# Discourse Fingerprint - Browser Fingerprinting Plugin

**URL:** https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890
**Category:** Plugin
**Tags:** experimental
**Created:** [May 7, 2019, 9:45am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890 "2019-05-07T09:45:03Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![mcdanlj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcdanlj/32/131829_2.png) [@mcdanlj](https://meta.discourse.org/u/mcdanlj)
#### Post date: [August 24, 2020, 11:54am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/22 "2020-08-24T11:54:59Z")

</div>

I had a user ask me as an admin to help them with something, so I impersonated them to make sure I understood the problem they were seeing.

Now I’m registered as sharing a fingerprint with this user. I hid that fingerprint, but it’s still noise on the fingerprint display.

Given the ability of admins to impersonate, would it make sense to have a setting to exclude staff, or at least admins, from fingerprint matching?

---

<div class="post-metadata">

### Author: ![Chaboi\_3000](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chaboi_3000/32/163015_2.png) [@Chaboi\_3000](https://meta.discourse.org/u/Chaboi_3000)
#### Post date: [August 26, 2020, 10:05pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/23 "2020-08-26T22:05:41Z")

</div>

Are there any plans for this plugin to be added to Business hosting? This would help me fingerprint possible sockpuppets much easily. If not, what other alternatives do you recommend?

---

<div class="post-metadata">

### Author: ![WorldIsMine](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/worldismine/32/455660_2.png) [@WorldIsMine](https://meta.discourse.org/u/WorldIsMine)
#### Post date: [September 8, 2020, 8:04am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/24 "2020-09-08T08:04:48Z")

</div>

Looks like an awesome plugin, giving it a whirl now.

---

<div class="post-metadata">

### Author: ![WorldIsMine](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/worldismine/32/455660_2.png) [@WorldIsMine](https://meta.discourse.org/u/WorldIsMine)
#### Post date: [September 10, 2020, 9:59am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/25 "2020-09-10T09:59:50Z")

</div>

My observations so far.

Lots of matches and lots of data to look through if one was to fish for suspected duplicate accounts. In my opinion, this plugin would be a lot more useful if the fingerprint list highlighted (or prioritized) matching devices if one of the members is/was banned and/or silenced. There are very few reasons people will set up secondary accounts when not banned, but banned members will always try to sneak in. Having this show up on the list would most likely make this plugin more useful.

---

<div class="post-metadata">

### Author: ![Mevo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mevo/32/187732_2.png) [@Mevo](https://meta.discourse.org/u/Mevo)
#### Post date: [September 10, 2020, 11:57am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/26 "2020-09-10T11:57:10Z")

</div>

> [@WorldIsMine](#):
>
> There are very few reasons people will set up secondary accounts when not banned

I disagree with you on that. Sockpuppeting can be a major problem in some communities. Also, some users are more prone to do that kind of thing, almost wherever they participate. I’ve personally seen it.  
I’m also not sure about the “_always_ try to sneak in” when it comes to banned members.

Now, this doesn’t say your suggestion can’t be useful.

---

<div class="post-metadata">

### Author: ![WorldIsMine](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/worldismine/32/455660_2.png) [@WorldIsMine](https://meta.discourse.org/u/WorldIsMine)
#### Post date: [September 10, 2020, 12:28pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/27 "2020-09-10T12:28:18Z")

</div>

I guess you’re right now that I think of it. Forgot about users creating secondary accounts to push their agenda, whatever that may be.

---

<div class="post-metadata">

### Author: ![dan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dan/32/101549_2.png) [@dan](https://meta.discourse.org/u/dan)
#### Post date: [October 12, 2020, 9:46am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/29 "2020-10-12T09:46:27Z")

</div>

> [@preterive](#):
>
> I would really like a feature to ban a fingerprint.

Users can be silenced next time they visit the site with a matching fingerprint.

> [@Foriusz](#):
>
> Missing translation

> [@RubyRhod](#):
>
> It’s missing a couple of translations

These errors should be fixed.

