(default settings)
|
brave 1.62 |
chrome 121.0 |
edge 121.0 |
firefox 122.0 |
librewolf 122.0-2 |
mullvad 13.0 |
opera 107.0 |
safari 17.3 |
tor 13.0 |
ungoogled 121.0 |
vivaldi 6.5 |
---|---|---|---|---|---|---|---|---|---|---|---|
State Partitioning testsWhich browsers isolate websites to prevent them from sharing data to track you?
A common vulnerability of web browsers is that they allow tracking companies to 'tag' your browser with some data ('state') that identifies you. When third-party trackers are embedded in websites, they can see this identifying data as you browse to different websites. Fortunately, it is possible for this category of leaks to be fixed by partitioning all data stored in the browser such that no data can be shared between websites. | |||||||||||
Alt-Svc
Alt-Svc allows the server to indicate to the web browser that a resource should be loaded on a different server. Because this is a persistent setting, it could be used to track users across websites if it is not correctly partitioned. |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: h2, h2, h2, h2 unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: h2, h2, h2 unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same first party: h3, h3, h3, h3 result, different first party: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
blob
A 'blob URL' is a local reference to some raw data. Trackers can use a blob URL to share data between websites. |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: Failed to fetch, Error: Failed to fetch, Error: Failed to fetch, Error: Failed to fetch unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: Error: Load failed, Error: Load failed, Error: Load failed, Error: Load failed unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource., Error: NetworkError when attempting to fetch resource. unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { try { let blobURL = URL.createObjectURL(new Blob([secret])); fetch(`${baseURI}blob?mode=write&key=${secret}&blobUrl=${encodeURIComponent(blobURL)}`); } catch (e) { throw new Error("Unsupported"); } } read: async (secret) => { let response = await fetch(`${baseURI}blob?mode=read&key=${secret}`); let result = await response.json(); let blobUrl = decodeURIComponent(result.blobUrl); let blobResponse = await fetch(blobUrl); return blobResponse.text(); } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
BroadcastChannel
A BroadcastChannel is designed to send messages between tabs. In some browsers it can be used for cross-site communication and tracking. |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { try { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data === "request") { bc.postMessage(secret); } }; } catch (e) { throw new Error("Unsupported"); } } read: () => new Promise((resolve, reject) => { let bc = new BroadcastChannel("secrets"); bc.onmessage = (event) => { if (event.data !== "request") { resolve(event.data); } }; bc.postMessage("request"); setTimeout(() => reject({message: "no BroadcastChannel message"}), 3000); }) result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message, Error: no BroadcastChannel message unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
CacheStorage
The Cache API is a content storage mechanism originally introduced to support ServiceWorkers. If the same Cache object is accessible to multiple websites, it can be abused to track users. |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url'), Error: Cannot read properties of undefined (reading 'url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
cookie (HTTP)
The cookie, first introduced by Netscape in 1994, is a small amount of data stored by your browser on a website's behalf. It has legitimate uses, but it is also the classic cross-site tracking mechanism, and today still the most popular method of tracking users across websites. Browsers can stop cookies from being used for cross-site tracking by either blocking or partitioning them. |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb_http, 46c9d46f-e178-45f0-ae22-71738826c7c6_http, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_http, a2df8ec1-fca5-41b3-b305-178b4c93306a_http result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb_http, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_http, b1ff8f81-4fda-4162-b2be-c5732c406a6d_http, 8d70f742-8fe2-4c59-985f-140ab800ef18_http result, different first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb_http, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_http, b1ff8f81-4fda-4162-b2be-c5732c406a6d_http, 8d70f742-8fe2-4c59-985f-140ab800ef18_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499_http, 11fa82e0-deea-4b47-af13-d5f16a3e3329_http, 58f380ad-8e76-437c-9a17-521fdd79be36_http, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_http result, different first party: af8ae3a9-80a9-49d2-af13-89e657489499_http, 11fa82e0-deea-4b47-af13-d5f16a3e3329_http, 58f380ad-8e76-437c-9a17-521fdd79be36_http, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_http, 2c63bf33-4e2b-4827-b61a-91bac9889546_http, 775a0d7d-da52-4123-ae11-eff48f4a8736_http, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_http result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb_http, c94b72db-c9df-48bf-b945-fba6367c1bb6_http, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_http, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_http result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30_http, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0_http, d6845763-314c-4342-aac7-b6cdd1e6e6c0_http, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9_http result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_http, 5a27df6f-2a5e-48f5-a0be-9430200adc42_http, 6f8771de-d02d-4d13-b826-14ae8e21b13a_http, 39fbf8c7-535b-439c-a1f6-7de01be90e50_http result, different first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_http, 5a27df6f-2a5e-48f5-a0be-9430200adc42_http, 6f8771de-d02d-4d13-b826-14ae8e21b13a_http, 39fbf8c7-535b-439c-a1f6-7de01be90e50_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df_http, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_http, 238c9375-7e5b-48c5-9475-345eb19cb1fb_http, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_http result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8_http, 66050919-0edd-4ff7-912a-afff0332b1d8_http, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d_http result, different first party: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf_http, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_http, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_http, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_http result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75_http, 0e012f74-3469-4f07-ba88-551445db542b_http, 5dec35c7-2d29-4d63-8db1-67275c761c2c_http, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_http result, different first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75_http, 0e012f74-3469-4f07-ba88-551445db542b_http, 5dec35c7-2d29-4d63-8db1-67275c761c2c_http, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
cookie (JS)
The cookie, first introduced by Netscape in 1994, is a small amount of data stored by your browser on a website's behalf. It has legitimate uses, but it is also the classic cross-site tracking mechanism, and today still the most popular method of tracking users across websites. Browsers can stop cookies from being used for cross-site tracking by either blocking or partitioning them. |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb_js, 46c9d46f-e178-45f0-ae22-71738826c7c6_js, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_js, a2df8ec1-fca5-41b3-b305-178b4c93306a_js result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb_js, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_js, b1ff8f81-4fda-4162-b2be-c5732c406a6d_js, 8d70f742-8fe2-4c59-985f-140ab800ef18_js result, different first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb_js, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_js, b1ff8f81-4fda-4162-b2be-c5732c406a6d_js, 8d70f742-8fe2-4c59-985f-140ab800ef18_js unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499_js, 11fa82e0-deea-4b47-af13-d5f16a3e3329_js, 58f380ad-8e76-437c-9a17-521fdd79be36_js, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_js result, different first party: af8ae3a9-80a9-49d2-af13-89e657489499_js, 11fa82e0-deea-4b47-af13-d5f16a3e3329_js, 58f380ad-8e76-437c-9a17-521fdd79be36_js, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_js unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_js, 2c63bf33-4e2b-4827-b61a-91bac9889546_js, 775a0d7d-da52-4123-ae11-eff48f4a8736_js, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_js result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb_js, c94b72db-c9df-48bf-b945-fba6367c1bb6_js, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_js, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_js result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30_js, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0_js, d6845763-314c-4342-aac7-b6cdd1e6e6c0_js, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9_js result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_js, 5a27df6f-2a5e-48f5-a0be-9430200adc42_js, 6f8771de-d02d-4d13-b826-14ae8e21b13a_js, 39fbf8c7-535b-439c-a1f6-7de01be90e50_js result, different first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_js, 5a27df6f-2a5e-48f5-a0be-9430200adc42_js, 6f8771de-d02d-4d13-b826-14ae8e21b13a_js, 39fbf8c7-535b-439c-a1f6-7de01be90e50_js unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: f9fbccbd-9421-476e-91af-07ab091157df_js, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_js, 238c9375-7e5b-48c5-9475-345eb19cb1fb_js, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_js result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8_js, 66050919-0edd-4ff7-912a-afff0332b1d8_js, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d_js result, different first party: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf_js, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_js, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_js, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_js result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75_js, 0e012f74-3469-4f07-ba88-551445db542b_js, 5dec35c7-2d29-4d63-8db1-67275c761c2c_js, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_js result, different first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75_js, 0e012f74-3469-4f07-ba88-551445db542b_js, 5dec35c7-2d29-4d63-8db1-67275c761c2c_js, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_js unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
CookieStore
The Cookie Store API is an alternative asynchronous API for managing cookies, supported by some browsers. |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true passed: undefined test failed: false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
CSS cache
CSS stylesheets are cached, and if that cache is shared between websites, it can be used to track users across sites. |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_33197568708401604, fake_4186145091929727, fake_5846271774929857, fake_23489296739234056 result, different first party: fake_04406981075014649, fake_2635244900177667, fake_35580773094647644, fake_9244295728054781 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_5088700231512708, fake_7785217145243837, fake_018225751075681806, fake_4780249131815044 result, different first party: fake_615310103208417, fake_16798364398383958, fake_10050449831383346, fake_9987118588374222 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_21127689301345742, fake_5143521197946879, fake_7489287678587808, fake_016163353558598992 result, different first party: fake_3686224953166575, fake_8022460050073481, fake_6517288285588483, fake_7697017197061558 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_49835435158862507, fake_2434488922900253, fake_8733344556973253, fake_948600291991635 result, different first party: fake_8112178573338784, fake_7680931258905752, fake_363407662319142, fake_03074829522181788 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_21181179862725186, fake_3200918250625351, fake_8384841906026146, fake_5897947642443684 result, different first party: fake_20787180581438602, fake_7033280097254959, fake_9335011047248132, fake_5633706264383733 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_709038471931335, fake_6531138051013334, fake_10036881603789816, fake_33336522385970047 result, different first party: fake_8818249905752995, fake_8478828116614672, fake_34257846849785145, fake_6148108685446871 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_15566838757429258, fake_248372665504901, fake_2578105707648759, fake_2276739678286377 result, different first party: fake_024674544460021597, fake_657845598237689, fake_4238833747306101, fake_7902086742343359 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_01157689849257948, fake_17507141672504933, fake_870492373052588, fake_46500193997681705 result, different first party: fake_4331991160286708, fake_6183537711157623, fake_001965687555180118, fake_11227382964023147 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_293746400228049, fake_49820412884909704, fake_3869932213878202 result, different first party: fake_6406324195408202, fake_893512910869088, fake_6160367322741356 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_7853931178962461, fake_1349615529499777, fake_162960318938568, fake_5671567566788296 result, different first party: fake_09244357034187867, fake_040824882545911434, fake_0472070958019859, fake_5470254036675835 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same first party: fake_7938253296532414, fake_4868902154775565, fake_9979804955331959, fake_24167815020017658 result, different first party: fake_1071783964227837, fake_8924124501710045, fake_25172770156772906, fake_218870372128102 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
favicon cache
A favicon is an icon that represents a website, typically shown in browser tab and bookmarks menu. If the favicon cache is not partitioned, it can be used to track users across websites. |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same first party: 2, 2, 2, 2 result, different first party: 3, 3, 3, 3 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
fetch cache
When a resource is received via the Fetch API, it is frequently cached. That cache can potentially be abused for cross-site tracking. |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
font cache
Web fonts are sometimes stored in their own cache, which is vulnerable to being abused for cross-site tracking. |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 2, 2, 2, 2 result, different first party: 3, 3, 3, 3 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
getDirectory
