Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's possible to differentiate the major browsers and operating systems without javascript, and even the versions can be narrowed down without javascript even with user agent spoofing.

p0f, for example, can do this.

http://lcamtuf.coredump.cx/p0f3/



I didn’t know packets leaked this much information… Thank you for mentioning this.


One of the less obvious things is that the fact you're using a VPN may be leaked on a TCP session by the MTU/MSS values.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: