Does this mean browser fingerprint is somehow scrambled before it is sent to the tracker instead of blocking?
Does this mean browser fingerprint is somehow scrambled before it is sent to the tracker instead of blocking?
It might be homogenized instead of scrambled. Every iOS device could be given (barring IP etc.) the same fingerprint.
But that doesn't affect iOS, because you can't install fonts on iOS.
Custom fonts can be installed via custom configuration profiles[0], which is what some font applications do[1]
I'm not sure if this is exposed via Safari or not, so it could still be a moot point.
[0] - https://developer.apple.com/library/content/featuredarticles...
Alternately: why not anonymize CSSOM return values? Your browser might have access to OS fonts A+B+C, but if your JS asked the CSSOM about the size of characters on the page, the answer it would give would come from an "alternate world" where the browser only has access to the web-safe fonts, and so is using one of them.
For a specific example, it's more pleasing to split a long line of text in a way that all the split lines have roughly the same length - "a a a b b b" -> "a a a\nb b b". But CSS only gives you one way to split lines - as much text as possible in all but the last line and whatever's leftover in the last line - "a a a b b\nb". This means a renderer library has to be able to measure the width of text to be able to insert linebreaks itself.
Changing line-lengths will cause odd bits of layout breakage, so just giving bogus results as if rendered with a different set of fonts won't work properly either.