navigator.storage.getDirectory exposes a location for storing files to web content. In some cases, these files may be shared across tabs. |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: , , , result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: Error: Unsupported, Error: Unsupported, Error: Unsupported result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt", { create: true }); const stream = await fileHandle.createWritable(); await stream.write(secret); await stream.close(); } catch (e) { throw new Error("Unsupported"); } } read: async () => { try { const root = await navigator.storage.getDirectory(); const fileHandle = await root.getFileHandle("secret.txt"); const file = await fileHandle.getFile(); return file.text(); } catch (e) { throw new Error("Unsupported"); } } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
H1 connection
HTTP/1.x are the classic web connection protocols. If these connections are re-used across websites, they can be used to track users. |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, , 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, , b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, , 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, , 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, , e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h1.privacytests2.org:8901/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h1.privacytests2.org:8901/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, , 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
H2 connection
HTTP/2 is a web connection protocol introduced in 2015. Some browsers re-use HTTP/2 connections across websites and can thus be used to track users. |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, , 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, , b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, , 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, , 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, , e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
write: async (secret) => { await fetch(`https://h2.privacytests2.org:8902/?mode=write&secret=${secret}`, {cache: "no-store"}); } read: async () => { let response = await fetch(`https://h2.privacytests2.org:8902/?mode=read`, {cache: "no-store"}); return await response.text(); } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, , 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: , , , unsupported: false, false, false, false passed: true, true, true test failed: false, true, false, false |
H3 connection
HTTP/3 is a new standard HTTP connection protocol, still in draft but widely supported by browsers. If it is not partitioned, it can be used to track users across websites. |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: 1f4279f2f1714f3b20f9943d99bd73ca, 634f859416cb99cdbf3c0897df5ee2c7, eb414f4662fb0be538c8ce91fb61bd5c, b2c86533220b9922c7b66b4fba304b4c result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: 0f83c1c2c6c7afe2bae0a803697ecb3a, 5535da864a3f9805587f7be6ad4da7ed, e7ec2ee18a7a62e43fa105626041525c, 3b15f7d6e6f17c4b13cba04d3c90a7e6 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: f0f41e0ad7b79b918ac8acff329df378, 0b6567382f5eb911d59078814afcc369, 959418b57cfd4539eef3097a9f76fb35, bd0ca522a17ccc9ad20acc893a37dc5b result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: baca77ec31f8d8e02e06a350f342efc7, 5fd62dbcdf41aae7c49d1d46da362778, dfa99811e4a6557ca0c936afe90c5b82, 95a0a600dc5909f5dc7a64e47c3145a0 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: 94ac95b4927fa93f5cb2e9547fcb571d, e4fce439935ef38594dc8394b87e626b, 2476682232f944736c66c39fc461b9d7, dce03c89a455cc8f3cd667ecb90870d4 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: 3481a20e2d532fa8d38853602a2ffdd5, a54f86b1b5ce719fa539f4f546370b17, 122b6fae34f7ebb65460bd2d959bca3e, a43ff93a64f760c21f27e03c15f5ec7f result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: 573454fa30b85f15ebd4db6df5a05f2c, f5d23287d3b0c51facf99cfb820eb28b, 4e8951b997f11252790b3b410583e1e4, bc2f01d2dc7e82b2e8f9ec88559b9d02 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: , , , result, different first party: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: , , result, different first party: , , unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: a6a486db3b024483a915aabc113e13d2, 2272ff3f72fdbf3d0df34b0e47623349, 66ac1cb40d6c72326fcfad6a40e6647f, bab6c9910d35729bea84724857868fa0 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Ensure that we can switch over to h3 via alt-svc: for (let i = 0; i<3; ++i) { await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); await sleepMs(500); } // Are we now connecting over h3? let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`, {cache: "no-store"}); let text = await response.text(); // Empty response text indicates we are not connecting over h3: if (text.trim() === "") { throw new Error("Unsupported"); } } read: async () => { let response = await fetch(`https://h3.privacytests2.org:4434/connection_id`); return await response.text(); } result, same first party: a16f5e076f38e04f994a7761a692c181, 2d24b6db91871f6b9f1ed76eb74a47df, 92f260f46d66bb69f93c87f2eeef4c69, cdb2debdb55d10e47e30330f5473a59a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
HSTS cache
The HTTP Strict-Transport-Security response header allows a website to signal that it should only be accessed via HTTPS. The browser remembers this directive in a database, but if this database is not partitioned, then it can be used to track users across websites." |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Used http, Used http, Used http, Used http unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Used http, Used http, Used http, Used http unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: null read: null result, same first party: , , , result, different first party: HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected unsupported: , , , passed: true, true, true, true test failed: false, false, false, false |
write: null read: null result, same first party: , , , result, different first party: HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected unsupported: , , , passed: true, true, true, true test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Used http, Used http, Used http, Used http unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: null read: null result, same first party: , , result, different first party: HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected unsupported: , , passed: true, true, true test failed: false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
HSTS cache (fetch)
The HTTP Strict-Transport-Security response header allows a website to signal that it should only be accessed via HTTPS. The browser remembers this directive in a database, but if this database is not partitioned, then it can be used to track users across websites." |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Used http, Used http, Used http, Used http unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Used http, Used http, Used http, Used http unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: null read: null result, same first party: , , , result, different first party: HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected unsupported: , , , passed: true, true, true, true test failed: false, false, false, false |
write: null read: null result, same first party: , , , result, different first party: HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected unsupported: , , , passed: true, true, true, true test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Used http, Used http, Used http, Used http unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: null read: null result, same first party: , , result, different first party: HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected, HTTPS used by default; no HSTS cache issue expected unsupported: , , passed: true, true, true test failed: false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: set HSTS flag read: read HSTS flag result, same first party: not tested, not tested, not tested, not tested result, different first party: Upgraded to https, Upgraded to https, Upgraded to https, Upgraded to https unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
iframe cache
An iframe is an element in a web page than allows websites to embed a second web page. Caching of this web page could be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
image cache
Caching of images in web browsers is a standard behavior. But if that cache leaks between websites, it can be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 2, 2, 2, 2 result, different first party: 3, 3, 3, 3 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
indexedDB
The IndexedDB API exposes a transactional database to web pages. That database can be used to track users across websites, unless it is partitioned. |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: The user denied permission to access the database., Error: The user denied permission to access the database., Error: The user denied permission to access the database., Error: The user denied permission to access the database. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
localStorage
The localStorage API gives websites access to a key-value database that will remain available across visits. If the localStorage API is not partitioned or blocked, it can also be used to track users across websites. |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
locks
navigator.locks (only supported in some browsers) allows scripts on multiple tabs to coordinate. If this API is not partitioned, it can be used for cross-site tracking. |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: The request was denied., Error: The request was denied., Error: The request was denied., Error: The request was denied. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: Error: undefined is not an object (evaluating 'queryResult.held[0].name'), Error: undefined is not an object (evaluating 'queryResult.held[0].name'), Error: undefined is not an object (evaluating 'queryResult.held[0].name'), Error: undefined is not an object (evaluating 'queryResult.held[0].name') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context, Error: LockManager.query: query() is not allowed in this context unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (navigator.locks) { navigator.locks.request(key, lock => new Promise((f,r) => {})); let queryResult = await navigator.locks.query(); return queryResult.held[0].clientId; } else { throw new Error("Unsupported"); } } read: async () => { if (navigator.locks) { let queryResult = await navigator.locks.query(); return queryResult.held[0].name; } } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name'), Error: Cannot read properties of undefined (reading 'name') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
prefetch cache
A <link rel='prefetch'...> suggests to browsers they should fetch a resource ahead of time and cache it. But if browsers don't partition this cache, it can be used to track users across websites. |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different first party: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different first party: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different first party: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: Error: No requests received, Error: No requests received, Error: No requests received result, different first party: Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
script cache
Caching of scripts in web browsers is a standard behavior. But if that cache leaks between websites, it can be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 2, 2, 2, 2 result, different first party: 3, 3, 3, 3 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
ServiceWorker
The ServiceWorker API allows websites to run code in the background and store content in the browser for offline use. If a ServiceWorker can be accessed from multiple websites, it can be abused to track users across sites. |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> result, different first party: Error: Failed to register a ServiceWorker for scope ('https://test-pages.privacytests2.org/') with script ('https://test-pages.privacytests2.org/serviceWorker.js'): The user denied permission to use Service Worker., Error: Failed to register a ServiceWorker for scope ('https://test-pages.privacytests2.org/') with script ('https://test-pages.privacytests2.org/serviceWorker.js'): The user denied permission to use Service Worker., Error: Failed to register a ServiceWorker for scope ('https://test-pages.privacytests2.org/') with script ('https://test-pages.privacytests2.org/serviceWorker.js'): The user denied permission to use Service Worker., Error: Failed to register a ServiceWorker for scope ('https://test-pages.privacytests2.org/') with script ('https://test-pages.privacytests2.org/serviceWorker.js'): The user denied permission to use Service Worker. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: , , , result, different first party: , , , unsupported: false, false, false, false passed: undefined test failed: true, true, true, true |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: , , , result, different first party: , , , unsupported: false, false, false, false passed: undefined test failed: true, true, true, true |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined result, different first party: Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: , , , result, different first party: , , , unsupported: false, false, false, false passed: undefined test failed: true, true, true, true |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined result, different first party: Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined, Error: navigator.serviceWorker is undefined unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { if (!navigator.serviceWorker) { throw new Error("Unsupported"); } let registration = await navigator.serviceWorker.register( 'serviceWorker.js'); console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); await fetch(`serviceworker-write?secret=${key}`); } read: async () => { console.log("trying to register the serviceworker now..."); const registration = await Promise.race([ navigator.serviceWorker.register('serviceWorker.js'), sleepMs(500) ]); if (registration === undefined) { // We timed out or otherwise failed. throw new Error("ServiceWorker registration failed"); } console.log(registration); await navigator.serviceWorker.ready; console.log("service worker ready"); await sleepMs(100); let response = await fetch("serviceworker-read"); return await response.text(); } result, same first party: <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> , <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
SharedWorker
