Hacker News new | ask | show | jobs
by gkbrk 1197 days ago
This is not the only thing Chrome/Chromium does differently for Google domains.

- The header X-Rlz-String is added to requests that go to the Google home page. This header seems to contain info about language/region, and from which campaign you installed Chrome. Useful for fingerprinting and only Google domains get to have it.

- Incorrect TLS certificates for Google domains are silently and automatically reported to Google.

- X-Chrome-UMA-Enabled and X-Chrome-Variations headers sent to Google domains. The first header seems to be a single "1" value, while the second one seems more useful for fingerprinting.

- Flash-style embeds for old YouTube videos are automatically converted. Other video websites and embeds that no longer work don't get the same treatment.