Live data from Hacker News

The Underpants Project

lab.cubiq.org

71–80 of 87 posts

Re: The Underpants Project

#71
post #59

I'm the (co)author of the project. Please note that it's just a one-day proof of concept, imagine what a well motivated corporation could do. It's nothing new (someone correctly pointed the EFF project) but I wanted to make a real world demo out of it. The demo doesn't store each bits of info separately, it simply creates an hash out of them. If I stored the data separately I could for example identify small user age…

Surely an IP comparison achieves everything this does, and is probably more than 90% reliable?

Re: The Underpants Project

#72

> This technique can be used to find out some of the softwares installed on your system. For example I can say that you probably don't have Adobe Creative Suite installed. Sorry, I have CS3 installed and fully licensed. But still a nice demo.

Presumably they're looking at installed fonts to see if you have Adobe CS, so what did you do with the fonts that would fox this? I'm guessing you're on Mac OSX? Can you have fonts available that aren't apparent to the browser somehow?

If cubiq is right it doesn't check for my old version. It's pretty much a vanilla install on OSX.

Re: The Underpants Project

#73
post #59

I'm the (co)author of the project. Please note that it's just a one-day proof of concept, imagine what a well motivated corporation could do. It's nothing new (someone correctly pointed the EFF project) but I wanted to make a real world demo out of it. The demo doesn't store each bits of info separately, it simply creates an hash out of them. If I stored the data separately I could for example identify small user age…

Surely an IP comparison achieves everything this does, and is probably more than 90% reliable?

Just IP comparison only works if the user's IP is constant, which rules out many phones, tablets, and laptops that frequent coffee shops and restaurant wifi. It also doesn't allow you to tell when IP $a and IP $b are really the same person at home and work. Further, IP comparison doesn't let you distinguish between multiple users coming from the same home or office network, or from a proxy.

Commercial implementations of this sort of tracking include the user's IP in their dataset, but track a number of other datapoints so they can tell if e.g. everything but a user's IP matches an entry in their database, it's probably the same person connecting from a different location.

Re: The Underpants Project

#74

Simply resizing my browser window before pasting the second url seems to thwart this (But I don't have flash installed). Without flash, it falls firmly into the "kinda-works sometimes if everything goes perfect" camp. So its another demonstration of flash being ridiculously insecure. These guys did it better, even defeating tor to reveal the origin IP. http://dl.packetstormsecurity.net/0610-advisories/Practical_...

If someone's foolish enough to run javascript and flash on Tor, of course it's trivially easy to defeat it!

I expect most users of Tor fall into that category.

Re: The Underpants Project

#75
post #3

Earlier quoted context omitted.

*The following is your unique fingerprint on the web:* *loading...* I'll bet my fingerprint isn't unique.

https://panopticlick.eff.org/ You'd be surprised.

"Your browser fingerprint appears to be unique among the 2,155,876 tested so far."

Huh, that's awesome ... in a bad way. According to that page , both my system fonts and browser plugin details are unique among the browsers they've tested thus far.

Re: The Underpants Project

#76
post #34

Simply resizing my browser window before pasting the second url seems to thwart this (But I don't have flash installed). Without flash, it falls firmly into the "kinda-works sometimes if everything goes perfect" camp. So its another demonstration of flash being ridiculously insecure. These guys did it better, even defeating tor to reveal the origin IP. http://dl.packetstormsecurity.net/0610-advisories/Practical_...

Interesting, I had Chrome Flash Block enabled but it did not seem to thwart this.

I have a scriptblocker, an adblocker and ghostery installed. did not thwart this.

Re: The Underpants Project

#77
post #2

With NoScript, it does not provide a tracking ID. Which shows yet another reason to browse with NoScript.

Indeed. Similarly, if you barricade yourself inside your house you'll be well-protected against thieves.

Re: The Underpants Project

#78

Simply resizing my browser window before pasting the second url seems to thwart this (But I don't have flash installed). Without flash, it falls firmly into the "kinda-works sometimes if everything goes perfect" camp. So its another demonstration of flash being ridiculously insecure. These guys did it better, even defeating tor to reveal the origin IP. http://dl.packetstormsecurity.net/0610-advisories/Practical_...

Works on the ipad though. No flash, and cant resize window. Must be working off timezone? Surely some more ipads in the UK?

Re: The Underpants Project

#80
Source site said Fingerprint: cb71811ba44d8d86755b03be8a83938d2946169b And I chose the word: Charismatic

Libellu.la said Fingerprint: e0349008d04cc0c73e5cc9a9ea15a246feebf3b1 Word: Chortle

So... no?

Ipad2, jailbroken with AdBlocket running, no idea if that was a factor or not.

Post reply on HN