The SharedWorker API allows scripts from multiple tabs to share a background thread of computation. If SharedWorker is not partitioned, then it can be abused to shared data between websites in your browser. |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: Error: no SharedWorker message received, Error: no SharedWorker message received, Error: no SharedWorker message received, Error: no SharedWorker message received unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: Error: Unsupported, Error: no SharedWorker message received, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); // console.log("worker", worker); const messagePromise = new Promise((resolve) => { worker.port.onmessage = (e) => resolve(e.data); }); worker.port.postMessage(secret); await messagePromise; } catch (e) { throw new Error("Unsupported"); } } read: async () => { let worker = new SharedWorker("supercookies_sharedworker.js"); worker.port.start(); const messagePromise = new Promise((resolve, reject) => { worker.port.onmessage = (e) => resolve(e.data); setTimeout(() => reject(new Error("no SharedWorker message received")), 200); }); worker.port.postMessage("request"); const message = await messagePromise; if (message === "none") { throw new Error("Unsupported"); } return message; } result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
TLS Session ID
The TLS protocol is used by HTTPS to make connections secure. If the browser were to re-use a TLS session, then the session ID could be used to track users across websites. |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 5fa9e37a7f772d1c1d56f7802ac3d7dc8cad3788fcad36d2c9979eaab85e536d, 28131109d6a4047998e2be937dd7b6627a1fd5df9dde1a98ee02e88bf6de9b9d, 9d346b3900707dfa9865f08c102dfac75f276c656d49bd9ffc73e57b168eee5b, 2e470816136ea20cc82b8467a48e64ed0d6997281132180a1056a62d6ce1bd78 result, different first party: 2b7599b71ba1036d722800db70195392d73dbc0b81e3e5322a340d8b9461b923, b06ca5790c7ee6559f8aec33743b95a154d1a81856e70f2fb4b90e39959fd9ef, c2194957f4d3e355e06ecd7f522076ee3a3fe2335c61949f0543c8bb9abec86c, bc3ec0e6c47d40bb03b3612a84326a22e7b6c89c717fa9e4386433aaefbc55e4 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: e724a8958c80f4004b5be9b618b8ecacc51a99906efa6be93a87feba820b8493, de5a88a9784077926e61bb3418dcd82ec6e4689fcf33564e0657c175d23a5c0c, f8e9c50a7c2cf9c734c25645ca61affa892644e367063cee43bd75b5bb9680d1, 3b76ce0a7187a1ef06a9e9dc52d3c2520707f7d8d9ca5bda1c4be78b1b386ecf result, different first party: 359477f69a5c3dd7dace01ec69e8eff65b2ef26b21d6d9ff81f657205e92a755, ef966231467d2d7f8f378c4ecbb2b2157120e508bb440e4bb8f8fd113a532db9, 26d5569c36b95416a3e4efe6516ae126155d2ef59790f662b029256826610e2f, f3208cdba63d006b119841a56b1c2d70dcd9deea740c06c340c1d1f6923c0c5c unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 38e1016741c52bfa981c2ab4d375f805adaf6cec12ce039ce7700924c7d05f2f, 4c0c70e757d744d5d3bebf8ad6430180b336f549a287be40c87f317469128dfd, d0e0bf1e5c5fc7f2d509a4537834e717c051d59c7227e1db7f2daa458edfa712, b8e2c01b2622043e38934bad02570ea52ae993aa8980ec29baab79d3d8090914 result, different first party: 868d393395e379220662b7fd20589642c0e9c29501aca01fa7ba256abfe4378d, 4e1a017186d6db85bd92ad2a33fc385cf1db408b05d693c5e676bfa44d1cc54b, e5d883dce959849276527ec560e644d228018a6920bb05d3e77c8b694773d529, b9f6f6f1082dde5c63a7a3f4140c0321a7a7ca14186eb9071687b884fd4982de unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 3c656063b2f97cb5e9c053f2fe4a848de8b06ace8b0e39f89b92df0894e51ca7, 6907512d857c04ec812439af001d10f7eb572f602c5ea9ef3a581b5fc95421d8, bf81ea3fde13f86efd236d611e6001270628ff13bac056b5ac4ff89bf430af10, ed535c35f4fd67b3feaf6e34512fe4c79c71f7f089408497a6f72675060d2521 result, different first party: 73f5e70541a5e0975e6b9a1da34407c91267bd9b7a3caf5905ce4c0c0e6a0697, f6d83193c6724fb1a3d8d6ea0821a440460b8d4ad0b5f3abc4b9e35a12f87477, df384a6fe8c912bfb54d66c68ff060c96af83cb236abb4248d6d483819ad6cec, 85dbf19e96b6ef6ccd4b16db31c5d53a052224e63ef3f9a7ba37c7785214529e unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: c11cd54e524e5132382b05051f4896b4ba4080f2af481a91fb6ff7e5bbb88da7, e5b9a0a0f7ce574e0559c0da1b17aa73f7ad9b3018857132866a7039f0b299e1, 88a2990d89b9cb87de7cf6d953b1a923054cbdd985e4e974e44b523d06147bf5, d799e92de4e0287f8c6c1fa52e0c551a1389937ac6043c647d77c7345ca850d3 result, different first party: 8a4f7a4dd8aa2944cfb69c431c98e28171a8ace4edd26671e99a71f21963d8f9, 8d6b0eb569985d16a24dd2e5783fe28a860b685c0c30b833be0cd18ebdd5e0e2, 444a48671d51bd42da27ed9b0b5907467b859046a3ce96fac66ae9eff0e41acb, c88020e6badce7364065ae0ea54ac04c942db07c8626c1fab7e27f4dad29d19c unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: d3f9b214f40a8f78eac16be7a0da35d327eec21b7ddf099b48da69699ff1c0c3, 9a84a2e83e59feee7db570bb0d6f1554e4291124f16414dfaf54b0c700547a04, e6624265263ec65214e9b94164faca778b0d8c098abf2278cd6aaead15802eb1, 32afaf4787c7e31d83954809b5605891dd8b2e4eae655eccbb28e483adb1724d result, different first party: f5e6a7a281a01e3755dcb8bfd0a9617eb75f9f6483cebe4025cb7a3efc62c6bd, 99cd9a471ae6125566baf9b025373b3e865156f5663effc7e0489c09e86a6ea0, 93c33a7e02536c382bff2d8ca88e26f94185a7ac6ca663c53e0f192c87dbc4f5, 3119367736d1fad12e06b181c6e8f0019daaca36e88a0029d3ec27a8ad6882b2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 5ba92dc5137631e5ab6f4ac390121838d87e79352786d164d3d0855a250a0c8b, 65bee3071e154410d590d68eafe6e0685e14075b557342fe267ebf9c454d920a, f1e8c3781b198d2770dcd5e02452229370a9a3204e86543ade03e82341dc472e, 3dfbfe8a116c9932092f6138491d7e15d0b35b331458fa19ca5d09e98a1f7b83 result, different first party: 69bcf876ecdee71d85d661b558e12f83e46dfb49851838a64510739ecc69c734, db2e95124aba618559370082d7c748f1991687e4f2e73027a883a5f201b19ad7, d6fcee375232ab46354b90f3344157fad24f7d74faa97a9044727e07817f4d9f, 56e7538ce4ea5a45e7cc2050803cd704611b552e27ec27df51d7f7aa732b9331 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 8c78562b58c393e5e639a386216903e903978dffb463e6577835c8f058065329, c37a0479f84349af6be008d2dc3a2cdaabbe813aafadea333044d664018879e4, 721896560219c4cd6f58f8561f5b3c97b6a827212d731fa190e60358721f9566, a60901c0fa4bc16123a2c5d0fcd09f4c27f300487eb5d20b42d7710a425238a4 result, different first party: 1b6edbf708d3464448a4788646eef8cfb5f24f1a1edc0e04676efd04678f7355, 3fa063c380bf49ca19ee8eb48f430d6ec3841658974882680be9a436ce5eebe1, 390b5ec8f88069eb8d220792c11af54cfd904a7ec8b034ae2cc2a5a06f061e92, 7b0a6d3a91f2e813b2cfa02101dc8a113c518e95d9ef2ec3fb68044a976019b9 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: f16a2e972176714f867e6d375237bec824ead9aea19d601c3201a6fea27aec27, a43604c1edf41dd00b0a7801680dcad0e3ac2b0fb1ac680b22d5fa16956a3aec, d846c7f4a0088b8caf1250e1f6a762226aa09dccb1c877e8b446cf4478967659 result, different first party: fc359f58b5f22712b70146e9eeb281e0a99dd7b515749da4e607678d98cbab8a, 0b493425453dbe096771bcdb4df800839f4bbd6221924b1ed7d5c9ff247c998d, 3cabfbb6023e300bc31e60b2b1a8a2bb68d4beac82e7decee234b9e572e520c2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 5451fb7b70d26f53b7a0488bcf08770414a8487c02653828f4df94e1a42dc0a8, f6da900c9eabbc1f136c97e07fbf256d5c06208710cd508ea9fd53d261698cb8, 0b621eedf3c95fc21b4ddbc540a92ed6f4f132bdb38339266a99f212bc5331dd, a759e94277906530f4092e1e370f44c30ade57c63aeb7e65c976d5081fcbdf3a result, different first party: 59ed24bb0759d0a353ac1b9ab03d7c4c1c99236946a262ee6551d01cf4bfe9c9, 7dbca821d92d494c94eb10825f96792c0772c336d4b8b6920be48309495c2623, 3f95960eef03dbd1c941bcb843586fbe0f3b46bfc3d590299489148bc06ac80c, be9e11fee8a3cfbffa3b8b87f052a1cad01ab8dd34b0f024b6259a9d6e5534ad unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } read: async () => { let results = await fetch("https://tls.privacytests2.org:8900/"); return (await results.json()).sessionId; } result, same first party: 4849e7da4483c478623a5a74247be0c41b2bd10960f08b42297b1bdc29d507ab, fb461e4bc987b586479b6bed6ea03078c4996f5d354ca57a588dc7e1d2aca907, 5380cb41e277ebf31001270616945671470d44c3d3be6c0cb2ecb3cd69b34feb, 5b8038f65869952fd86c053d23a5daad688555d043fdf7c03f83e2211def9ed4 result, different first party: fba2ea824826a1207e28dc304a2b84a9b16415b3b8954c9b649b0a7bc820e939, 44ada8a6e434ba3d121acdf0ee6e8df10bd860cc395548fc79e881441a51c052, 4d3aab32b449f49ce79208d4c4fc10f7940117cd9d4e702d4aa92ee5d9217cea, df4cfa447f3969a5109817c931847fde786fe2309f7bfba93bcf788e688fead7 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
XMLHttpRequest cache
Similar to the newer Fetch API, any resource received may be cached by the browser. The cache is potentially vulnerable to cross-site tracking attack. |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1 result, different first party: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same first party: 1, 1, 1, 1 result, different first party: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
Navigation testsWhich browsers prevent websites from sharing tracking data when you click on a link?
When you click a hyperlink to navigate your browser from one site to another, certain browser APIs allow the first site to communicate to the second site. These privacy vulnerabilities can be fixed by introducing new limits on how much data is transfered between sites.', | |||||||||||
document.referrer
The Referer [sic] request header is a mechanism used by browsers to let a website know where the user is visiting from. This header is inherently tracking users across websites. In recent times, browsers have switched to a policy of trimming a referrer to convey less tracking information, but Referer continues to convey cross-site tracking data by default. |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false passed: false, false, false test failed: false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { /* do nothing */ } read: () => document.referrer result, same first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ result, different first party: https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/, https://test-pages.privacytests2.org/ unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
sessionStorage
The sessionStorage API is similar to the localStorage API, but it does not persist across tabs or across browser sessions. Nonetheless, it can be used to track users if they navigate from one website to another. This tracking can be thwarted by partitioning sessionStorage between websites. |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 2d48718a-b028-4710-bd73-9e0a292f72fb, 46c9d46f-e178-45f0-ae22-71738826c7c6, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 6be3e841-efd7-406b-afe2-0acce9cde6bb, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, b1ff8f81-4fda-4162-b2be-c5732c406a6d, 8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: af8ae3a9-80a9-49d2-af13-89e657489499, 11fa82e0-deea-4b47-af13-d5f16a3e3329, 58f380ad-8e76-437c-9a17-521fdd79be36, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, 2c63bf33-4e2b-4827-b61a-91bac9889546, 775a0d7d-da52-4123-ae11-eff48f4a8736, 68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 6f447164-0c9c-4013-b060-d77a48f2b1cb, c94b72db-c9df-48bf-b945-fba6367c1bb6, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, 9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0, d6845763-314c-4342-aac7-b6cdd1e6e6c0, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, 5a27df6f-2a5e-48f5-a0be-9430200adc42, 6f8771de-d02d-4d13-b826-14ae8e21b13a, 39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: f9fbccbd-9421-476e-91af-07ab091157df, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, 238c9375-7e5b-48c5-9475-345eb19cb1fb, dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, 66050919-0edd-4ff7-912a-afff0332b1d8, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 19163bc3-1fee-4f26-b999-855d1e356cdf, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => sessionStorage.setItem("secret", secret) read: () => sessionStorage.getItem("secret") result, same first party: 15e90e11-94e1-40c3-9427-5e17fdbecc75, 0e012f74-3469-4f07-ba88-551445db542b, 5dec35c7-2d29-4d63-8db1-67275c761c2c, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
window.name
The window.name API allows websites to store data that will persist after the user has navigated the tab to a different website. This mechanism could be partitioned so that data is not allowed to persist between websites. |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_2d48718a-b028-4710-bd73-9e0a292f72fb, name_46c9d46f-e178-45f0-ae22-71738826c7c6, name_7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9, name_a2df8ec1-fca5-41b3-b305-178b4c93306a result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_6be3e841-efd7-406b-afe2-0acce9cde6bb, name_9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, name_b1ff8f81-4fda-4162-b2be-c5732c406a6d, name_8d70f742-8fe2-4c59-985f-140ab800ef18 result, different first party: name_6be3e841-efd7-406b-afe2-0acce9cde6bb, name_9210e31a-706a-4ed5-a6d3-6e1ec98f63e7, name_b1ff8f81-4fda-4162-b2be-c5732c406a6d, name_8d70f742-8fe2-4c59-985f-140ab800ef18 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_af8ae3a9-80a9-49d2-af13-89e657489499, name_11fa82e0-deea-4b47-af13-d5f16a3e3329, name_58f380ad-8e76-437c-9a17-521fdd79be36, name_e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 result, different first party: name_af8ae3a9-80a9-49d2-af13-89e657489499, name_11fa82e0-deea-4b47-af13-d5f16a3e3329, name_58f380ad-8e76-437c-9a17-521fdd79be36, name_e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_9b6bf6ad-fa80-416f-b929-ff3f771cd7ec, name_2c63bf33-4e2b-4827-b61a-91bac9889546, name_775a0d7d-da52-4123-ae11-eff48f4a8736, name_68cecb34-9be8-402d-8ec7-a44e33d1d8df result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_6f447164-0c9c-4013-b060-d77a48f2b1cb, name_c94b72db-c9df-48bf-b945-fba6367c1bb6, name_37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7, name_9d01f87c-0a70-4252-8ee9-6e9b033efd52 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_c5618ee4-fb7b-4367-86a1-b5eaedbf2d30, name_218c6d6b-fb2c-47fd-930b-c9e7462c21e0, name_d6845763-314c-4342-aac7-b6cdd1e6e6c0, name_0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9 result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, name_5a27df6f-2a5e-48f5-a0be-9430200adc42, name_6f8771de-d02d-4d13-b826-14ae8e21b13a, name_39fbf8c7-535b-439c-a1f6-7de01be90e50 result, different first party: name_b610bc9a-6705-4a92-b3b3-24f20cdd0ab2, name_5a27df6f-2a5e-48f5-a0be-9430200adc42, name_6f8771de-d02d-4d13-b826-14ae8e21b13a, name_39fbf8c7-535b-439c-a1f6-7de01be90e50 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_f9fbccbd-9421-476e-91af-07ab091157df, name_2edd7663-4b0f-4ff2-a125-4dd4c767e2e6, name_238c9375-7e5b-48c5-9475-345eb19cb1fb, name_dfdc2a78-a4f1-48b5-9744-ab6d424621ec result, different first party: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8, name_66050919-0edd-4ff7-912a-afff0332b1d8, name_6e15cff0-391b-49fe-ab4b-ca21ebd8885d result, different first party: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_19163bc3-1fee-4f26-b999-855d1e356cdf, name_8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, name_e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, name_9d9fa49d-112f-4b8f-b837-fd2b98d8a097 result, different first party: name_19163bc3-1fee-4f26-b999-855d1e356cdf, name_8d21088b-6cb9-4635-b0e1-f51fbbe1af3c, name_e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831, name_9d9fa49d-112f-4b8f-b837-fd2b98d8a097 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => window.name = "name_" + secret read: () => window.name result, same first party: name_15e90e11-94e1-40c3-9427-5e17fdbecc75, name_0e012f74-3469-4f07-ba88-551445db542b, name_5dec35c7-2d29-4d63-8db1-67275c761c2c, name_41e5d7db-bb69-4704-a50d-a67f09d9bfeb result, different first party: name_15e90e11-94e1-40c3-9427-5e17fdbecc75, name_0e012f74-3469-4f07-ba88-551445db542b, name_5dec35c7-2d29-4d63-8db1-67275c761c2c, name_41e5d7db-bb69-4704-a50d-a67f09d9bfeb unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
HTTPS testsWhich browsers prevent unencrypted network connections?
