• iglou@programming.dev
    link
    fedilink
    arrow-up
    9
    ·
    13 hours ago

    The point is not that they know your IP, but that even your IP already gives away information. That’s why they start with the information, rather than the IP being the source.

    This is not intended to be for people who understand how this works.

    And as someone else said, probably vibe coded.

    • Zerush@lemmy.ml
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      3 hours ago

      The public IP is irrelevant, only shows the IP of the server used by your ISP, which can be at the other side of the country. It can maybe identify the ISP, but not the user, less if a dynamic changing IP is used. The public IP is always leaked if you don’t use a VPN or the TOR network.

      • iglou@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        44 minutes ago

        Absolutely not, the public IP a website sees is your home IP. The resolved location will be inaccurate by design, but the IP definitely identifies you at that time.

      • Ironfacebuster@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        2 hours ago

        Depending on your location it can actually be geolocated into your specific city block, I geolocated an online friend’s IP just for the hell of it (I already knew where they lived) and it spit back out the city block they lived in as well as a lot of other very identifiable information

        Also, if you can ping devices on that network using that IP you can also use that as a way to easily identify users. That’s if they have anything that isn’t firewalled, obviously, but the point stands!

    • Bane_Killgrind@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      I understand how all of it works. Whether it’s vibe coded or not it, it showed me stuff that I didn’t think about like arbitrary web pages can know my phone tilt, battery level??

      The opsec implications are severe.

      • iglou@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        4 hours ago

        Oh yeah, it’s insane. The only way to truly protect your identity on the internet is by not using the internet. Second best would be tor, I suppose

        • Bane_Killgrind@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          Well maybe fingerprint duplication, some secure proxy provides a profile to follow/ plugin to install and all their customers look identical. Still gets your traffic pegged as a customer of that service.