
Personally, I don’t care if a site can fingerprint me. As long as they can’t tie that fingerprint to a rich data set.
So I make sure that each domain gets a different fingerprint response. That means that a site can validate that I’m still the same user, but any XSS attempting fingerprint based data exchange just gets garbage.


You forgot to follow it up with “copilot: open windows” then.