HTTPS is the protocol that web browsers use to connect securely to websites. When HTTPS is being used, the connection is encrypted so that third parties on the network cannot read content being sent between the server and your browser. In the past, insecure connections were the default and websites would need to actively request that a browser use HTTPS. Now the status quo is shifting, and browser makers are moving toward a world where HTTPS is the default protocol.` | |||||||||||
Insecure website warning
Checks to see if the browser stops loading an insecure website and warns the user before giving them the option to continue. Known as HTTPS-Only Mode in some browsers. |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: true, true, true, true result: Insecure website never loaded, Insecure website never loaded, Insecure website never loaded, Insecure website never loaded |
passed: true, true, true, true result: Insecure website never loaded, Insecure website never loaded, Insecure website never loaded, Insecure website never loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: true, true, true result: Insecure website never loaded, Insecure website never loaded, Insecure website never loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
passed: false, false, false, false result: Insecure website loaded, Insecure website loaded, Insecure website loaded, Insecure website loaded |
Upgradable address
Checks to see if an insecure address entered into the browser's address bar is upgraded to HTTPS whenever possible. |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: false, false, false, false passed: false, false, false, false |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: false, false, false, false passed: false, false, false, false |
upgraded: true, true, true passed: true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
Upgradable hyperlink
Checks to see if the user has clicked on a hyperlink to an insecure address, if the browser upgrades that address to HTTPS whenever possible. |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: false, false, false, false passed: false, false, false, false |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: false, false, false, false passed: false, false, false, false |
upgraded: true, true, true passed: true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
upgraded: true, true, true, true passed: true, true, true, true |
Upgradable image
Checks to see if the browser attempts to upgrade an insecure address for an image to HTTPS whenever possible. |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: false, false, false, true result: loaded insecurely, loaded insecurely, loaded insecurely, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: false, false, false, false result: loaded insecurely, loaded insecurely, loaded insecurely, loaded insecurely |
passed: true, true, true result: upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
Upgradable script
Checks to see if the browser attempts to upgrade an insecure address for an script to HTTPS whenever possible. |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: upgraded, upgraded, upgraded, upgraded |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true result: upgraded, upgraded, upgraded |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
passed: true, true, true, true result: blocked, blocked, blocked, blocked |
Misc testsWhich browsers provide additional assorted privacy protections?
This category includes tests for the presence of miscellaneous privacy features | |||||||||||
ECH enabled
Encrypted Client Hello (ECH) is a new protocol that hides the website you are visiting from third-party network eavesdroppers. |
SNI_status: encrypted passed: true, true, true, true |
SNI_status: encrypted passed: true, true, true, true |
SNI_status: encrypted passed: true, true, true, true |
SNI_status: plaintext passed: false, false, false, false |
SNI_status: plaintext passed: false, false, false, false |
SNI_status: plaintext passed: false, false, false, false |
SNI_status: plaintext passed: false, true, true, true |
SNI_status: plaintext passed: false, false, false, false |
SNI_status: plaintext passed: false, false, false |
SNI_status: encrypted passed: true, true, true, true |
SNI_status: encrypted passed: true, true, true, true |
GPC enabled first-party
The Global Privacy Control is an HTTP header that can be sent by a browser to instruct a website not to sell the user's personal data to third parties. This test checks to see if the GPC header is sent by default to the top-level website. |
header value: 1 passed: true, true, true, true |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false |
header value: undefined passed: false, false, false, false |
header value: undefined passed: false, false, false, false |
GPC enabled third-party
The Global Privacy Control is an HTTP header that can be sent by a browser to instruct a visited website not to sell the user's personal data to other parties. This test checks to see if the GPC header is sent to third-party elements on the web page. |
sec-gpc: 1 passed: true, true, true, true |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
IP address leak
IP addresses can be used to uniquely identify a large percentage of users. A proxy, VPN, or Tor can mask a user's IP address. |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: false, false, false, false |
passed: true, true, true |
passed: false, false, false, false |
passed: false, false, false, false |
Stream isolation
Browsers that use Tor can use a different Tor circuit per top-level website. |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: false, false, false readSameFirstParty: 2001:67c:6ec:203:192:42:116:186, 2a0b:f4c2::9, 2.58.56.220 readDifferentFirstParty: 2001:67c:6ec:203:192:42:116:188, 2607:5300:60:9aff:ff:ff:625f:8de4, 2001:67c:6ec:203:192:42:116:184 passed: true, true, true testFailed: false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
write: () => { if (!usingTor) { throw new Error("Unsupported"); } } read: async () => { if (usingTor) { return ipAddress; } else { throw new Error("Unsupported"); } } unsupported: true, true, true, true readSameFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported readDifferentFirstParty: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported testFailed: false, false, false, false |
Tor enabled
The Tor network sends the browser's web requests through a series of relays to hide a user's IP address, thereby helping to mask their identity and location. This test checks to see if the Tor network is being used by default. |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: true, true, true passed: true, true, true |
IsTorExit: false, false, false, false passed: false, false, false, false |
IsTorExit: false, false, false, false passed: false, false, false, false |
Fingerprinting resistance testsWhich browsers hide what's unique about your device?
Fingerprinting is a technique trackers use to uniquely identify you as you browse the web. A fingerprinting script will measure several characteristics of your browser and, combining this data, will build a fingerprint that may uniquely identify you among web users. Browsers can introduce countermeasures, such as minimizing the distinguishing information disclosed by certain web APIs so your browser is harder to pick out from the crowd (so-called 'fingerprinting resistance').`, | |||||||||||
Media query screen height
Height of the user's screen in pixels. |
expression: undefined desired expression: undefined actual value: 1292,1291,1296,1296 desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 900,900,900,900 desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: 900,900,900,900 desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 900,900,900 desired value: undefined passed: true,true,true |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
Media query screen width
Width of the user's screen in pixels. |
expression: undefined desired expression: undefined actual value: 1200,1205,1207,1206 desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 1600,1600,1600,1600 desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: 1400,1400,1400,1400 desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 1400,1400,1400 desired value: undefined passed: true,true,true |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
outerHeight
Height of the browser window in pixels, including browser chrome. |
expression: outerHeight desired expression: undefined actual value: 1292,1291,1296,1296 desired value: undefined passed: true,true,true,true |
expression: outerHeight desired expression: undefined actual value: 1371,1371,1371,1371 desired value: undefined passed: false,false,false,false |
expression: outerHeight desired expression: undefined actual value: 1371,1371,1371,1371 desired value: undefined passed: false,false,false,false |
expression: outerHeight desired expression: undefined actual value: 1040,1040,1040,1040 desired value: undefined passed: false,false,false,false |
expression: outerHeight desired expression: undefined actual value: 900,900,900,900 desired value: undefined passed: true,true,true,true |
expression: outerHeight desired expression: undefined actual value: 900,900,900,900 desired value: undefined passed: true,true,true,true |
expression: outerHeight desired expression: undefined actual value: 0,1061,1061,1061 desired value: undefined passed: false,false,false,false |
expression: outerHeight desired expression: undefined actual value: 1335,1335,1335,1335 desired value: undefined passed: false,false,false,false |
expression: outerHeight desired expression: undefined actual value: 900,900,900 desired value: undefined passed: true,true,true |
expression: outerHeight desired expression: undefined actual value: 1371,1371,1371,1371 desired value: undefined passed: false,false,false,false |
expression: outerHeight desired expression: undefined actual value: 1371,1371,1371,1371 desired value: undefined passed: false,false,false,false |
screen.height
Height of the user's screen, in pixels. |
expression: screen.height desired expression: undefined actual value: 1292,1291,1296,1296 desired value: undefined passed: true,true,true,true |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: screen.height desired expression: undefined actual value: 900,900,900,900 desired value: undefined passed: true,true,true,true |
expression: screen.height desired expression: undefined actual value: 900,900,900,900 desired value: undefined passed: true,true,true,true |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: screen.height desired expression: undefined actual value: 900,900,900 desired value: undefined passed: true,true,true |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
expression: screen.height desired expression: undefined actual value: 1440,1440,1440,1440 desired value: undefined passed: false,false,false,false |
screen.width
Width of the user's screen, in pixels. |
expression: screen.width desired expression: undefined actual value: 1200,1205,1207,1206 desired value: undefined passed: true,true,true,true |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: screen.width desired expression: undefined actual value: 1600,1600,1600,1600 desired value: undefined passed: true,true,true,true |
expression: screen.width desired expression: undefined actual value: 1400,1400,1400,1400 desired value: undefined passed: true,true,true,true |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: screen.width desired expression: undefined actual value: 1400,1400,1400 desired value: undefined passed: true,true,true |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
expression: screen.width desired expression: undefined actual value: 2560,2560,2560,2560 desired value: undefined passed: false,false,false,false |
screenX
Position, in pixels, of the left edge of the browser window on screen. |
expression: screenX desired expression: undefined actual value: 1,7,0,4 desired value: undefined passed: true,true,true,true |
expression: screenX desired expression: undefined actual value: 22,22,22,22 desired value: undefined passed: false,false,false,false |
expression: screenX desired expression: undefined actual value: 22,22,22,22 desired value: undefined passed: false,false,false,false |
expression: screenX desired expression: undefined actual value: 4,4,4,4 desired value: undefined passed: true,true,true,true |
expression: screenX desired expression: undefined actual value: 0,0,0,0 desired value: undefined passed: true,true,true,true |
expression: screenX desired expression: undefined actual value: 0,0,0,0 desired value: undefined passed: true,true,true,true |
expression: screenX desired expression: undefined actual value: 0,320,320,320 desired value: undefined passed: true,false,false,false |
expression: screenX desired expression: undefined actual value: 1358,1358,1358,1358 desired value: undefined passed: false,false,false,false |
expression: screenX desired expression: undefined actual value: 0,0,0 desired value: undefined passed: true,true,true |
expression: screenX desired expression: undefined actual value: 22,22,22,22 desired value: undefined passed: false,false,false,false |
expression: screenX desired expression: undefined actual value: 22,22,22,22 desired value: undefined passed: false,false,false,false |
screenY
Position, in pixels, of the top edge of the browser window on screen. |
expression: screenY desired expression: undefined actual value: 0,3,3,0 desired value: undefined passed: true,true,true,true |
expression: screenY desired expression: undefined actual value: 47,47,47,47 desired value: undefined passed: false,false,false,false |
expression: screenY desired expression: undefined actual value: 47,47,47,47 desired value: undefined passed: false,false,false,false |
expression: screenY desired expression: undefined actual value: 25,25,25,25 desired value: undefined passed: false,false,false,false |
expression: screenY desired expression: undefined actual value: 0,0,0,0 desired value: undefined passed: true,true,true,true |
expression: screenY desired expression: undefined actual value: 0,0,0,0 desired value: undefined passed: true,true,true,true |
expression: screenY desired expression: undefined actual value: 0,202,202,202 desired value: undefined passed: true,false,false,false |
expression: screenY desired expression: undefined actual value: 54,54,54,54 desired value: undefined passed: false,false,false,false |
expression: screenY desired expression: undefined actual value: 0,0,0 desired value: undefined passed: true,true,true |
expression: screenY desired expression: undefined actual value: 47,47,47,47 desired value: undefined passed: false,false,false,false |
expression: screenY desired expression: undefined actual value: 47,47,47,47 desired value: undefined passed: false,false,false,false |
System font detection
Web pages can detect the presence of a font installed on the user's system. The presence or absence of various fonts is commonly used to fingerprint users. |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: true,true,true,true |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: true,true,true |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: false,false,false,false |
expression: undefined desired expression: undefined actual value: undefined desired value: undefined passed: false,false,false,false |
Tracking query parameter testsWhich browsers remove URL parameters that can track you?