> [@MarcP](#):
>
> How do I delete this plugin? Did a rebuild after removing the line from my app.yml but the plugin is still there.

Removing the line from app.yml and rebuilding your instance should be enough.

> [@RubyRhod](#):
>
> And I can’t click on the ignore flag - important because as the administrator of the site, I need an ‘alternative ego’ to post as a regular user, not as the admin.

What error are you experiencing?

> [@mcdanlj](#):
>
> Given the ability of admins to impersonate, would it make sense to have a setting to exclude staff, or at least admins, from fingerprint matching?

I think I could add an option for that.

> [@WorldIsMine](#):
>
> Lots of matches and lots of data to look through if one was to fish for suspected duplicate accounts. In my opinion, this plugin would be a lot more useful if the fingerprint list highlighted (or prioritized) matching devices if one of the members is/was banned and/or silenced. There are very few reasons people will set up secondary accounts when not banned, but banned members will always try to sneak in. Having this show up on the list would most likely make this plugin more useful.

I agree with you and I believe I could implement some indicator to highlight banned users.

> [@anon54446237](#):
>
> Hey, we’ve just started to get 500’s on attempting to load the /fingerprint page. Not sure what’s happened here - any ideas?

Hmm, that is an interesting error given that there are already checks to ensure that method is not called unless data really exists. Are you running the latest version?

> <https://github.com/discourse/discourse-fingerprint/blob/main/app/serializers/flagged_fingerprint_serializer.rb#L22-L26>

---

<div class="post-metadata">

### Author: ![mcdanlj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcdanlj/32/131829_2.png) [@mcdanlj](https://meta.discourse.org/u/mcdanlj)
#### Post date: [October 12, 2020, 12:42pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/30 "2020-10-12T12:42:10Z")

</div>

> [@Mevo](#):
>
> Sockpuppeting can be a major problem in some communities.

I’ve had one new link spammer come in with _five_ sockpuppet accounts before _any_ of the accounts were banned. It’s real. I’d expect that almost any site that gets search traffic and has open sign-up probably is getting SEO spam sockpuppets; the only question is whether admins are _finding_ it. :smiley:

@dan one more suggestion after having used this plugin more: In the list of users matching a fingerprint, I keep on clicking on users’ avatars, expecting them to be links to their admin pages or profiles, so that I can easily investigate whether they are accidental matches or actually sock puppets. I’d suggest admin page would probably be more useful for that investigation, but either would be easier than reading the hovertext, memorizing their user id from the hovertext, then hoping I type it right in user search to finally get to their actual user data. :smiling_face:

---

<div class="post-metadata">

### Author: ![dylanh724](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dylanh724/32/119642_2.png) [@dylanh724](https://meta.discourse.org/u/dylanh724)
#### Post date: [October 14, 2020, 3:08am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/32 "2020-10-14T03:08:04Z")

</div>

This plugin is amazing … so many of the trolls caught that would just keep changing VPN IP.

This should be considered to be native to Discourse ( @codinghorror ). Cookies, cache and IP don’t do justice for catching repeated troll attacks in 2020.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [October 14, 2020, 4:07am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/33 "2020-10-14T04:07:23Z")

</div>

Except it totally fails when your users have iPhones. That is a critical weakness, and it is impossible to surmount.

---

<div class="post-metadata">

### Author: ![mcdanlj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcdanlj/32/131829_2.png) [@mcdanlj](https://meta.discourse.org/u/mcdanlj)
#### Post date: [October 16, 2020, 2:13pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/34 "2020-10-16T14:13:31Z")

