Live data from Hacker News

The Underpants Project

lab.cubiq.org

1–10 of 87 posts

Re: The Underpants Project

#3
post #2

With NoScript, it does not provide a tracking ID. Which shows yet another reason to browse with NoScript.

   *The following is your unique fingerprint on the web:*

        *loading...*
I'll bet my fingerprint isn't unique.

Re: The Underpants Project

#4
Simply resizing my browser window before pasting the second url seems to thwart this (But I don't have flash installed). Without flash, it falls firmly into the "kinda-works sometimes if everything goes perfect" camp.

So its another demonstration of flash being ridiculously insecure. These guys did it better, even defeating tor to reveal the origin IP. http://dl.packetstormsecurity.net/0610-advisories/Practical_...

Re: The Underpants Project

#5
I think it doesn't work.

After typing "meow" and hitting enter. The copy paster url had this to say about me "It seems you didn't save the word. Go to lab.cubiq.org/underpants first."

The unique fingerprint is also different. "93615388f7f54cd79d2f806ac3795c182217aa9b" somehow became "f37ec3fdd05c27c13cbb7fcdef95cc004297f62d" after copy-pasting.

Other than that technical glitch for me (Linux, Chrome latest unstable version), I still think this is actually a pretty good idea. But will websites use it now that the ones we actually want to worry about are injected into every website via Tweet and Like and + and whatever buttons.

Google in particular is everywhere with their gAnalytics tracking code.

edit: now that I think about it, I may have misunderstood the point. Was it a proof of concept of providing cross-site tracking without tying to a personal identity?

If not, insecurities in cross-site whatever hardly matter when I am logged into every little tidbit that is loaded via iframe and appears on almost every website. Even porn sites have like buttons these days.

Re: The Underpants Project

#6
post #3
post #2

With NoScript, it does not provide a tracking ID. Which shows yet another reason to browse with NoScript.

*The following is your unique fingerprint on the web:* *loading...* I'll bet my fingerprint isn't unique.

https://panopticlick.eff.org/

You'd be surprised.

Re: The Underpants Project

#7

Simply resizing my browser window before pasting the second url seems to thwart this (But I don't have flash installed). Without flash, it falls firmly into the "kinda-works sometimes if everything goes perfect" camp. So its another demonstration of flash being ridiculously insecure. These guys did it better, even defeating tor to reveal the origin IP. http://dl.packetstormsecurity.net/0610-advisories/Practical_...

Resizing my browser didn't go it but moving it to another screen it changed from "1ccf9e9301db4fb87b1d178d77edad5bfa598057" to "ab0e6beb449408b28473dd66a6f4501528087c0e". I don't think this method is prefect at all or should be used for anything reliable(like logins).
Post reply on HN