Live data from Hacker News

Supercookie: Browser Fingerprinting via Favicon (2021)

github.com

51–60 of 105 posts

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#51

I don't understand the live demo it gave me some ID, but how do I test that some different website can track me resulting in same ID? or is it only "detect private browsing/container on same browser" kind of stuff?

The "supercookie" phenomenon from a few years ago (when this was created) was that despite using private browsing or deleting cookies, the site id remains the same for the same browser.

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#53
post #2

I was sure this has been a thing for a while, either that or safari has a UI bug since forever. I regularly get the wrong favicon in specific sites, for example ars technica favicon in reddit

Safari has super long lived favicon caches too. The only way to force a rebuild is to set your system clock forward a few years.

According to the Github page, you can just run `rm ~/Library/Safari/Favicon Cache/*`

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#56
post #2

I was sure this has been a thing for a while, either that or safari has a UI bug since forever. I regularly get the wrong favicon in specific sites, for example ars technica favicon in reddit

My hacker news icon has been stuck as the icon for a weather site that I sometimes check. It’s been stuck that way for close to a year now, and has survived an iOS update too. It persists across profiles and into private browsing mode.

[deleted]

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#57
post #2

I was sure this has been a thing for a while, either that or safari has a UI bug since forever. I regularly get the wrong favicon in specific sites, for example ars technica favicon in reddit

For me the iOS HN icon changes between the reddit and github, depending on which one I've been using the most on my phone recently. This happens on both iOS Safari and Kagi's Orion.

I thought that this was just a bug in iOS but based on the comments in this thread, it seems to be common not only across OSes but browser vendors too (I assume iOS Orion uses the same engine as Safari)

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#58

Earlier quoted context omitted.

Safari has super long lived favicon caches too. The only way to force a rebuild is to set your system clock forward a few years.

According to the Github page, you can just run `rm ~/Library/Safari/Favicon Cache/*`

yes, but time travel is cooler

Re: Supercookie: Browser Fingerprinting via Favicon (2021)

#59
At some point we need actual consequences for sites that intentionally hide their tracking. It should be criminal. It is stalking and has real world consequences. Just because an exploit exists doesn't mean it should be used. That logic is like saying it is OK to break into a house because the lock on the door was weak. If we don't get real protections, at what point does it become justified to go offensive against sites that exploit things like this? If I found someone putting trackers on me with the intent to sell that information (harm me) I would defend myself. When am I allowed to do that in the digital world?

Quick side note here. I appreciate the research calling this out. We need to know the dangers out there to figure out how to protect ourselves, especially since governments don't seem to take this seriously.

Post reply on HN