When you browse from one web page to another, tracking companies will frequently attach a 'tracking query parameter' to the address of the second web page. That query parameter may contain a unique identifier that tracks you individually as you browse the web. And these query parameters are frequently synchronized with cookies, making them a powerful tracking vector. Web browsers can protect you from known tracking query parameters by stripping them from web addresses before your browser sends them. (The set of tracking query parameters tested here was largely borrowed from Brave.)` | |||||||||||
__hsfp
HubSpot tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
__hssc
HubSpot tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
__hstc
HubSpot tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
__s
Drip.com email address tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
_hsenc
HubSpot tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
_openstat
Yandex tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
dclid
DoubleClick Click ID (Google) |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
fbclid
Facebook Click Identifier |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
gclid
Google Click Identifier |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
hsCtaTracking
HubSpot tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
mc_eid
Mailchimp Email ID (email recipient's address) |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
mkt_tok
Adobe Marketo tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
ml_subscriber
MailerLite email tracking |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
ml_subscriber_hash
MailerLite email tracking |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
msclkid
Microsoft Click ID |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
oly_anon_id
Omeda marketing 'anonymous' customer id |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
oly_enc_id
Omeda marketing 'known' customer id |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
rb_clickid
Unknown high-entropy tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
s_cid
Adobe Site Catalyst tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
vero_conv
Vero tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
vero_id
Vero tracking parameter |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
wickedid
Wicked Reports e-commerce tracking |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
yclid
Yandex Click ID |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true, true |
passed: true, true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
passed: true, true, true |
value: 5456301701128969 passed: false, false, false, false |
value: 5456301701128969 passed: false, false, false, false |
Tracker content blocking testsWhich browsers block important known tracking scripts and pixels?
When you visit a web page, it frequently has third-party embedded tracking content, such as scripts and tracking pixels. These embedded components spy on you. Some browsers and browser extensions maintain list of tracking companies and block their content from being loaded. This section checks to see if a browser blocks 20 of the largest trackers listed by https://whotracks.me.` | |||||||||||
Adobe
Tests whether the browser blocks the page from loading the tracker at https://munchkin.marketo.net/munchkin.js |
url: https://munchkin.marketo.net/munchkin.js passed: true, true, true, true |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: true, true, true, true |
url: https://munchkin.marketo.net/munchkin.js passed: true, true, true, true |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
url: https://munchkin.marketo.net/munchkin.js passed: false, false, false, false |
Adobe Audience Manager
Tests whether the browser blocks the page from loading the tracker at https://dpm.demdex.net/ibs |
url: https://dpm.demdex.net/ibs passed: true, true, true, true |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
url: https://dpm.demdex.net/ibs passed: true, true, true, true |
url: https://dpm.demdex.net/ibs passed: true, true, true, true |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
url: https://dpm.demdex.net/ibs passed: false, false, false |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
url: https://dpm.demdex.net/ibs passed: false, false, false, false |
Amazon adsystem
Tests whether the browser blocks the page from loading the tracker at https://s.amazon-adsystem.com/dcm |
url: https://s.amazon-adsystem.com/dcm passed: true, true, true, true |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: true, true, true, true |
url: https://s.amazon-adsystem.com/dcm passed: true, true, true, true |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
url: https://s.amazon-adsystem.com/dcm passed: false, false, false, false |
AppNexus
Tests whether the browser blocks the page from loading the tracker at https://ib.adnxs.com/px?id=178248&t=1 |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: true, true, true, true |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: true, true, true, true |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: true, true, true, true |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
url: https://ib.adnxs.com/px?id=178248&t=1 passed: false, false, false, false |
Bing Ads
Tests whether the browser blocks the page from loading the tracker at https://bat.bing.com/bat.js |
url: https://bat.bing.com/bat.js passed: true, true, true, true |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
url: https://bat.bing.com/bat.js passed: true, true, true, true |
url: https://bat.bing.com/bat.js passed: true, true, true, true |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
url: https://bat.bing.com/bat.js passed: false, false, false |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
url: https://bat.bing.com/bat.js passed: false, false, false, false |
Chartbeat
Tests whether the browser blocks the page from loading the tracker at https://static.chartbeat.com/js/chartbeat.js |
url: https://static.chartbeat.com/js/chartbeat.js passed: true, true, true, true |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: true, true, true, true |
url: https://static.chartbeat.com/js/chartbeat.js passed: true, true, true, true |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
url: https://static.chartbeat.com/js/chartbeat.js passed: false, false, false, false |
Criteo
Tests whether the browser blocks the page from loading the tracker at https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: true, true, true, true |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: true, true, true, true |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: true, true, true, true |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx passed: false, false, false, false |
DoubleClick (Google)
Tests whether the browser blocks the page from loading the tracker at https://securepubads.g.doubleclick.net/static/glade.js |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: true, true, true, true |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: true, true, true, true |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: true, true, true, true |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
url: https://securepubads.g.doubleclick.net/static/glade.js passed: false, false, false, false |
Facebook tracking
Tests whether the browser blocks the page from loading the tracker at https://connect.facebook.net/en_US/fbevents.js |
url: https://connect.facebook.net/en_US/fbevents.js passed: true, true, true, true |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: true, true, true, true |
url: https://connect.facebook.net/en_US/fbevents.js passed: true, true, true, true |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
url: https://connect.facebook.net/en_US/fbevents.js passed: false, false, false, false |
Google (third-party ad pixel)
Tests whether the browser blocks the page from loading the tracker at https://www.google.com/pagead/1p-user-list/ |
url: https://www.google.com/pagead/1p-user-list/ passed: true, true, true, true |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: true, true, true, true |
url: https://www.google.com/pagead/1p-user-list/ passed: true, true, true, true |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
url: https://www.google.com/pagead/1p-user-list/ passed: false, false, false, false |
Google Analytics
Tests whether the browser blocks the page from loading the tracker at https://google-analytics.com/urchin.js |
url: https://google-analytics.com/urchin.js passed: true, true, true, true |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
url: https://google-analytics.com/urchin.js passed: true, true, true, true |
url: https://google-analytics.com/urchin.js passed: true, true, true, true |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
url: https://google-analytics.com/urchin.js passed: false, false, false |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
url: https://google-analytics.com/urchin.js passed: false, false, false, false |
Google Tag Manager
Tests whether the browser blocks the page from loading the tracker at https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: true, true, true, true |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: true, true, true, true |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: true, true, true, true |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL passed: false, false, false, false |
Index Exchange
Tests whether the browser blocks the page from loading the tracker at https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: true, true, true, true |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: true, true, true, true |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: true, true, true, true |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 passed: false, false, false, false |
New Relic
Tests whether the browser blocks the page from loading the tracker at https://js-agent.newrelic.com/nr-1212.min.js |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: true, true, true, true |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: true, true, true, true |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: true, true, true, true |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
url: https://js-agent.newrelic.com/nr-1212.min.js passed: false, false, false, false |
Quantcast
Tests whether the browser blocks the page from loading the tracker at https://pixel.quantserve.com/pixel |
url: https://pixel.quantserve.com/pixel passed: true, true, true, true |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
url: https://pixel.quantserve.com/pixel passed: true, true, true, true |
url: https://pixel.quantserve.com/pixel passed: true, true, true, true |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
url: https://pixel.quantserve.com/pixel passed: false, false, false |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
url: https://pixel.quantserve.com/pixel passed: false, false, false, false |
Scorecard Research Beacon
Tests whether the browser blocks the page from loading the tracker at https://sb.scorecardresearch.com/internal-c2/default/cs.js |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: true, true, true, true |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: true, true, true, true |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: true, true, true, true |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
url: https://sb.scorecardresearch.com/internal-c2/default/cs.js passed: false, false, false, false |
Taboola
Tests whether the browser blocks the page from loading the tracker at https://trc.taboola.com/futureplc-tomsguide/trc/3/json |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: true, true, true, true |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: true, true, true, true |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: true, true, true, true |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json passed: false, false, false, false |
Twitter pixel
Tests whether the browser blocks the page from loading the tracker at https://t.co/i/adsct |
url: https://t.co/i/adsct passed: true, true, true, true |
url: https://t.co/i/adsct passed: false, false, false, false |
url: https://t.co/i/adsct passed: false, false, false, false |
url: https://t.co/i/adsct passed: false, false, false, false |
url: https://t.co/i/adsct passed: true, true, true, true |
url: https://t.co/i/adsct passed: true, true, true, true |
url: https://t.co/i/adsct passed: false, false, false, false |
url: https://t.co/i/adsct passed: false, false, false, false |
url: https://t.co/i/adsct passed: false, false, false |
url: https://t.co/i/adsct passed: false, false, false, false |
url: https://t.co/i/adsct passed: false, false, false, false |
Yandex Ads
Tests whether the browser blocks the page from loading the tracker at https://yandex.ru/ads/system/header-bidding.js |
url: https://yandex.ru/ads/system/header-bidding.js passed: true, true, true, true |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: true, true, true, true |
url: https://yandex.ru/ads/system/header-bidding.js passed: true, true, true, true |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
url: https://yandex.ru/ads/system/header-bidding.js passed: false, false, false, false |
Tracking cookie protection testsWhich browsers block important known tracking cookies?
