Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On Lowes.com? Retest in a clean profile. Seems that once they trust you you are ok for a while, at least from a friend's test, who was able to reproduce in a clean profile. But maybe it is IP linked and takes a little bit to accumulate. Did you just enable privacy.resistFingerprinting recently?

Also. Doublecheck that it is enabled. Also, I'm using Nightly firefox. It may be the resist fingerprinting is more robust there.

BTW, this isn't using a VPN or anything that might seem suspicious. Just my bog standard US broadband.



>On Lowes.com? Retest in a clean profile.

I tested on a fresh container so for all intents and purposes it's a "clean profile".

> Did you just enable privacy.resistFingerprinting recently?

No, but it shouldn't matter given that I was using a fresh container and VPN.

>Also. Doublecheck that it is enabled. Also, I'm using Nightly firefox. It may be the resist fingerprinting is more robust there.

It's definitely enabled. I'm not using nightly though.


Sorry to belabour this, but by "it" you mean the setting in about:config called privacy.resistFingerprinting right?

Some people confuse it with the general enhanced tracking protection in Settings menu.

If so, welp, no idea (aside from the Nightly thing). It consistently breaks for me and others though. Guess you're just lucky.


> Sorry to belabour this, but by "it" you mean the setting in about:config called privacy.resistFingerprinting right?

yes, it's definitely the about:config option.

>If so, welp, no idea (aside from the Nightly thing). It consistently breaks for me and others though. Guess you're just lucky.

Just for fun I tried with various VPN servers across two different providers and got

5 / 5 working on provider A

6 / 6 working on provider B

One possibility is that they fingerprinted me and determined that my fingerprint was "good" (despite having RFP enabled) and therefore all the subsequent attempts were whitelisted. The other possibility is that RFP spoofs the user-agent to be the latest ESR version, and this causes issues when you're using nightly because it might have different fingerprinting characteristics (eg. TLS fingerprint) compared to the actual ESR release. An anti-bot system might flag that inconsistency as suspicious and therefore ban you based on that.


FWIW, I just replicated the exact same behaviour in Stable in a brand new profile (plus resistFingerprinting enabled). So, maybe it's something special about VPN IPs :) (I thought the Nightly theory was a bit of a long shot since I was pretty sure my friend tested in Stable)

Perhaps they whitelist generic profiles coming from VPN services.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: