Mobile hotspot + Windows new user accounts

nethead01

Power Member
Joined
Sep 21, 2009
Messages
556
Reaction score
337
I've been researching for days on how to keep all my GMB accounts seperate and creating new gmails..

this is the method I am going to try and use mobile hotspot + windows user profile accounts.. will this work? I only plan on doing like 50 accounts
 
You've solved one part with the 4G hotspot, but changing user account won't change your device fingerprint.

You'll need a tool like Multilogin for that part after you take it past ~3 or so.
 
You've solved one part with the 4G hotspot, but changing user account won't change your device fingerprint.

You'll need a tool like Multilogin for that part after you take it past ~3 or so.
thanks for the advice, i have checked multilogin and it look like a great product but for starting out the price is a bit steep for me.. still might consider it if its the only option
 
thanks for the advice, i have checked multilogin and it look like a great product but for starting out the price is a bit steep for me.. still might consider it if its the only option

This one can be detected more easily, but it's free and will probably suffice for what you are doing (given your use case doesn't seem likely to trigger many other red flags - ie spamming Facebook etc): https://incogniton.com/pricing/
 
thanks for the advice, i have checked multilogin and it look like a great product but for starting out the price is a bit steep for me.. still might consider it if its the only option

Bro just use firefox profiles block webrtc and change user agent, you will be okay you dont need to spoof it harder!
 
Google Chrome Portable - https://portableapps.com/apps/internet/google_chrome_portable
and install these add-ons:
For Proxy Management:
https://chrome.google.com/webstore/detail/foxyproxy-standard/gcknhkkoolaabfmlnjonogaaifnjlfnp?hl=en
UBLOCK - block unwanted trackers (Check the Prevent WebRTC in settings)
https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm?hl=en
Prevent Fingerprint Canvass (Choose Disable Non-Proxied UDP (force proxy)
https://chrome.google.com/webstore/detail/canvas-blocker-fingerprin/nomnklagbgmgghhjidfhnoelnjfndfpd?hl=en
Disable WebRTC
https://chrome.google.com/webstore/detail/webrtc-leak-prevent/eiadekoaikejlgdbkbdfeijglgfdalml?hl=en
And if you want to change browser user-agent
https://chrome.google.com/webstore/detail/user-agent-switcher-and-m/bhchdcejhohfmigjafbampogmaanbfkg?hl=en
 
Last edited:
Bro just use firefox profiles block webrtc and change user agent, you will be okay you dont need to spoof it harder!
He is planning 50 accounts, google will most probably block them.

OP, Mobile SIM cards can't get you 50 different IPs usually (even if they can it'd be IPv6 and companies don't trust IPv6 much). You'd need proxies to run these accounts.
 
This one can be detected more easily, but it's free and will probably suffice for what you are doing (given your use case doesn't seem likely to trigger many other red flags - ie spamming Facebook etc): https://incogniton.com/pricing/
He is planning 50 accounts, google will most probably block them.

OP, Mobile SIM cards can't get you 50 different IPs usually (even if they can it'd be IPv6 and companies don't trust IPv6 much). You'd need proxies to run these accounts.
i am wanting 50 GMBs but i will have 3 per g account so actually will only need about 15-20 accounts
 
He is planning 50 accounts, google will most probably block them.

OP, Mobile SIM cards can't get you 50 different IPs usually (even if they can it'd be IPv6 and companies don't trust IPv6 much). You'd need proxies to run these accounts.

What country are you based in? I definitely get unique, non-repeating IPs each time, and have my cell APN to only connect to the IPv4 network (if you hit a carrier that only allows IPv6, then just choose a different carrier).
IPv6 is actually more likely to result in a repeat IP as the carrier is able to allocate each device a single IP permanently.
 

A couple of thoughts - mainly given he is going up against a heavyweight like Google on the Blue Team:

Chrome + User Agent change:
Vanilla Chrome + changed user agent is very easy to detect, especially given your contraparty is Google itself (who owns the browser).

UBLOCK:
This won't really do anything given he is accessing services on Googles first-party domains.

