Live data from Hacker News

Virtual Machine Detection in the Browser (2019)

bannedit.github.io

51–60 of 98 posts

Re: Virtual Machine Detection in the Browser (2019)

#51

Earlier quoted context omitted.

VPNs, proxies, Tor, you name it.

Ooof, yeah. I was trying to make a new, purely anonymized identity. Went through an anonymized bitcoin VPN with TOR on top. Registered an email through Protonmail. Pretty much no social media platform will accept Protonmail as an address without also having a phone number. Got banned from Discord within 3 hours, literally all I'd done was send three friend requests and join one discord. My IP was rotating and I then…

How did you get Bitcoin anonymously? It seems very difficult at least for US citizens.

Re: Virtual Machine Detection in the Browser (2019)

#52

uh, I've been using GoLogin.com for a long time and no one detects me xD

That looks very interesting indeed! But it's so absurdly expensive that you have to wonder who the target audience for this service is? From their "Use Cases" page it seems that this is geared towards (shady?) online marketers (which would explain the price) rather than privacy-conscious individuals. Would be awesome if they offered a plan for normal users priced similar to a normal VPN service...

Re: Virtual Machine Detection in the Browser (2019)

#53

quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…

While changing the reported device names can just make the VM a little less obvious, I suspect there will always be clues that indicate a VM. For example:

- Do network adapter MAC vendor ID's make sense?

- Does the hard drive size make sense?

- Which 3D acceleration features are supported/work correctly?

- How much graphics RAM is there?

- Timing-based methods

It's a bit like detecting private/incognito mode in a browser. Everything worked great, until websites realised there are ways to detect it, then became a game of cat and mouse.

Re: Virtual Machine Detection in the Browser (2019)

#54

quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…

I didn't know WebGL leaks so much information about my machine. I already open a browser just in ingokigno/private mode 90% of the time. Maybe is time to start just each time a different VM for browsing.

Re: Virtual Machine Detection in the Browser (2019)

#55

quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…

I didn't know WebGL leaks so much information about my machine. I already open a browser just in ingokigno/private mode 90% of the time. Maybe is time to start just each time a different VM for browsing.

I tried it, it's highly inconvenient. Maybe QubesOS would help, not sure.

Re: Virtual Machine Detection in the Browser (2019)

#56

quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…

> JS needs to be off by default and whitelisted only for the (very few) sites that one truly trusts.

Or the information provided by JS regarding the local machine should be reduced

Re: Virtual Machine Detection in the Browser (2019)

#57

Earlier quoted context omitted.

VPNs, proxies, Tor, you name it.

Ooof, yeah. I was trying to make a new, purely anonymized identity. Went through an anonymized bitcoin VPN with TOR on top. Registered an email through Protonmail. Pretty much no social media platform will accept Protonmail as an address without also having a phone number. Got banned from Discord within 3 hours, literally all I'd done was send three friend requests and join one discord. My IP was rotating and I then…

Did you drive 6 hours to a different city and wear a costume to buy the burner?

Re: Virtual Machine Detection in the Browser (2019)

#58
post #18

quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…

> Ideally, a VM should be indistinguishable from real hardware Why? I mean, it's possible to make a VM that's indistinguishable (except for speed), but what's the purpose of doing so? Most people who run VMs have the purpose of "I want this application to run more conveniently than having dedicated hardware for it." For that purpose, it's useful to provide abstractions (e.g., providing dedicated access to CPUs in a w…

[deleted]

Re: Virtual Machine Detection in the Browser (2019)

#59
post #18

quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…

> Ideally, a VM should be indistinguishable from real hardware Why? I mean, it's possible to make a VM that's indistinguishable (except for speed), but what's the purpose of doing so? Most people who run VMs have the purpose of "I want this application to run more conveniently than having dedicated hardware for it." For that purpose, it's useful to provide abstractions (e.g., providing dedicated access to CPUs in a w…

Right question. I'm also missing the "Why" from this article.

Re: Virtual Machine Detection in the Browser (2019)

#60
post #22
post #11

Earlier quoted context omitted.

Then do go to those websites. It's not a right that you have access to a website. Seek out only sites that don't block adblock, or has no ads. This might include a paid option (for example, youtube premium, or twitch subscription for ad-free viewing).

This entirely ignores the implications of a society that heads down that path. There are questions substantially more interesting than a reductionist "do I have an innate right to access private websites?"

There is nothing “reductionist” about this petty quibble.
Post reply on HN