Brave vulnerable to evercookie tracking

I tested on this website Samy Kamkar - evercookie - virtually irrevocable persistent cookies generating an evercookie. I have all settings recommended by Privacy Guides. At first, didn’t work, so great.

However, this is artificial. Blocking lists seem to block any evercookie.js script, but in reality the real data brokers and other will obfuscate it. So I disable strict ad blocking, and it now can generate a cookie (id from 1 to 1000).

I close the browser, and open it again. The same number that was previously displayed appears.

On Firefox, it doesn’t seem to work, when I open again it just says undefined.

To protect yourself, go to Settings > Privacy & Security > Delete browsing data > On exit > select Cookies and other sites data
(this isn’t currently recommended by Privacy Guides)

Anyone can confirm this ?

2 Likes

I tested it with “Allow all trackers & ads” and restarted Brave and it says Cookie found: uid = undefined

Did you get an evercookie number in the first place ?

Yes, I tested it 2 times and got a number each time, but it was undefined after both restarts.

weird, do you have the delete browsing data settings enabled ?

I have brave://settings/content/siteData set to Delete data sites have saved to your device when you close all windows

If you disable ? I say this because most people haven’t enable this cause not recommended by PG

Doesn’t Forget me when I close this site achieve the same thing that is recommended by PG?

1 Like

No it deletes when you close the tab, but doesn’t seem to be as robust as what you activated.

A brave moderator said the opposite on a Reddit thread. I’m not sure how accurate it is, though.

edit: found some more information here

So I agree with the mod. The flag you shared earlier refers to deleting data on windows close, as inidcated by the text.

BTW, yeah it’s not a duplicate at all, one is from Chromium while the other is brough the Shields.