Glassbox Tool Exposes Browser Fingerprinting Risks and Limitations of Incognito Mode
Developer and security researcher David Dale has released Glassbox, a tool designed to demonstrate how visible a user is to modern browser fingerprinting systems. The service performs more than 30 checks that advertising trackers, anti-fraud platforms, and other entities commonly use to identify visitors without relying on cookies.
Among the attributes collected are Canvas rendering, WebGL capabilities, installed fonts, WebAssembly support, available APIs, authentication status on third-party sites, and audio processing behavior. Nearly all computations occur locally inside the browser, with the only external request made to a public API for geolocation data.
Users receive raw test results along with a calculated identifiability score. The developer stresses that the score is derived from a mathematical model rather than comparison against an actual database of visitors. Glassbox sums the uniqueness of individual attributes, accounts for built-in browser protections, and caps the result at approximately 33 bits—enough in theory to distinguish one individual among the entire world population.
In tests conducted by The Register, a standard Chrome browser scored 99 percent identifiability and was presumed unique among 7.6 billion browsers. Tor Browser scored 56 percent while Firefox reached 89 percent. These percentages should not be treated as definitive because the tool lacks server-side statistics on how rare each fingerprint actually is in the wild.
Dale notes that the most effective way to reduce visibility is to use a browser that blends into a large group of identical users. Overly customized or hardened configurations can backfire, as a unique combination of disabled APIs may itself become a strong identifier. He also recommends combining VPN or Tor with measures to block WebRTC leaks.
Related articles
Android 17 Adds Local Network Protection and Strengthens Wi-Fi Privacy Controls
Android 17 introduces Local Network Protection, requiring apps to obtain explicit permission before scanning or connecting to devices on the same Wi-Fi network. The feature limits unauthorized discovery of TVs, cameras, printers, consoles and other local equipment that could previously be used to build detailed user profiles. The update also enables Encrypted Client Hello by default to hide domain names during HTTPS handshakes from network observers. Certificate Transparency is now activated by default to detect fraudulent or mis-issued certificates that could enable interception attacks. Additional safeguards block forced downgrades to insecure 2G networks often exploited by fake base stations for SMS-based fraud. These changes collectively reduce passive tracking and man-in-the-middle risks without disrupting legitimate local network functions such as media casting.
Review of GL.iNet Mudi 7 and Xray Configuration for Flexible Traffic Routing
The article provides a hands-on review of the GL.iNet Mudi 7 portable router combined with detailed instructions for deploying Xray. The author explains moving away from managing multiple separate VPN clients by installing Xray directly on the router. This setup allows all connected devices to route traffic intelligently without manual configuration on each endpoint. Local and Russian services connect directly to avoid latency, while international traffic is forwarded through a personal server. The guide covers practical scenarios for home use and emphasizes maintaining speed for permitted connections while ensuring selective proxying for the rest of the traffic.
Taiwan Man Uses Robot Vacuum Camera to Prove Wife's Affair, Wins Compensation but Receives Prison Sentence for Illegal Recording
A resident of Taiwan suspected his wife of infidelity after discovering a stranger's toothbrush in their countryside home. He reviewed footage from a parking lot camera and later accessed the live feed of their robot vacuum cleaner through its mobile application, capturing intimate recordings without consent. The man preserved the video evidence and successfully sued for breach of marital rights, receiving approximately $19,000 in compensation. His wife filed a counterclaim, arguing that the recordings violated her right to privacy because the device's sensors and indicators did not clearly indicate active surveillance. Although the footage was accepted in the civil case, the court ruled that the illegal method of obtaining it outweighed marital obligations, prioritizing personal privacy protections. The husband was sentenced to five months in prison and fined 150,000 Taiwanese dollars, representing 30 percent of his awarded compensation.
Russian Firms Accumulate Digital Clutter: 35% of Corporate Files Unused for Years, Weak Passwords Expose Sensitive Data
A study by Russian cybersecurity firm Garda examined more than 157 terabytes of data and over 511,000 user accounts across more than 100 companies. Researchers found that approximately 35% of files in corporate repositories had not been accessed for more than five years, while duplicate data could occupy another 35% of storage volume. In several industries, up to one-third of stored content consisted of personal photographs, videos, and archives unrelated to business operations. More than 33% of accounts used critically weak passwords or credentials that had not been changed for extended periods, and numerous contractor and temporary employee accounts remained active despite being unused for over 90 days. Direct access permissions bypassing security groups were widespread, allowing broad access to folders containing passport scans, client registries, and database exports. Garda recommends automated inventory, classification, centralized access management, and lifecycle automation to reduce risks instead of manual cleanup.