Hacker News new | ask | show | jobs
by jchook 2193 days ago
Curious, how do you do fingerprinting without JS? User agent, header order, etc? How well does it work?
3 comments

Basically, each layer of any implementation of the OSI stack will have its own peculiarities. E.g. there's a paper on re-identifying computers via TCP clock drift.

How well they work depends on the amount of effort you're putting in. Since Javascript is easy and offers a very rich attack surface, there seems to be little rain to really plunge the depths of other layers.

Panopticlick did some of this with headers included, their order, and their timing. Which of course can be defeated without much loss of features. Tor Browser being one example
Cookie?
and also transparent pixel