A large fraction of web pages on the web have hidden third-party trackers that read and write cookies in your browser. These cookies can be used to track your browsing across websites. This section checks to see if a browser stops cross-site tracking by cookies from 20 of the largest trackers listed by https://whotracks.me.`, | |||||||||||
Adobe
Tests whether the browser stops cookies from munchkin.marketo.net from tracking users across websites. |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://munchkin.marketo.net/munchkin.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://munchkin.marketo.net/munchkin.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false |
passed: true, true, true, true url: https://munchkin.marketo.net/munchkin.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://munchkin.marketo.net/munchkin.js cookieFound: true, true, true, true |
Adobe Audience Manager
Tests whether the browser stops cookies from dpm.demdex.net from tracking users across websites. |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dpm.demdex.net/ibs cookieFound: true, true, true, true |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dpm.demdex.net/ibs cookieFound: true, true, true, true |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false |
passed: true, true, true, true url: https://dpm.demdex.net/ibs cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dpm.demdex.net/ibs cookieFound: true, true, true, true |
Amazon adsystem
Tests whether the browser stops cookies from s.amazon-adsystem.com from tracking users across websites. |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: false, false, false, false url: https://s.amazon-adsystem.com/dcm cookieFound: true, true, true, true |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: false, false, false, false url: https://s.amazon-adsystem.com/dcm cookieFound: true, true, true, true |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false |
passed: true, true, true, true url: https://s.amazon-adsystem.com/dcm cookieFound: false, false, false, false |
passed: false, false, false, false url: https://s.amazon-adsystem.com/dcm cookieFound: true, true, true, true |
AppNexus
Tests whether the browser stops cookies from ib.adnxs.com from tracking users across websites. |
passed: true, true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false, false |
passed: false, false, false, false url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: true, true, true, true |
passed: false, false, true, false url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: true, true, false, true |
passed: true, true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false, false |
passed: true, true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false, false |
passed: true, true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false, false |
passed: false, false, false, false url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: true, true, true, true |
passed: true, true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false, false |
passed: true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false |
passed: true, true, true, true url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: false, false, false, false |
passed: false, false, false, false url: https://ib.adnxs.com/px?id=178248&t=1 cookieFound: true, true, true, true |
Bing Ads
Tests whether the browser stops cookies from bat.bing.com from tracking users across websites. |
passed: true, true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://bat.bing.com/bat.js cookieFound: true, true, true, true |
passed: false, false, true, false url: https://bat.bing.com/bat.js cookieFound: true, true, false, true |
passed: true, true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://bat.bing.com/bat.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false, false |
passed: true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false |
passed: true, true, true, true url: https://bat.bing.com/bat.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://bat.bing.com/bat.js cookieFound: true, true, true, true |
Chartbeat
Tests whether the browser stops cookies from static.chartbeat.com from tracking users across websites. |
passed: true, true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://static.chartbeat.com/js/chartbeat.js cookieFound: true, true, true, true |
passed: false, false, true, false url: https://static.chartbeat.com/js/chartbeat.js cookieFound: true, true, false, true |
passed: true, true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://static.chartbeat.com/js/chartbeat.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false, false |
passed: true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false |
passed: true, true, true, true url: https://static.chartbeat.com/js/chartbeat.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://static.chartbeat.com/js/chartbeat.js cookieFound: true, true, true, true |
Criteo
Tests whether the browser stops cookies from dis.criteo.com from tracking users across websites. |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: true, true, true, true |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: true, true, true, true |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false |
passed: true, true, true, true url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dis.criteo.com/dis/rtb/appnexus/cookiematch.aspx cookieFound: true, true, true, true |
DoubleClick (Google)
Tests whether the browser stops cookies from securepubads.g.doubleclick.net from tracking users across websites. |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false |
passed: true, true, true, true url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://securepubads.g.doubleclick.net/static/glade.js cookieFound: true, true, true, true |
Facebook tracking
Tests whether the browser stops cookies from connect.facebook.net from tracking users across websites. |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://connect.facebook.net/en_US/fbevents.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://connect.facebook.net/en_US/fbevents.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false |
passed: true, true, true, true url: https://connect.facebook.net/en_US/fbevents.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://connect.facebook.net/en_US/fbevents.js cookieFound: true, true, true, true |
Google (third-party ad pixel)
Tests whether the browser stops cookies from www.google.com from tracking users across websites. |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: false, false, false, false url: https://www.google.com/pagead/1p-user-list/ cookieFound: true, true, true, true |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: false, false, false, false url: https://www.google.com/pagead/1p-user-list/ cookieFound: true, true, true, true |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false |
passed: true, true, true, true url: https://www.google.com/pagead/1p-user-list/ cookieFound: false, false, false, false |
passed: false, false, false, false url: https://www.google.com/pagead/1p-user-list/ cookieFound: true, true, true, true |
Google Analytics
Tests whether the browser stops cookies from google-analytics.com from tracking users across websites. |
passed: true, true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://google-analytics.com/urchin.js cookieFound: true, true, true, true |
passed: false, false, true, false url: https://google-analytics.com/urchin.js cookieFound: true, true, false, true |
passed: true, true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://google-analytics.com/urchin.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false, false |
passed: true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false |
passed: true, true, true, true url: https://google-analytics.com/urchin.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://google-analytics.com/urchin.js cookieFound: true, true, true, true |
Google Tag Manager
Tests whether the browser stops cookies from www.googletagmanager.com from tracking users across websites. |
passed: true, true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false, false |
passed: false, false, false, false url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: true, true, true, true |
passed: false, false, true, false url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: true, true, false, true |
passed: true, true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false, false |
passed: true, true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false, false |
passed: true, true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false, false |
passed: false, false, false, false url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: true, true, true, true |
passed: true, true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false, false |
passed: true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false |
passed: true, true, true, true url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: false, false, false, false |
passed: false, false, false, false url: https://www.googletagmanager.com/gtag.js?id=GTM-NX4SMZL cookieFound: true, true, true, true |
Index Exchange
Tests whether the browser stops cookies from dsum-sec.casalemedia.com from tracking users across websites. |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: true, true, true, true |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: true, true, true, true |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false |
passed: true, true, true, true url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: false, false, false, false |
passed: false, false, false, false url: https://dsum-sec.casalemedia.com/crum?cm_dsp_id=10&external_user_id=629685505537&C=1 cookieFound: true, true, true, true |
New Relic
Tests whether the browser stops cookies from js-agent.newrelic.com from tracking users across websites. |
passed: true, true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: true, true, true, true |
passed: false, false, true, false url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: true, true, false, true |
passed: true, true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false, false |
passed: true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false |
passed: true, true, true, true url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://js-agent.newrelic.com/nr-1212.min.js cookieFound: true, true, true, true |
Quantcast
Tests whether the browser stops cookies from pixel.quantserve.com from tracking users across websites. |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, false, false, false url: https://pixel.quantserve.com/pixel cookieFound: false, true, true, true |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, false, false, false url: https://pixel.quantserve.com/pixel cookieFound: false, true, true, true |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false |
passed: true, true, true, true url: https://pixel.quantserve.com/pixel cookieFound: false, false, false, false |
passed: true, false, false, false url: https://pixel.quantserve.com/pixel cookieFound: false, true, true, true |
Scorecard Research Beacon
Tests whether the browser stops cookies from sb.scorecardresearch.com from tracking users across websites. |
passed: true, true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: true, true, true, true |
passed: false, false, true, false url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: true, true, false, true |
passed: true, true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false, false |
passed: true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false |
passed: true, true, true, true url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://sb.scorecardresearch.com/internal-c2/default/cs.js cookieFound: true, true, true, true |
Taboola
Tests whether the browser stops cookies from trc.taboola.com from tracking users across websites. |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: false, false, false, false url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: true, true, true, true |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: false, false, false, false url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: true, true, true, true |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false |
passed: true, true, true, true url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: false, false, false, false |
passed: false, false, false, false url: https://trc.taboola.com/futureplc-tomsguide/trc/3/json cookieFound: true, true, true, true |
Twitter pixel
Tests whether the browser stops cookies from t.co from tracking users across websites. |
passed: true, true, true, true url: https://t.co/i/adsct cookieFound: false, false, false, false |
passed: false, false, false, false url: https://t.co/i/adsct cookieFound: true, true, true, true |
passed: false, false, true, false url: https://t.co/i/adsct cookieFound: true, true, false, true |
passed: true, true, true, true url: https://t.co/i/adsct cookieFound: false, false, false, false |
passed: true, true, true, true url: https://t.co/i/adsct cookieFound: false, false, false, false |
passed: true, true, true, true url: https://t.co/i/adsct cookieFound: false, false, false, false |
passed: false, false, false, false url: https://t.co/i/adsct cookieFound: true, true, true, true |
passed: true, true, true, true url: https://t.co/i/adsct cookieFound: false, false, false, false |
passed: true, true, true url: https://t.co/i/adsct cookieFound: false, false, false |
passed: true, true, true, true url: https://t.co/i/adsct cookieFound: false, false, false, false |
passed: false, false, false, false url: https://t.co/i/adsct cookieFound: true, true, true, true |
Yandex Ads
Tests whether the browser stops cookies from yandex.ru from tracking users across websites. |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://yandex.ru/ads/system/header-bidding.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://yandex.ru/ads/system/header-bidding.js cookieFound: true, true, true, true |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false |
passed: true, true, true, true url: https://yandex.ru/ads/system/header-bidding.js cookieFound: false, false, false, false |
passed: false, false, false, false url: https://yandex.ru/ads/system/header-bidding.js cookieFound: true, true, true, true |
Cross-session first-party tracking testsWhich browsers prevent websites from tracking you across browser sessions?
A common vulnerability of web browsers is that they allow websites ("first parties") to 'tag' your browser with some tracking data. This tag can be used to re-identify you when you return to a website you visited before. This category of leaks can be prevented by browser if they clean or isolate data between browser sessions. (In cases where a user has logged into a website or entered detailed information, it may be justifiable for a browser to retain information across sessions. These tests check when no such justification exists: when you have entered no significant information into a website, will the browser still retain data that allows you to be tracked across sessions?) | |||||||||||
Alt-Svc
Alt-Svc allows the server to indicate to the web browser that a resource should be loaded on a different server. Because this is a persistent setting, it could be used to track users across websites if it is not correctly partitioned. |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h2, h2, h2, h2 result, different session: h2, h2, h2, h2 unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h2, h2, h2 result, different session: h2, h2, h2 unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
CacheStorage
The Cache API is a content storage mechanism originally introduced to support ServiceWorkers. If the same Cache object is accessible to multiple websites, it can be abused to track users. |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p result, different session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p result, different session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p result, different session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_1p, c94b72db-c9df-48bf-b945-fba6367c1bb6_1p, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_1p, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_1p result, different session: Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p result, different session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: f9fbccbd-9421-476e-91af-07ab091157df_1p, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_1p, 238c9375-7e5b-48c5-9475-345eb19cb1fb_1p, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_1p result, different session: Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p result, different session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p result, different session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
cookie (HTTP)
The cookie, first introduced by Netscape in 1994, is a small amount of data stored by your browser on a website's behalf. It has legitimate uses, but it is also the classic cross-site tracking mechanism, and today still the most popular method of tracking users across websites. Browsers can stop cookies from being used for cross-site tracking by either blocking or partitioning them. |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p_http, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p_http, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p_http, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p_http, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p_http, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p_http, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_1p_http, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p_http, 58f380ad-8e76-437c-9a17-521fdd79be36_1p_http, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p_http, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p_http, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p_http, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p_http result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p_http, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p_http, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p_http, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_1p_http, c94b72db-c9df-48bf-b945-fba6367c1bb6_1p_http, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_1p_http, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30_1p_http, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0_1p_http, d6845763-314c-4342-aac7-b6cdd1e6e6c0_1p_http, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p_http, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p_http, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p_http, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: f9fbccbd-9421-476e-91af-07ab091157df_1p_http, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_1p_http, 238c9375-7e5b-48c5-9475-345eb19cb1fb_1p_http, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_1p_http result, different session: f9fbccbd-9421-476e-91af-07ab091157df_1p_http, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_1p_http, 238c9375-7e5b-48c5-9475-345eb19cb1fb_1p_http, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_1p_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8_1p_http, 66050919-0edd-4ff7-912a-afff0332b1d8_1p_http, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d_1p_http result, different session: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p_http, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p_http, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p_http, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p_http, 0e012f74-3469-4f07-ba88-551445db542b_1p_http, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p_http, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
cookie (JS)
