Live data from Hacker News

Show HN: What every browser knows about you

webkay.robinlinus.com

21–30 of 209 posts

Re: Show HN: What every browser knows about you

#21
post #20
post #15

Earlier quoted context omitted.

Sorry! Didn't think about that. It is fixed.

You should leave it in, if the whole point is to demonstrate the capabilities. It's incredible that a webpage can do that.

Agreed - good on OP to raise awareness.

Re: Show HN: What every browser knows about you

#22
post #20
post #15

Earlier quoted context omitted.

Sorry! Didn't think about that. It is fixed.

You should leave it in, if the whole point is to demonstrate the capabilities. It's incredible that a webpage can do that.

I think a button would be more appropriate. Not everyone reads HN on a network they control and port scanning one's neighbors can lead to some unpleasant conversations.

Re: Show HN: What every browser knows about you

#23
Not much of interest showed up for me. Monitor resolution, browser ID, geo location, OS and public IP.

My main browser, Firefox, has uBlock and Self-Destructing Cookies. Tried it in both IE11 and Edge (both of which I never use), and I got pretty much the same result. Firefox and Epiphany on Gentoo Linux also failed to startle me.

I'd like to see a screenshot of a "worst case scenario".

Re: Show HN: What every browser knows about you

#24
This is a perfect example of what an attacker could do with your browser. If you can get a user's browser to run code, as this site demonstrates there is a lot of information you can find. And coupled with a Cross-Site Request Forgery, you could get access to a bunch of things. If your home router has a vulnerability that bypasses authentication and allows you to execute commands on the router or similar (which is not uncommon, home router security is awful), you could get a foothold into the network just by sending someone a email with links that they are likely to click on.

Note to the author: I am not entirely sure how the WebRTC connection gets you a local IP, it seems to be connecting to stun:stun.services.mozilla.com. Anyway,that grabs the wrong local address for me, and gets the IP of my docker0 interface, perhaps it could grab more IPs, or is it just displaying the first one it finds?

Edit: Oh, the getIP function just calls the callback on the first candidate it finds.

Re: Show HN: What every browser knows about you

#25
post #14

Scanning the visitor's /24 without notice, warning, or opportunity to opt out is a dick move. Our IDS probably just lit up like a Christmas tree.

Yup. I have a honeypot on my home network that hits Twilio when it gets poked at. So the author at least got my phone to light up.

That sounds awesome, care to share a few more details?

Re: Show HN: What every browser knows about you

#27
post #9

And what are methods to prevent browser from leaking all this information? I presume browsing in private mode is not a solution.

I started to add some information/advice to every section on how to prevent the regarding type leak.

It would be great to hear your suggestions on how to improve both the advices!

Re: Show HN: What every browser knows about you

#28

> Your Device is propably laying on a Table I'm one of those heathens that actually puts the desktop tower on top of the desk. Got me.

Me too, my tower is in fact "laying" not standing, on a table. Just as an aside, this declaration should read. Your Device is "probably", not propably.
Post reply on HN