# Discourse Fingerprint - Browser Fingerprinting Plugin

**URL:** https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890
**Category:** Plugin
**Tags:** experimental
**Created:** [7 mei 2019 om 09:45 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890 "2019-05-07T09:45:03Z")
**Posts on this page:** 10
**Page:** 4

<div class="post-metadata">

### Author: ![Aaron\_Walsh](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/aaron_walsh/32/312661_2.png) [@Aaron\_Walsh](https://meta.discourse.org/u/Aaron_Walsh)
#### Post date: [25 april 2024 om 16:56 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/70 "2024-04-25T16:56:01Z")

</div>

> [@Jumanji](#):
>
> The plugin.

The plugin used to gather all users using the same IP address without manual searching. But this has stopped working now, and I can only find out by searching.

---

<div class="post-metadata">

### Author: ![Roi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roi/32/130587_2.png) [@Roi](https://meta.discourse.org/u/Roi)
#### Post date: [18 juli 2026 om 09:51 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/71 "2026-07-18T09:51:28Z")

</div>

I just upgraded Discourse and see a message now:

> **[Admin-Hinweis]** Eines deiner Themes oder Plug-ins enthält Code, der aktualisiert werden muss. (ID:discourse.deprecated-resolver-normalization)

And in developer console:

`DEPRECATION NOTICE: Looking up 'route:admin-plugins-fingerprint' is no longer permitted. Rename to 'route:admin-plugins/fingerprint' instead [deprecation id: discourse.deprecated-resolver-normalization]`

---

<div class="post-metadata">

### Author: ![Overgrow](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/overgrow/32/478189_2.png) [@Overgrow](https://meta.discourse.org/u/Overgrow)
#### Post date: [1 augustus 2026 om 16:51 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/72 "2026-08-01T16:51:20Z")

</div>

Following up on the deprecation above.. on current core (v2026.8.0-latest.1) it’s not just a warning any more, the report page itself looks broken.

`/admin/plugins/fingerprint` comes up with an empty “latest matches” and flagged list, and the console throws:

```plaintext
Uncaught (in promise) TypeError: Cannot convert undefined or null to object
    at Object.values (<anonymous>)
    at fingerprint-report.js:58

```

---

<div class="post-metadata">

### Author: ![Roi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roi/32/130587_2.png) [@Roi](https://meta.discourse.org/u/Roi)
#### Post date: [7 augustus 2026 om 20:53 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/73 "2026-08-07T20:53:44Z")

</div>

My imaginary friend and I tried around a litte bit and came up with two changes for this plugin. One for the deprecation notice and one for the JS error in the development console of the browser.

> **[Comparing discourse:main...msebald:main · discourse/discourse-fingerprint](https://github.com/discourse/discourse-fingerprint/compare/main...msebald:discourse-fingerprint:main)**
>
> A plugin that computes user fingerprints to help administrators combat internet trolls. - Comparing discourse:main...msebald:main · discourse/discourse-fingerprint

I would like to ask you to take a look at this. I can’t really program.

If the fixes are okay I can do a PR. If desired.

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [8 augustus 2026 om 00:30 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/74 "2026-08-08T00:30:23Z")

</div>

I usually spoof my fingerprints; how will it treat folks like me? I promise I’m not a troll 😂

Asking because I’m with the privacy tribe, and they are usually very respectful of discussion ethos but do not want to give their data everywhere and every time.

---

<div class="post-metadata">

### Author: ![Overgrow](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/overgrow/32/478189_2.png) [@Overgrow](https://meta.discourse.org/u/Overgrow)
#### Post date: [10 augustus 2026 om 16:05 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/75 "2026-08-10T16:05:02Z")

</div>

I don’t see browser fingerprints as a real threat to privacy. I’d rather have tools to protect against botnets, spoofed fingerprints, scrapers and DoS attacks than focus on alleged privacy. As a site operator, that’s a real threat for me.

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [10 augustus 2026 om 16:13 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/76 "2026-08-10T16:13:43Z")

</div>

Well, in EU fingerprinting is considered as a real threat, and that’s why it is forbidden.

---

<div class="post-metadata">

### Author: ![Overgrow](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/overgrow/32/478189_2.png) [@Overgrow](https://meta.discourse.org/u/Overgrow)
#### Post date: [10 augustus 2026 om 20:24 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/77 "2026-08-10T20:24:45Z")

</div>

It is not forbidden. And I have legitimate use case: to flag account bot activity and suspicious login patterns, etc.

But don’t trust my words. Check yourself what Cloudflare is doing and how with EU based sites.

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [11 augustus 2026 om 01:19 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/78 "2026-08-11T01:19:10Z")

</div>

> [@Overgrow](#):
>
> I don’t see browser fingerprints as a real threat to privacy

Well, some of us see the opposite:

> **[Executive Summary](https://browsergate.eu/executive-summary/)**
>
> Microsoft Corporation’s LinkedIn is running a massive, global, and illegal spying operation on every computer that visits their website.
> 1. The Regulation of Linkedin In 2024 Microsoft was designated as a “gatekeeper” under the Digital Markets Act in...

> **[Apple Safari Fingerprinting Privacy Class Action](https://openclassactions.com/lawsuits/privacy/apple-safari-fingerprinting-privacy-class-action-lawsuit.php)**
>
> A new complaint alleges Safari lets third parties fingerprint users despite Apple's privacy promises, even in Private Browsing.

> **[Toyota broadsided by website tracking class action](https://www.courthousenews.com/toyota-broadsided-by-website-tracking-class-action/)**
>
> According to one business that specializes in privacy compliance, more than 800 such "trap and trace" claims were filed in 2025 alone.

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [11 augustus 2026 om 06:12 UTC](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890/79 "2026-08-11T06:12:25Z")

</div>

> [@Overgrow](#):
>
> It is not forbidden. And I have legitimate use case: to flag account bot activity and suspicious login patterns, etc.

That is not a legitime use case at all. You just can’t use such profiling tool for masses that creates a database to indentify individuals.

[Vorige pagina](https://meta.discourse.org/t/discourse-fingerprint-browser-fingerprinting-plugin/114890.md?page=3)