The cookie, first introduced by Netscape in 1994, is a small amount of data stored by your browser on a website's behalf. It has legitimate uses, but it is also the classic cross-site tracking mechanism, and today still the most popular method of tracking users across websites. Browsers can stop cookies from being used for cross-site tracking by either blocking or partitioning them. |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p_js, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p_js, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p_js, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p_js, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p_js, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p_js, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_1p_js, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p_js, 58f380ad-8e76-437c-9a17-521fdd79be36_1p_js, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p_js, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p_js, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p_js, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p_js result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p_js, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p_js, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p_js, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p_js unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_1p_js, c94b72db-c9df-48bf-b945-fba6367c1bb6_1p_js, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_1p_js, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30_1p_js, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0_1p_js, d6845763-314c-4342-aac7-b6cdd1e6e6c0_1p_js, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p_js, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p_js, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p_js, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: f9fbccbd-9421-476e-91af-07ab091157df_1p_js, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_1p_js, 238c9375-7e5b-48c5-9475-345eb19cb1fb_1p_js, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8_1p_js, 66050919-0edd-4ff7-912a-afff0332b1d8_1p_js, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d_1p_js result, different session: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p_js, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p_js, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p_js, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p_js, 0e012f74-3469-4f07-ba88-551445db542b_1p_js, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p_js, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
CookieStore
The Cookie Store API is an alternative asynchronous API for managing cookies, supported by some browsers. |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true passed: undefined test failed: false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
CSS cache
CSS stylesheets are cached, and if that cache is shared between websites, it can be used to track users across sites. |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_8535963529855635, fake_6995022513985478, fake_17213109716577146, fake_736494868755861 result, different session: fake_8535963529855635, fake_6995022513985478, fake_17213109716577146, fake_736494868755861 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_9476274652551087, fake_9523250860523271, fake_18532361159406774, fake_030170010874980502 result, different session: fake_9476274652551087, fake_9523250860523271, fake_18532361159406774, fake_030170010874980502 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_588242136618609, fake_5369343220911447, fake_19969335925636522, fake_6155114067244978 result, different session: fake_588242136618609, fake_5369343220911447, fake_19969335925636522, fake_6155114067244978 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_33591413290322913, fake_5057979407517414, fake_26391710467297225, fake_965234443898942 result, different session: fake_33591413290322913, fake_5057979407517414, fake_26391710467297225, fake_965234443898942 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_4925136218365411, fake_7042213450057508, fake_7377176142717141, fake_5231038256067408 result, different session: fake_18288286980814394, fake_2102901221382032, fake_7286508487706413, fake_2219027393925359 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_5557745039197217, fake_5805306368147714, fake_38066009354792585, fake_16920999514474366 result, different session: fake_02031316257932514, fake_5265575843352388, fake_17985744288277083, fake_24114154320280323 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_02699572089476665, fake_6471403698207332, fake_13325683188684678, fake_15879076593909858 result, different session: fake_02699572089476665, fake_6471403698207332, fake_13325683188684678, fake_15879076593909858 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_36641878774665493, fake_8384533666924541, fake_6171338935657567, fake_5398616677708434 result, different session: fake_36641878774665493, fake_8384533666924541, fake_6171338935657567, fake_5398616677708434 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_5872810807420019, fake_27284321150019375, fake_3514119151324473 result, different session: fake_8218606578867274, fake_08754707791859206, fake_3418764252137583 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_4426455913413767, fake_4226984371650422, fake_25958511870789747, fake_9967152957409684 result, different session: fake_4426455913413767, fake_4226984371650422, fake_25958511870789747, fake_9967152957409684 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_6586553897460721, fake_03542169954387764, fake_0012916341460238456, fake_32155128324086557 result, different session: fake_6586553897460721, fake_03542169954387764, fake_0012916341460238456, fake_32155128324086557 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
favicon cache
A favicon is an icon that represents a website, typically shown in browser tab and bookmarks menu. If the favicon cache is not partitioned, it can be used to track users across websites. |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 2, 1, 1 result, different session: 1, 2, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 2, 2, 2, 2 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
fetch cache
When a resource is received via the Fetch API, it is frequently cached. That cache can potentially be abused for cross-site tracking. |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
font cache
Web fonts are sometimes stored in their own cache, which is vulnerable to being abused for cross-site tracking. |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 2 result, different session: 1, 1, 1, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
iframe cache
An iframe is an element in a web page than allows websites to embed a second web page. Caching of this web page could be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 2 result, different session: 1, 1, 1, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
image cache
Caching of images in web browsers is a standard behavior. But if that cache leaks between websites, it can be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
indexedDB
The IndexedDB API exposes a transactional database to web pages. That database can be used to track users across websites, unless it is partitioned. |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p result, different session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p result, different session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p result, different session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_1p, c94b72db-c9df-48bf-b945-fba6367c1bb6_1p, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_1p, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_1p result, different session: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30_1p, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0_1p, d6845763-314c-4342-aac7-b6cdd1e6e6c0_1p, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9_1p result, different session: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p result, different session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: f9fbccbd-9421-476e-91af-07ab091157df_1p, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_1p, 238c9375-7e5b-48c5-9475-345eb19cb1fb_1p, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_1p result, different session: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8_1p, 66050919-0edd-4ff7-912a-afff0332b1d8_1p, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d_1p result, different session: undefined unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p result, different session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p result, different session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
localStorage
The localStorage API gives websites access to a key-value database that will remain available across visits. If the localStorage API is not partitioned or blocked, it can also be used to track users across websites. |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p result, different session: 2d48718a-b028-4710-bd73-9e0a292f72fb_1p, 46c9d46f-e178-45f0-ae22-71738826c7c6_1p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_1p, a2df8ec1-fca5-41b3-b305-178b4c93306a_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p result, different session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_1p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_1p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_1p, 8d70f742-8fe2-4c59-985f-140ab800ef18_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p result, different session: af8ae3a9-80a9-49d2-af13-89e657489499_1p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_1p, 58f380ad-8e76-437c-9a17-521fdd79be36_1p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_1p, 2c63bf33-4e2b-4827-b61a-91bac9889546_1p, 775a0d7d-da52-4123-ae11-eff48f4a8736_1p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_1p, c94b72db-c9df-48bf-b945-fba6367c1bb6_1p, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_1p, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: c5618ee4-fb7b-4367-86a1-b5eaedbf2d30_1p, 218c6d6b-fb2c-47fd-930b-c9e7462c21e0_1p, d6845763-314c-4342-aac7-b6cdd1e6e6c0_1p, 0c4b49d8-9185-4b0b-9ea3-3fe982e1dce9_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p result, different session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_1p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_1p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_1p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: f9fbccbd-9421-476e-91af-07ab091157df_1p, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_1p, 238c9375-7e5b-48c5-9475-345eb19cb1fb_1p, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_1p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 3d1902ec-f6d6-4bbb-ba43-9cf6ea855af8_1p, 66050919-0edd-4ff7-912a-afff0332b1d8_1p, 6e15cff0-391b-49fe-ab4b-ca21ebd8885d_1p result, different session: , , unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p result, different session: 19163bc3-1fee-4f26-b999-855d1e356cdf_1p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_1p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_1p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p result, different session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_1p, 0e012f74-3469-4f07-ba88-551445db542b_1p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_1p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_1p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
prefetch cache
A <link rel='prefetch'...> suggests to browsers they should fetch a resource ahead of time and cache it. But if browsers don't partition this cache, it can be used to track users across websites. |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 2 result, different session: 1, 1, 1, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
script cache
Caching of scripts in web browsers is a standard behavior. But if that cache leaks between websites, it can be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
XMLHttpRequest cache
Similar to the newer Fetch API, any resource received may be cached by the browser. The cache is potentially vulnerable to cross-site tracking attack. |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
Cross-session third-party tracking testsWhich browsers prevent third-party trackers from tracking you across browser sessions?
A common vulnerability of web browsers is that they allow third-party trackers to 'tag' your browser with some tracking data. This tag can be used to re-identify you when you return to a website you visited before. This category of leaks can be prevented by browser if they clean or isolate data between browser sessions. (In cases where a user has logged into a website or entered detailed information, it may be justifiable for a browser to retain information across sessions. These tests check when no such justification exists: when you have entered no significant information into a website, will the browser still retain data that allows you to be tracked across sessions?) | |||||||||||
Alt-Svc
Alt-Svc allows the server to indicate to the web browser that a resource should be loaded on a different server. Because this is a persistent setting, it could be used to track users across websites if it is not correctly partitioned. |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h2, h2, h2, h2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h2, h2, h2, h2 result, different session: h2, h2, h2, h2 unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h2, h2, h2 result, different session: h2, h2, h2 unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async () => { // Clear Alt-Svc caching first. let responseText = ""; for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/clear"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after clear:", responseText); // Store "h3" state in Alt-Svc cache for (let i = 0; i < 3; ++i) { await fetch(altSvcOrigin + "/set"); await sleepMs(100); } responseText = await fetchText(altSvcOrigin + "/protocol"); console.log("after set:", responseText); } read: async () => { const protocol = await fetchText(altSvcOrigin + "/protocol"); if ((new URL(location)).searchParams.get("thirdparty") === "same") { if (protocol !== "h3") { throw new Error("Unsupported"); } } return protocol; } result, same session: h3, h3, h3, h3 result, different session: h3, h3, h3, h3 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
CacheStorage
The Cache API is a content storage mechanism originally introduced to support ServiceWorkers. If the same Cache object is accessible to multiple websites, it can be abused to track users. |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent. result, different session: Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent., Error: Failed to execute 'open' on 'CacheStorage': An attempt was made to break through the security policy of the user agent. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p result, different session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p result, different session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_3p, c94b72db-c9df-48bf-b945-fba6367c1bb6_3p, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_3p, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_3p result, different session: Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined, Error: cacheKeys[0] is undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p result, different session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: f9fbccbd-9421-476e-91af-07ab091157df_3p, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_3p, 238c9375-7e5b-48c5-9475-345eb19cb1fb_3p, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_3p result, different session: Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url'), Error: undefined is not an object (evaluating 'cacheKeys[0].url') unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_3p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_3p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_3p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_3p result, different session: 19163bc3-1fee-4f26-b999-855d1e356cdf_3p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_3p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_3p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { try { let cache = await caches.open("supercookies"); cache.addAll([`test.css?key=${key}`]); } catch (e) { throw new Error("Unsupported"); } } read: async () => { let cache = await caches.open("supercookies"); let cacheKeys = await cache.keys(); let url = cacheKeys[0].url; return (new URL(url)).searchParams.get("key"); } result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p result, different session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
cookie (HTTP)
The cookie, first introduced by Netscape in 1994, is a small amount of data stored by your browser on a website's behalf. It has legitimate uses, but it is also the classic cross-site tracking mechanism, and today still the most popular method of tracking users across websites. Browsers can stop cookies from being used for cross-site tracking by either blocking or partitioning them. |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_3p_http, 46c9d46f-e178-45f0-ae22-71738826c7c6_3p_http, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_3p_http, a2df8ec1-fca5-41b3-b305-178b4c93306a_3p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p_http, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p_http, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p_http, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_3p_http, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p_http, 58f380ad-8e76-437c-9a17-521fdd79be36_3p_http, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p_http, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p_http, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p_http, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p_http result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p_http, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p_http, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p_http, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p_http unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_3p_http, c94b72db-c9df-48bf-b945-fba6367c1bb6_3p_http, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_3p_http, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_3p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p_http, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p_http, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p_http, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: , , result, different session: , , unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { // Request a page that will send an HTTPOnly 'set-cookie' response header with secret value. await fetch(`${baseURI}cookie?secret=${secret}_http`); } read: async () => { // Test if we now send a requests with a 'cookie' header containing the secret. let response = await fetch(`${baseURI}headers`); let cookie = (await response.json())["cookie"]; return cookie ? cookie.match(/secret=([\w-]+)/)[1]: null; } result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p_http, 0e012f74-3469-4f07-ba88-551445db542b_3p_http, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p_http, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p_http result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
cookie (JS)
The cookie, first introduced by Netscape in 1994, is a small amount of data stored by your browser on a website's behalf. It has legitimate uses, but it is also the classic cross-site tracking mechanism, and today still the most popular method of tracking users across websites. Browsers can stop cookies from being used for cross-site tracking by either blocking or partitioning them. |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_3p_js, 46c9d46f-e178-45f0-ae22-71738826c7c6_3p_js, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_3p_js, a2df8ec1-fca5-41b3-b305-178b4c93306a_3p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p_js, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p_js, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p_js, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_3p_js, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p_js, 58f380ad-8e76-437c-9a17-521fdd79be36_3p_js, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p_js, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p_js, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p_js, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p_js result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p_js, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p_js, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p_js, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p_js unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_3p_js, c94b72db-c9df-48bf-b945-fba6367c1bb6_3p_js, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_3p_js, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_3p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p_js, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p_js, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p_js, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: , , result, different session: , , unsupported: true, true, true passed: undefined test failed: false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (secret) => { document.cookie = `secret=${secret}_js; max-age=3600; SameSite=None; Secure`; } read: () => document.cookie ? document.cookie.match(/secret=([\w-]+)/)[1] : null result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p_js, 0e012f74-3469-4f07-ba88-551445db542b_3p_js, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p_js, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p_js result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
