finds.dev← search

// the find

jonasstrehle/supercookie

★ 7,386 · HTML · MIT · updated Nov 2025

⚠️ Browser fingerprinting via favicon!

A proof-of-concept web tracking technique that exploits the browser's favicon cache (F-Cache) as a side channel: by encoding a unique ID as a pattern of cached/uncached subpaths and timing which favicon requests fire, it builds a persistent client fingerprint that survives cookie clears, private/incognito mode, and VPNs. It's aimed at security researchers, privacy advocates, and anyone curious about browser fingerprinting attack surfaces, not something you'd deploy.

The core idea is genuinely clever and well-explained — it turns a caching optimization into a stateful identifier using nothing but redirect timing, and the repo backs the claim with a live demo plus a real cross-browser/cross-OS compatibility matrix rather than just asserting it works. The Node/TypeScript server is small enough to read end-to-end in one sitting, and docker-compose gets the demo running with almost no setup.

The browser version testing (Chrome 111, Firefox 86, Edge 87) is from around 2021 — despite a recent push date, there's no indication the fingerprinting behavior has been re-verified against current browser favicon caching internals, so you can't trust the compatibility table as current. There are no tests or CI at all, which is defensible for a PoC but means any fork or extension is on you to validate. It's explicitly a two-day student project by the author's own admission, so don't expect production concerns like rate limiting or hardened error handling — treat it strictly as a reference implementation of the technique, not a base to build on.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →