I’ve just been playing around with https://browserleaks.com/fonts . It seems no web browser provides adequate protection for this method of fingerprinting – in both brave and librewolf the tool detects rather unique fonts that I have installed on my system, such as “IBM Plex” and “UD Digi Kyokasho” – almost certainly a unique fingerprint. Tor browser does slightly better as it does not divulge these “weird” fonts. However, it still reveals that the google Noto fonts are installed, which is by far not universal – on a different machine, where no Noto fonts are installed, the tool does not report them.

For extra context: I’ve tested under Linux with native tor browser and flatpak’d Brave and Librewolf.

What can we do to protect ourselves from this method of fingerprinting? And why are all of these privacy-focused browsers vulnerable to it? Is work being done to mitigate this?

  • dohpaz42@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 months ago

    I’m an iOS user who has not installed custom fonts. I’m sure I’m not the only one. Certainly that wouldn’t provide much useful information?

  • electricprism@lemmy.ml
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    5 months ago

    There’s something beautiful about the simplicity of Gemini in Kristal and LaGrange.

    You set your font and colors offline and it’s universal.

    Hyper Text Web is great but I wonder if we will see a return to simplicity in high tech circles now that the Net is the new “Television Rules The Nation”

    • lemmyreader@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      I guess the important thing is in the unique versus total in for example 200 fonts and 150 unique metrics found.

      • kenkenken@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        It doesn’t matter really, one can write any words on a webpage, but show me the proof e.g. an unique and permanent resulting fingerprint.

        I see from topics like this that many people don’t understand fingerprinting, just showing a fingerprint, a soft of ID means nothing. A fingerprint must be:

        1. Unique for a particular browser instance, or at least effectively rare. For example, when the same browser on different distros shows different fingerprints.
        2. Permanent, the same each time you launch the browser.