CookieStore
The Cookie Store API is an alternative asynchronous API for managing cookies, supported by some browsers. |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_3p, 46c9d46f-e178-45f0-ae22-71738826c7c6_3p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_3p, a2df8ec1-fca5-41b3-b305-178b4c93306a_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: Error: Unsupported, Error: Unsupported, Error: Unsupported result, different session: Error: Unsupported, Error: Unsupported, Error: Unsupported unsupported: true, true, true passed: undefined test failed: false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: , , , result, different session: , , , unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (data) => { const msPerHour = 60 * 60 * 1000; if (!window.cookieStore) { throw new Error("Unsupported"); } window.cookieStore.set({ name: "partition_test", value: data, expires: Date.now() + msPerHour, sameSite: "none" }); } read: async () => { if (!window.cookieStore) { throw new Error("Unsupported"); } const cookie = await window.cookieStore.get("partition_test"); if (!cookie) { return null; } return cookie.value; } result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
CSS cache
CSS stylesheets are cached, and if that cache is shared between websites, it can be used to track users across sites. |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_9909099371069492, fake_6663620539687971, fake_5567673840841112, fake_942887365594101 result, different session: fake_9909099371069492, fake_6663620539687971, fake_5567673840841112, fake_942887365594101 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_28492838270101584, fake_04327914461939386, fake_2596936556757521, fake_9807533483244979 result, different session: fake_28492838270101584, fake_04327914461939386, fake_2596936556757521, fake_9807533483244979 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_7289507694799331, fake_0029738853055081282, fake_30381340648947863, fake_9875905028879559 result, different session: fake_7289507694799331, fake_0029738853055081282, fake_30381340648947863, fake_9875905028879559 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_16639964918758166, fake_6562244501708727, fake_866805104075618, fake_027468226274133034 result, different session: fake_16639964918758166, fake_6562244501708727, fake_866805104075618, fake_027468226274133034 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_4967382260508608, fake_5159684610495165, fake_15889963160891885, fake_1169658182187634 result, different session: fake_12464464688595345, fake_019526513942557555, fake_9270446229291147, fake_7697772487450556 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_47719570337748474, fake_6850538046233274, fake_7513756900397364, fake_6063437484292686 result, different session: fake_7115617220041746, fake_7909494705471862, fake_0040964717787930205, fake_8967919967943159 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_8783536217794048, fake_7555706363742949, fake_31435783290258446, fake_08540213548666942 result, different session: fake_8783536217794048, fake_7555706363742949, fake_31435783290258446, fake_08540213548666942 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_2563981515611402, fake_79895452662783, fake_009195160786232393, fake_7050750604154985 result, different session: fake_2563981515611402, fake_79895452662783, fake_009195160786232393, fake_7050750604154985 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_5207537854607289, fake_5978794505551639, fake_36899119456352913 result, different session: fake_9939212577396146, fake_3044864891751191, fake_3526305970138919 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_4613789162656361, fake_4481461687765873, fake_8479529304755826, fake_5189829693154937 result, different session: fake_4613789162656361, fake_4481461687765873, fake_8479529304755826, fake_5189829693154937 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return key; } read: async (key) => { const href = testURI("resource", "css", key); const head = document.getElementsByTagName("head")[0]; head.innerHTML += `<link type="text/css" rel="stylesheet" href="${href}">`; const testElement = document.querySelector("#css"); let fontFamily; while (true) { await sleepMs(100); fontFamily = getComputedStyle(testElement).fontFamily; if (fontFamily.startsWith("fake")) { break; } } console.log(fontFamily); return fontFamily; } result, same session: fake_706619470299918, fake_22864276168530662, fake_5468534243198249, fake_588356308866719 result, different session: fake_706619470299918, fake_22864276168530662, fake_5468534243198249, fake_588356308866719 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
favicon cache
A favicon is an icon that represents a website, typically shown in browser tab and bookmarks menu. If the favicon cache is not partitioned, it can be used to track users across websites. |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => key read: async (key) => { // Wait for the favicon to load (defined in supercookies.html) await sleepMs(2000); let response = await fetch( testURI("ctr", "favicon", key), {"cache": "reload"}); let count = (await response.text()).trim(); if (count === "0") { throw new Error("No requests received"); } return count; } result, same session: 2, 2, 2, 2 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
fetch cache
When a resource is received via the Fetch API, it is frequently cached. That cache can potentially be abused for cross-site tracking. |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); return key; } read: async (key) => { let response = await fetch(testURI("resource", "fetch", key), {cache: "force-cache"}); let countResponse = await fetch(testURI("ctr", "fetch", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
font cache
Web fonts are sometimes stored in their own cache, which is vulnerable to being abused for cross-site tracking. |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 2 result, different session: 1, 1, 1, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } body { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); return key; } read: async (key) => { const text = document.createElement("span"); text.id = "text"; text.innerText = "test"; document.body.appendChild(text); const originalWidth = text.getBoundingClientRect().width; let style = document.createElement("style"); style.type='text/css'; let fontURI = testURI("resource", "font", key); style.innerHTML = `@font-face {font-family: "myFont"; src: url("${fontURI}"); } #text { font-family: "myFont" }`; document.getElementsByTagName("head")[0].appendChild(style); let newWidth; do { await sleepMs(100); newWidth = text.getBoundingClientRect().width; } while (newWidth < 0 || newWidth === originalWidth) let response = await fetch( testURI("ctr", "font", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
iframe cache
An iframe is an element in a web page than allows websites to embed a second web page. Caching of this web page could be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); iframe.addEventListener("load", () => resolve(key), {once: true}); iframe.src = testURI("resource", "page", key); }) read: async (key) => { let iframe = document.createElement("iframe"); document.body.appendChild(iframe); let iframeLoadPromise = new Promise((resolve, reject) => { iframe.addEventListener("load", resolve, {once: true}); }); let address = testURI("resource", "page", key); iframe.src = address; await iframeLoadPromise; let response = await fetch( testURI("ctr", "page", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
image cache
Caching of images in web browsers is a standard behavior. But if that cache leaks between websites, it can be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 2 result, different session: 1, 1, 1, 2 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let img = document.createElement("img"); document.body.appendChild(img); img.addEventListener("load", () => resolve(key), {once: true}); img.src = testURI("resource", "image", key); }) read: async (key) => { let img = document.createElement("img"); document.body.appendChild(img); let imgLoadPromise = new Promise((resolve, reject) => { img.addEventListener("load", resolve, {once: true}); }); img.src = testURI("resource", "image", key); await imgLoadPromise; let response = await fetch( testURI("ctr", "image", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
indexedDB
The IndexedDB API exposes a transactional database to web pages. That database can be used to track users across websites, unless it is partitioned. |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: Error: The user denied permission to access the database., Error: The user denied permission to access the database., Error: The user denied permission to access the database., Error: The user denied permission to access the database. result, different session: Error: The user denied permission to access the database., Error: The user denied permission to access the database., Error: The user denied permission to access the database., Error: The user denied permission to access the database. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p result, different session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p result, different session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_3p, c94b72db-c9df-48bf-b945-fba6367c1bb6_3p, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_3p, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_3p result, different session: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p result, different session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: f9fbccbd-9421-476e-91af-07ab091157df_3p, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_3p, 238c9375-7e5b-48c5-9475-345eb19cb1fb_3p, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_3p result, different session: undefined unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_3p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_3p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_3p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_3p result, different session: 19163bc3-1fee-4f26-b999-855d1e356cdf_3p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_3p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_3p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (secret) => { try { return await IdbKeyVal.set("secret", secret); } catch (e) { throw new Error("Unsupported"); } } read: () => IdbKeyVal.get("secret") result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p result, different session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
localStorage
The localStorage API gives websites access to a key-value database that will remain available across visits. If the localStorage API is not partitioned or blocked, it can also be used to track users across websites. |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 2d48718a-b028-4710-bd73-9e0a292f72fb_3p, 46c9d46f-e178-45f0-ae22-71738826c7c6_3p, 7d5f6cd3-7d4b-4ac6-a583-58c8e1b5c6e9_3p, a2df8ec1-fca5-41b3-b305-178b4c93306a_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p result, different session: 6be3e841-efd7-406b-afe2-0acce9cde6bb_3p, 9210e31a-706a-4ed5-a6d3-6e1ec98f63e7_3p, b1ff8f81-4fda-4162-b2be-c5732c406a6d_3p, 8d70f742-8fe2-4c59-985f-140ab800ef18_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p result, different session: af8ae3a9-80a9-49d2-af13-89e657489499_3p, 11fa82e0-deea-4b47-af13-d5f16a3e3329_3p, 58f380ad-8e76-437c-9a17-521fdd79be36_3p, e9c42836-5c50-4904-a2ea-1e3bb3ca1ae9_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p result, different session: 9b6bf6ad-fa80-416f-b929-ff3f771cd7ec_3p, 2c63bf33-4e2b-4827-b61a-91bac9889546_3p, 775a0d7d-da52-4123-ae11-eff48f4a8736_3p, 68cecb34-9be8-402d-8ec7-a44e33d1d8df_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 6f447164-0c9c-4013-b060-d77a48f2b1cb_3p, c94b72db-c9df-48bf-b945-fba6367c1bb6_3p, 37f7c7c7-d24b-4e20-bd02-9e312fbbe4a7_3p, 9d01f87c-0a70-4252-8ee9-6e9b033efd52_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p result, different session: b610bc9a-6705-4a92-b3b3-24f20cdd0ab2_3p, 5a27df6f-2a5e-48f5-a0be-9430200adc42_3p, 6f8771de-d02d-4d13-b826-14ae8e21b13a_3p, 39fbf8c7-535b-439c-a1f6-7de01be90e50_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: f9fbccbd-9421-476e-91af-07ab091157df_3p, 2edd7663-4b0f-4ff2-a125-4dd4c767e2e6_3p, 238c9375-7e5b-48c5-9475-345eb19cb1fb_3p, dfdc2a78-a4f1-48b5-9744-ab6d424621ec_3p result, different session: , , , unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. result, different session: Error: The operation is insecure., Error: The operation is insecure., Error: The operation is insecure. unsupported: true, true, true passed: undefined test failed: false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 19163bc3-1fee-4f26-b999-855d1e356cdf_3p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_3p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_3p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_3p result, different session: 19163bc3-1fee-4f26-b999-855d1e356cdf_3p, 8d21088b-6cb9-4635-b0e1-f51fbbe1af3c_3p, e48f64b4-e7f7-48ff-8bd3-c2d2ec36b831_3p, 9d9fa49d-112f-4b8f-b837-fd2b98d8a097_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (secret) => localStorage.setItem("secret", secret) read: () => localStorage.getItem("secret") result, same session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p result, different session: 15e90e11-94e1-40c3-9427-5e17fdbecc75_3p, 0e012f74-3469-4f07-ba88-551445db542b_3p, 5dec35c7-2d29-4d63-8db1-67275c761c2c_3p, 41e5d7db-bb69-4704-a50d-a67f09d9bfeb_3p unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
prefetch cache
A <link rel='prefetch'...> suggests to browsers they should fetch a resource ahead of time and cache it. But if browsers don't partition this cache, it can be used to track users across websites. |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true, true passed: undefined test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: Error: No requests received, Error: No requests received, Error: No requests received result, different session: Error: No requests received, Error: No requests received, Error: No requests received unsupported: true, true, true passed: undefined test failed: false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); return key; } read: async (key) => { let link = document.createElement("link"); link.rel = "prefetch"; link.href = testURI("resource", "prefetch", key); document.getElementsByTagName("head")[0].appendChild(link); await sleepMs(500); let response = await fetch( testURI("ctr", "prefetch", key), {"cache": "reload"}); let countString = (await response.text()).trim(); if (parseInt(countString) === 0) { throw new Error("No requests received"); } return countString; } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
script cache
Caching of scripts in web browsers is a standard behavior. But if that cache leaks between websites, it can be abused for cross-site tracking. |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: (key) => new Promise((resolve, reject) => { let script = document.createElement("script"); document.body.appendChild(script); script.addEventListener("load", () => resolve(key), {once: true}); script.src = testURI("resource", "script", key); }) read: async (key) => { let script = document.createElement("script"); document.body.appendChild(script); let scriptLoadPromise = new Promise((resolve, reject) => { script.addEventListener("load", resolve, {once: true}); }); script.src = testURI("resource", "script", key); await scriptLoadPromise; let response = await fetch( testURI("ctr", "script", key), {"cache": "reload"}); return (await response.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
XMLHttpRequest cache
Similar to the newer Fetch API, any resource received may be cached by the browser. The cache is potentially vulnerable to cross-site tracking attack. |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 2, 2, 2, 2 unsupported: false, false, false, false passed: true, true, true, true test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1 result, different session: 2, 2, 2 unsupported: false, false, false passed: true, true, true test failed: false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
write: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; return key; } read: async (key) => { const req = new XMLHttpRequest(); const loadPromise = new Promise(resolve => req.addEventListener("load", resolve)); req.open("GET", testURI("resource", "xhr", key)); req.send(); await loadPromise; let countResponse = await fetch(testURI("ctr", "xhr", key), {cache: "reload"}); return (await countResponse.text()).trim(); } result, same session: 1, 1, 1, 1 result, different session: 1, 1, 1, 1 unsupported: false, false, false, false passed: false, false, false, false test failed: false, false, false, false |
DNS privacy testsWhich browsers keep their DNS queries encrypted?
The Domain Name System (DNS) is the method by which web browsers look up the IP address for each website you visit. In a DNS query, a web browser will ask a DNS resolver (somewhere on the internet) for the IP address corresponding to a domain name (such as nytimes.com) for a website you want to visit. Traditionally, most web browsers have sent their DNS queries unencrypted, which means your ISP or anyone else on the network between your computer and the DNS resolver can eavesdrop on the websites you visit. In recent years, web browsers and operating systems have begun to introduce encrypted DNS, including the DNS over HTTPS (DoH) protocol, to encrypt the DNS request from your browser and the response from the resolver to keep your browsing history from leaking. These tests check whether a browser is still protecting its DNS requests by sending them encrypted. | |||||||||||
Location: Brazil
Checks whether the browser decides to use encrypted DNS if the computer is located in Brazil. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
Location: China
Checks whether the browser decides to use encrypted DNS if the computer is located in China. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
Location: Germany
Checks whether the browser decides to use encrypted DNS if the computer is located in Germany. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
Location: India
Checks whether the browser decides to use encrypted DNS if the computer is located in India. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
Location: Nigeria
Checks whether the browser decides to use encrypted DNS if the computer is located in Nigeria. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
Location: Russia
Checks whether the browser decides to use encrypted DNS if the computer is located in Russia. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
Location: United States
Checks whether the browser decides to use encrypted DNS if the computer is located in United States. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
OS DNS: Cloudflare
Checks whether the browser decides to use encrypted DNS if the operating system's default DNS provider is Cloudflare. |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
OS DNS: Comodo
Checks whether the browser decides to use encrypted DNS if the operating system's default DNS provider is Comodo. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
OS DNS: Google
Checks whether the browser decides to use encrypted DNS if the operating system's default DNS provider is Google. |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
OS DNS: Quad9
Checks whether the browser decides to use encrypted DNS if the operating system's default DNS provider is Quad9. |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true, true leak detected: false, false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: true, true, true, true leak detected: false, false, false, false |
passed: true, true, true leak detected: false, false, false |
passed: false, false, false, false leak detected: true, true, true, true |
passed: false, false, false, false leak detected: true, true, true, true |