</div>

It turns out that my spammers aren’t using iphones. We use [data explorer](https://meta.discourse.org/t/32566?silent=true) to look for the “start with innocuous text and later edit it to be link spam” attacks, and fingerprint has done a good job of helping identify those spammers and help us shut down attacks faster. Not making the argument that it should be included by default; I don’t like collecting PII and don’t collect it without cause. If we didn’t have a spammer/troll problem I would absolutely not want to be using it, not because it’s nefarious, but because I don’t want to collect PII without a need related to providing service. So I think that it’s useful but also it makes sense to me that it’s a plugin rather than core. Making it be a conscious choice is a win for privacy. I asked my whole mod community about how they felt about it before implementing it, and was glad to have that conversation up front.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [October 23, 2020, 12:33am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/35 "2020-10-23T00:33:00Z")

</div>

That’s fine, it’s an experiment I am happy to run, but everyone needs to be aware the trend is strongly towards browsers locking down all fingerprinting methods. This trend is most advanced in iOS but I expect it to extend to almost all browsers and platforms over time.

---

<div class="post-metadata">

### Author: ![mcdanlj](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcdanlj/32/131829_2.png) [@mcdanlj](https://meta.discourse.org/u/mcdanlj)
#### Post date: [October 23, 2020, 2:40am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/36 "2020-10-23T02:40:06Z")

</div>

This is where discourse half-threading gets confusing; not sure who you are meaning to respond to, which leaves your antecedent unclear. Not sure if you’re actually responding to me or to @dylanh724…

In any case, I think that the status quo of leaving it in a plugin is a good idea.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [October 23, 2020, 3:09am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/37 "2020-10-23T03:09:35Z")

</div>

The context is clear; I’m replying to the topic (fundamental weaknesses of browser fingerprinting), and to anyone who finds what I said relevant to them.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [November 21, 2020, 8:43am UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/40 "2020-11-21T08:43:06Z")

</div>

Some related news

> **[Cover Your Tracks](https://coveryourtracks.eff.org/)**
>
> See how trackers view your browser

---

<div class="post-metadata">

### Author: ![anon23393886](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@anon23393886](https://meta.discourse.org/u/anon23393886)
#### Post date: [November 21, 2020, 4:47pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/41 "2020-11-21T16:47:59Z")

</div>

With Firefox (and Safari, I think) now blocking fingerprinting, the nail in the coffin will be when Google Chrome blocks fingerprinting by default, then the rest of the Chromium dominoes will follow.

---

<div class="post-metadata">

### Author: ![ArcticTheHunter](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/arcticthehunter/32/200189_2.png) [@ArcticTheHunter](https://meta.discourse.org/u/ArcticTheHunter)
#### Post date: [December 1, 2020, 1:49pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/42 "2020-12-01T13:49:19Z")

</div>

Could this give a false positive if two people are sharing a computer?

---

<div class="post-metadata">

### Author: ![Mevo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mevo/32/187732_2.png) [@Mevo](https://meta.discourse.org/u/Mevo)
#### Post date: [December 1, 2020, 1:55pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/43 "2020-12-01T13:55:34Z")

</div>

Same computer AND same browser, it sure will. A POSITIVE, nothing false in it :slight_smile: (It analyzes the browser, not the user behind the keyboard)

---

<div class="post-metadata">

### Author: ![anon23393886](https://avatars.discourse-cdn.com/v4/letter/a/a698b9/32.png) [@anon23393886](https://meta.discourse.org/u/anon23393886)
#### Post date: [December 9, 2020, 9:57pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/44 "2020-12-09T21:57:35Z")

</div>

Isn’t that pretty easy to bypass (whether that be through Tor or a different method)?

---

<div class="post-metadata">

### Author: ![Mevo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mevo/32/187732_2.png) [@Mevo](https://meta.discourse.org/u/Mevo)
#### Post date: [December 9, 2020, 10:36pm UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/46 "2020-12-09T22:36:08Z")

</div>

> [@anon23393886](#):
>
> through Tor or a different method

Everything can be bypassed. Here, it isn’t linked to the IP (what Tor or a Vpn would help with) but on the BROWSER. The easiest way to go around this is to use another browser, or directly another device (you still need to do this ON TOP of the Tor/Vpn thing to not be detected with the IP address)

[Previous page](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890.md?page=1)

[Next page](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890.md?page=3)
