Earlier quoted context omitted.
That wouldn't really help. The containers/VMs might be separated from each other, but they're running on the same hardware/software stack, so they'll behave the same should you decide to fingerprint it.
I meant for convenience since launching VM is part of the OS. Wouldn't every Qubes VM (whatever the underlying physical machine) return the same fingerprint? Something like VM Fedora version XXX running on Xen hypervisor.
Virtual Machine Detection in the Browser (2019)
91–98 of 98 posts
Re: Virtual Machine Detection in the Browser (2019)
#92Earlier quoted context omitted.
Ooof, yeah. I was trying to make a new, purely anonymized identity. Went through an anonymized bitcoin VPN with TOR on top. Registered an email through Protonmail. Pretty much no social media platform will accept Protonmail as an address without also having a phone number. Got banned from Discord within 3 hours, literally all I'd done was send three friend requests and join one discord. My IP was rotating and I then…
How did you get Bitcoin anonymously? It seems very difficult at least for US citizens.
Oh! But to your question: Mullvad VPN seems to be highly regarded, and has an option to configure a recurring payment that they (claim to) decouple from your identity. Their service even supports defining multi-hop routes.
And to be clear: My goal is to obfuscate my identity from malicious individuals (think: politician that wants to be kinky, but has to resort to online interactions during COVID lockdown, and wants to avoid both simple tracert IP identification as well as a potential password breach & leak of social media platform X). Hiding my identity from governments is not my goal, so trusting Mullvad was an acceptable risk assessment. I'd add additional layers if I wanted to be more anonymous.
My next step, when I get around to it, is to try to track down a cheap anonymous virtual host to SSL into... then at least I'll have a static IP. But I'd still be up a creek if they ever wanted to do two factor for some reason.
Re: Virtual Machine Detection in the Browser (2019)
#93Earlier quoted context omitted.
Ooof, yeah. I was trying to make a new, purely anonymized identity. Went through an anonymized bitcoin VPN with TOR on top. Registered an email through Protonmail. Pretty much no social media platform will accept Protonmail as an address without also having a phone number. Got banned from Discord within 3 hours, literally all I'd done was send three friend requests and join one discord. My IP was rotating and I then…
Did you drive 6 hours to a different city and wear a costume to buy the burner?
But, if you are a citizen in a country that would employ law enforcement against you due to your minority status, I might encourage that protocol.
Re: Virtual Machine Detection in the Browser (2019)
#94Earlier quoted context omitted.
It's just unfortunate that companies are employing precog future-crime concepts to what (should) be standard privacy approaches. And, to be clear, I'm not acting like someone I'm not. I'm forthcoming that I have an identity, and I'm even willing to prove that I'm a self-consistent individual. I'm acting like someone that has purchased a month-to-month phone, and have signed up for a free email account, and values the…
For my money, I can't help but think of people who have legitimate reasons for wanting privacy and how my relative lack thereof deprives them of it. For every one of us that has a well defined presence, it becomes that much easier to spot people who hide, and like you say, there are perfectly legitimate reasons to do so. I would venture out even and say that categorically, there are unjust laws that people should be…
May your holidays be safe and rejuvenating.
Re: Virtual Machine Detection in the Browser (2019)
#95Earlier quoted context omitted.
OP is just suggesting you vote with your 'wallet' by not using those sites - they're not saying you should stop complaining.
Bad actors generally win monitary contests. The entire vote with your wallet is a mostly disproven idea.
Re: Virtual Machine Detection in the Browser (2019)
#96Earlier quoted context omitted.
Ooof, yeah. I was trying to make a new, purely anonymized identity. Went through an anonymized bitcoin VPN with TOR on top. Registered an email through Protonmail. Pretty much no social media platform will accept Protonmail as an address without also having a phone number. Got banned from Discord within 3 hours, literally all I'd done was send three friend requests and join one discord. My IP was rotating and I then…
How did you get Bitcoin anonymously? It seems very difficult at least for US citizens.
Re: Virtual Machine Detection in the Browser (2019)
#97quickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such infor…
> JS needs to be off by default and whitelisted only for the (very few) sites that one truly trusts. Or the information provided by JS regarding the local machine should be reduced
You should have enough ropes to hang yourself, and also a few more just in case.
Re: Virtual Machine Detection in the Browser (2019)
#98Earlier quoted context omitted.
I think the sane argument here is for sensible defaults. Leaving all those switches turned on is just opening the door for adtech. The set of information that's made available out of the box should be small, and if you need to access information about my graphics card, you can ask for it.
I think this only works if the average consumer can assess what is being asked for, though. “Do you want to let this website know what hardware you have?” is not a simple question. “What is hardware?” “Should I let a game know my hardware? Should I let a news website know my hardware?”