Hacker News new | comments | ask | show | jobs | submit login

So, literally all this said was:

- "MacIntel"

- some stuff from my User Agent string (changing it to IE11 made it think I'm on Windows 8)

- my public IP, network provider and approx. downstream speed.

I don't use Facebook or Google so I don't know if those things would have worked.

None of the network scanning worked, it didn't use the geolocation stuff, etc.

If Chrome/Firefox/IE do allow access to all/some of those things without prompting, jesus titty fucking christ.

All of you claiming "Safari is the new IE6" need to perhaps pay attention.

Google has a vested interest in pushing browser technologies regardless the cost to privacy or user security - their ChromeOS devices depend on a world where web apps can do everything.

Same here, it didn't detect some of the things it should have (theoretically?), e.g. AdBlock plug-in, Twitter & Co., and the EXIF data wasn't fully exposed. The geo location was wrong by some 70 miles, but that's a question of a proper geoip database I suppose.

All in all, not very spooky with Safari at least.

I think it's specifically not GeoIP location - that doesn't require a browser to leak anything as its using your public IP address.

I assume (because mine didn't show anything) that it's relying on the browser leaking it's device-detected location without prompting?

Right it does not use the HTML5 Geolocation GPS. It uses Google's Geolocation API to locate the user without asking for permission.

I don't think it's possible without user's permission, so no it's likely one of those public GeoIP databases which are usually a bit behind, inaccurate and incomplete.

Hmm yes, quite odd. The first time I loaded the site, nothing appeared in the location area, leading me to suspect that it was abusing a prompt-less device location API.

After your comment I loaded the page again, and sure enough it shows a very specific, but quite wrong location. Wrong province wrong.

I actually got better GeoIP results than that (down to the local city) on my old broadband connection. I just tried it now (we moved 2KM and changed ISP, from DOCSIS to ADSL) and all I get is the country now - possibly because its dynamic whereas our DOCSIS IP never seemed to change.

So it's kind of creepy on Google's part that they even offer this service, but the data seems to be so woefully useless that I can't believe anyone would actually use it.

Guidelines | FAQ | Support | API | Security | Lists | Bookmarklet | Legal | Apply to YC | Contact