entirely, which your browser fingerprint survives. It is a strong identifier, not a permanent one.


Fun fact: some malware won't execute if it sees a Russian/Ukrainian keyboard layout, because the authors avoid hitting victims in their own jurisdiction.



I built this after a thread here about Alibaba using an audio-context trick to fingerprint visitors. I knew a fair number of fingerprinting methods but not that one, and I wanted to see all of them in one place, running against my own browser.

GlassBox runs ~31 probes (canvas, WebGL/WebGPU, audio, fonts, the WASM feature set, math/engine quirks, WebRTC IP, timezone/locale, the permission and API matrices, an incognito heuristic, cross-site login-state, and so on) and shows the raw values plus an estimate of how identifiable you are.

A few deliberate choices:

- One static HTML file, no dependencies, no build step. Everything runs client-side and nothing is sent, with one opt-out exception: IP geolocation, which calls a public API. I didn't want a privacy tool that phones home.

- The "identifiability" number is an honest model, not a measurement. It sums published per-signal entropy (Panopticlick / AmIUnique / Cover Your Tracks), discounts signals your browser masks, and caps at the ~33 bits needed to single out one person on Earth. A no-server tool can't compute true rarity against a live population, so I label it an estimate instead of pretending. For real population numbers, Cover Your Tracks and AmIUnique have the datasets.

- There's a companion guide on lowering your fingerprint, with the caveat that uniqueness isn't privacy: blending into a big crowd (Tor at its default size) beats a bespoke hardened setup that makes you the only one who looks like that.

Source (MIT): https://github.com/HotStartLabs/glassbox

I'd genuinely like to know which vectors I'm missing, especially from the anti-fraud / detection side.


You even used an LLM to write your comment.

If you’re ESL, that’s not an excuse. You can write something in your own language and use a translator or even an LLM to translate it.

But using an LLM to write is delegating your cognition to a machine. At that point, you’re acknowledging that your own cognition has no value, so why are you trying to inflict a faked version of it on the rest of us?


Does anyone know a way to do this for a computer? I built a p2ppoker website the protects the shuffle from the server but I would like to blank the cards on screenshots to prevent huds and AIs from making the game unplayable.


I’m interested in reading more about this. how does p2ppoker work out?


https://p2ppoker.com/#how - I will opensource it soon just need some time to write it up


Congratulations you just provided source material to deepfake your staff.


Air travel can be revolutionized with a pod-based boarding system to reduce travel times and enhance safety. Passengers would have individual pods with built-in luggage compartments under their seats, allowing for fast, automated boarding and unloading. This system would eliminate the need for overhead storage and flight attendants, streamlining operations. In emergencies, each pod would feature a deployable parachute, offering increased survivability. By minimizing human touchpoints and maximizing automation, airlines could drastically cut boarding times, improve passenger privacy, and enhance overall efficiency in air travel.


Air travel can be revolutionized with a vacuum-sealed passenger transport system, reducing total airport time to just 10 minutes while maximizing efficiency and safety. Upon arrival, passengers would undergo a rapid preparation process, where an oxygen-rich biofluid is introduced through both mouth and anus, ensuring full oxygenation without the need for active breathing. They would then be gently encased in a flexible, vacuum-sealed transport sheet, immobilizing them completely to eliminate security concerns and expedite boarding.

These passenger sheets would be automatically sorted and loaded onto aircraft via a conveyor system, optimizing cabin space with a precision-stacked configuration. Without the need for traditional seating, aisles, or security screening, aircraft capacity could increase significantly, lowering ticket prices while enhancing operational efficiency. Upon landing, passengers would be swiftly unloaded, revived from stasis, and ready to continue their journey within minutes.

This system would not only eliminate delays caused by baggage handling and TSA procedures but also enhance fuel efficiency by optimizing passenger distribution within the aircraft.


Wait just a minute. That would take up space that they could otherwise use to cram in an extra row of seats.


If I have a 2-year old child and I need to feed him or change his diaper but he's enclosed in his own sealed pod do I just have to wait 8 hours before I can interact with him at the other end or something? And what if I am traveling with my wife and she wants to put her head on my shoulder?


Classic LLM innovation


The lugagge compartment also serves as toilet. It is on the passenger to bring luggage or have a toilet, or both in a pinch /joke


My guess is they infiltrated the pager supply putting the bombs in all pagers and triggered them with Hezbollah's own encoded message system so only the guilty parties would be effected.


Seems more likely their explosive implant used a separate RF trigger -- makes the whole thing much simpler for them, less detectable. They could run a plane or drone overhead to send the radio initiate message.

Looked like 5-10g (maybe up to 20g?) of explosive, NOT battery. I think you could fit the whole package inside an AA battery, along with an AAAA battery, so you could do something crazy there, or just replace a rechargeable battery pack with something of smaller battery capacity containing the explosive, some electronics, etc. Or just use spare volume inside the case and hope no one does gross physical inspection.


It's trivial to sniff a data line to the LCD and look for a specific message(I regrettably had to do this in the late 90's to fix a bug using an additional Z8 microcontroller). That said, it would be more work than inserting a separate module with its own message reception logic.


Market data suggests that Lebanon is completely saturated with smart phones, like everywhere else in the developed world, so it seems likely that there are only "guilty" pagers (certainly in this shipment, but more likely in the region).


Many doctors all over the world still use pagers.


You think Iran ships 2000 pagers to doctors in Lebanon all at once?


I only provided a reasonable caveat to your suggestion that anyone in Lebanon with a pager can be assumed "guilty".


I used the word "guilty" (in quotes) because the parent comment did.


Though not ones supplied by a terror group, connected to their private network.

(This is an assumption, I'm neither a doctor nor a terrorist).


Get this in my microwave stat!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: