So does this mean that something like example.com/password-reset?token_id=2h2GV4nhySERT9pJ may get the random token stripped?
I don't understand how you can have a heuristic that doesn't break things.
I don't understand how you can have a heuristic that doesn't break things.
It has a specific blacklist of parameters to strip. In the several years I've been using it, I've only had two websites break from it, both being legit surveys that I needed to take.
View the demo in normal mode at https://fingerprint.com/ and then open it again in Incognito