In modern days, most of the tech websites were collecting your information using via browser. Most of the websites accessing lot of personal/device/network information without enduser permission.
What browser can access from enduser endpoint:
- Location
- Software (OS / Browser version / Browser Plugins)
- Hardware (CPU info / GPU / Battery percentage )
- Network Connection ( Public IP / Download Speed )
- Social Media (Currently logged in Social media websites information )
- Click jacking
- Auto-fill Browser data (Phishing )
- Gyroscope
- Network scan (WiFi/LAN scan from browser itself )
- Images ( Metadata reveals )
Demo Website
https://webkay.robinlinus.com/
Enduser Best Practices
Most of the websites were executing Java scripts to extract & data collection from end user browser.To block those scripts running in background, we have to install below items: 1. NoScript Chrome browser Add-on 2. NoScript Mozilla browser Add-on 3. Enable Private Browsing in enduser's browser. 4. Use Web-proxy to hide your real IP identity.