|
|
|
|
|
by asadkn
1593 days ago
|
|
Curious how useful is an IP address with a simple HTTP get request? As long as a sane Referer-Policy is set, the Referer won't be sent. Sure there's a lot more to browser fingerprinting but with just an HTTP request, all the data that would be known from it is the language and the user agent. Both of which are not unique data points and shared by thousands of other users. No cookies either in this case of Google Fonts. |
|
You are logged in to to google and so are your family members.
You visit YouTube.com from IP X with device (user agent) Y.
Your family member visits YouTube.com from IP X with device Z.
Google Fonts gets a request via the API key of mydomain.de from IP X and device Y.
Google now knows that you visited mydomain.de
Edit: I stand corrected that Google Fonts doesn't use an API key. I suspect they still can correlate the font request with the domain, however I have no proof.
Consider this an example for other services like maps.