Vytal can Spoof your timezone, locale, geolocation and user agent. This data can be used to track you or reveal your location.
Most extensions that provide anti-fingerprinting features rely on content scripts to inject script tags into webpages. There are many limitations to script tag injections which you can read about here: https://palant.info/2020/12/10/how-anti-fingerprinting-exten...
Vytal utilizes the chrome.debugger API to spoof this data. This allows the data to be spoofed in frames, web workers and during the initial loading of a website. It also makes the spoofing completely undetectable.
You can test and compare Vytal and other extensions on https://vytal.io
Unfortunately it doesn't work on Firefox since Firefox doesn't support the debugger API. Works on Brave tho.
It's my understanding that the usage of the debugger is detectable by scripts running on the page. I've actually come across content websites that will refuse to activate their features (play video) if the debugger is active.
Similarly on Android some video streaming apps will refuse to load and play their content catalog if USB debugging is enabled.
A javascript file, whose name changes with every refresh, is loaded. The script calls the `debugger` keyword, which only functions when you have DevTools open.
Meanwhile, a tickers is running. If a tick takes too long, it interprets that as the debugger having been called.
<script>
setInterval(function() {
try {
let before = new Date().getTime();
// This will pause the program execution if debugging is enabled.
// If debugging isn't enabled this statement is a no-op.
debugger;
let after = new Date().getTime();
// Detect if the program was paused or not.
if (after - before > 0.01) {
// > 10ms difference? The program was (most likely) paused by the debugger.
document.body.innerHTML = "<h1>Debugging started</h1>";
}
} catch(e) {}
}, 1000);
</script>
There are some other ways to detect it by implementing various prototype methods and continually logging the object to the console. The methods are only invoked if the dev console is opened.I think you’re probably right that it wouldn’t detect presence of your extension, since that code runs in its own context and I assume doesn’t actually call the debugger. If your extension injects a script into the page, then that could be detected with this technique or similar.
This method and a few others are described in this paper: https://www.usenix.org/system/files/sec21-musch.pdf
The debugger timing method is described on page 10.
"Vytal" started debugging this browser
Is there a way to get rid of it?
This should work
chrome.exe --silent-debugger-extension-api
Is it safe to do? I mean I want to stop this message for Vytal only, because I know that it uses debugger API. But I would want to know if tomorrow my adblocker starts to use debugger API.
For example:
I don’t believe this is possible in client JavaScript within a web browser. Very open to be proved wrong.
(FWIW, a website that is given media recording privileges can definitely do that, though, using WebRTC. If you don't have that privilege then you can still use the WebRTC API but it doesn't return alternative candidates. But I also don't think that is what they meant.)
There are services that wardrive around mapping locations of WiFi access points. Your laptop periodically will phone home with your nearby Wi-Fi MAC addresses (BSSIDs) to ask where they were detected.
Here's one such service: https://www.skyhook.com/wifi-location-solutions
When Location Services is on (which it is by default), macOS will periodically switch your wireless card to monitor mode to find those nearby SSIDs. That briefly interrupts normal network traffic.
IIRC, it does this more often when Find My.app is turned on.
You can disable Location Services in: System Preferences > Security & Privacy > Location Services
: if you're on Android, you'll need either an unstable version (Beta, Nightly) or a fork (Fennec from F-Droid) of Firefox to get access to that page because Mozilla decided users of the standard distribution can't be trusted with these settings.
I won't be going to anything chrome-like, but I do see myself spending a lot more time using and sponsoring qutebrowser, or simply passively consuming offline.
Most of my linux desktop usage these days is stuff like writing scrapers in cloud containers that need a real browser that I can control using selenium or puppeteer or whatever though, is it supporting anything like that? If this works on Windows too that would be a bonus.
Doesn't Mozilla's revenue breakdown still show Google as the majority of their revenue, and pocket et al are efforts to diversify?
You can literally accomplish this in firefox by other means.
https://security.stackexchange.com/questions/147166/how-can-...
Is there a risk that installing Chrome plugins makes your browser fingerprint more unique? Isn't the list of installed plugin-ins checked?
Vytal has no web-accessible resources so it can not be detected.
[1] https://developer.chrome.com/docs/extensions/reference/scrip...
The most common reason why you VPN didn't work is that they simply block IP ranges of common used (proxy) servers. They also can check if the IP is "Native IP" (means it's actually registered in the country that the server is in.)
So I tried creating a VPS in the same city as them last night, used freakin' lynx on a terminal so sans-Javascript, and lo and behold, still detected that I wasn't in their country :/
I think I've worked out how tho. They detect VPN/proxies, where there are plenty of libraries to do so.
So I tried creating a VPS in the same city as them last night, used freakin' lynx on a terminal so sans-Javascript, and lo and behold, still detected that I wasn't in their country :/
[1] https://developer.chrome.com/docs/extensions/mv3/messaging/
In my case, I’m interested in doing the same thing inside of Puppeteer for web scraping, unfortunately it seems like the only possible approach is similar to content scripts (for example https://github.com/berstend/puppeteer-extra/tree/master/pack...) which leads to it being easily detected. Are there any similar approaches that can be used for Puppeteer?
However is there any features over just going to developer tools > Sensors > Location and overriding it manually?
Is it just to be able to match your IP automatically ?
I'm currently using it on brave, and there is always an info bar that pops up("Vytal" started debugging this browser session)
Is there a way to permanently dismiss this?, because it pops up with every refresh and its very annoying.
Great job!
https://addons.mozilla.org/en-CA/firefox/addon/user-agent-sw...
Using a VPN as a proxy to circumvent geographical block is reasonable to a certain extent, but call them a privacy help, when you do not own the server is ridiculous...
It's hard to believe for me...
If I host my VPN for instance to include some remote machines to my LAN, or as a company to offer a LAN to nomadic clients, that's a thing. If I decide to route 100% of my traffic to some servers in exotic locations where no privacy laws exists, where I probably never ever look for a local lawyer just because of lack of norms, language and costs issues, it's IMVHO a crazy choice like those who regularly buy "anti-5G radiation-absorber stickers" or "air purifier" and things like that.
My ISP might spy on me, surely they do, but we have a contract under local laws we both knows, we speak the same language, I have a local lawyer I trust etc. Using something else to circumvent eventual geo-blocks ok, but for the rest? How can I trust more an unknown third from exotic places telling in its advertisement "we care about privacy"?
Surely the only correct answer is:
1) Go to browser preferences
2) Go to Privacy & Security
3) "Don't allow sites to see your location" = ON
Firefox has this. Brave has this.
And if you use Chrome, well, sharing your location is probably the least of your worries !Check out https://vytal.io/. There are many more data points then just the geolocation api.
I think most people would agree that your so called additional data points are worthless for the purpose that most people would be concerned about location data.
Something like timezone "location" (which basically what your vytal website is showing) is simply not granular enough to be used for nefarious purposes.
I mean, if my browser is telling someone that my "location" is EDT timezone what good is that going to do them ? Its still too much of haystack to be useful to anyone.
Let's be honest here, "location" to most people means GPS-type location (i.e. you'll find me in this house on this street). Anything more coarse than that is frankly of limited use to an adversary.
* browser with IP in USA but timezone in Russia
* browser with IP in USA and timezone in USA
* browser with IP in Russia with timezone in Russia
Hint: it’s the middle one. The smaller the anonymity set, the more conspicuous and therefore fingerprintable you are.