Canvas Blockers on Chrome:
Because you aren't changing any other part of your footprint, this just ends up making you look even more suspcious as the service is identifying you with their first-party cookies but noticing your canvas is constantly changing, which is obviously not "normal" user behaviour.
 
Oh and:


Perhaps not as much as a concern for Google, but a good fingerprinting script will likely test for suspicious extensions and add any strikes to a "risk score". Given VPNs have taken the mainstream market for privacy conscious users leading to proxies dropping in popularity relatively speaking, from a risk score perspective, I'd assume that FoxyProxy would be a flag, given the "spammer:realuser" ratio.

More info:

https://securityboulevard.com/2019/11/how-to-detect-browser-extensions-3/
 
A couple of thoughts - mainly given he is going up against a heavyweight like Google on the Blue Team:

Chrome + User Agent change:
Vanilla Chrome + changed user agent is very easy to detect, especially given your contraparty is Google itself (who owns the browser).

UBLOCK:
This won't really do anything given he is accessing services on Googles first-party domains.

Canvas Blockers on Chrome:
Because you aren't changing any other part of your footprint, this just ends up making you look even more suspcious as the service is identifying you with their first-party cookies but noticing your canvas is constantly changing, which is obviously not "normal" user behaviour.
What do you think is the best way to do it?
 
What do you think is the best way to do it?

What you laid out would actually work really well if he wasn't hitting Google directly (ie a mid-tier service that can't afford the same countermeasures as a Facebook or Google etc)

The first problem is that once you start working on these tier-1 type platforms, they almost always have your device fingerprinted (even if it's a fresh PC, the second you log on to any service using a social login, it adds your new fingerprint to it's chain). Using an ultra-common Mac with no special addons can definitely "help" mitigate the accuracy of the fingerprint but if you watch what the guys at Datadome are doing, I'm fairly convinced that even identical hardware is going to have leaks somehow.

The second problem is that because you are logging in to the service directly (ie GMB) anything you do to try obfuscate your fingerprint short of a full override with a tool like MLA, is going to set off alarms for their algorithm as they will see this highly unusual set of behaviours from your device.
It typically won't result in a ban per se (provided you're using good 4G IPs); but expect to get a ton of captchas and re-verifications.

For something relatively harmless like GMB where it's entirely possible that a legitimate agency may need to operate the accounts on behalf of clients, if you set it up the right way (ie to appear to Google as an agency) you'll typically avoid most of the pain. However for Blackhat style operation, (which I'm assuming the OP is requiring), the issues are a) the creation of the new accounts ostensibly from unique identities, and b) the damage a ban could cause if you were running an agency model (ie all your accounts wiped in one go).

So the only solutions I can see are the dedicated fingerprint managers like MLA (or for more simple requirements, Incognition provided they patch a few of the holes some others have pointed out) and good 4G IPs. For the OPs purpose, given he is operating the accounts manually without automation, he could easily run the 4G off his phone, resetting the IP with flight mode toggle. If you need automated switching, that's when things get a bit more complicated.

Lastly, all of the above is fairly unnecessary if he was saying he needed to operate < 10 accounts, but the requirement for 50+ accounts is what takes the problem into this next layer of complexity if the accounts need to stay alive. (Even if they are churn and burn, I still can't see a reason not to try keep them live with those numbers, purely as a way to avoid repeatedly creating new accounts which can end up costing you more than a strong solution, if you value your time at $x/hour)
 
be careful with putting mobile on airplane mode. I actually wrote a thread about this couple of days ago.
When I put on airplane mode, my ip doesn't change significantly, only the last number changes so for example
192.82.39.83
changes to
192.82.39.128

I don't see the big deal with device fingerprinting. how many toshiba laptops exist that have firefox 7.0 and resolution 1280x840? I bet there is thousands of them.
 
When I put on airplane mode, my ip doesn't change significantly, only the last number changes so for example
192.82.39.83
changes to
192.82.39.128

That's expected behavior given the way most carrier's DHCP and NAT is set up. Even a change from `x.x.39.1` to `x.x.39.2` is enough that the platform you are on has to assume it's a completely different user. Especially given the resolution services they use will flag quite clearly that it's a 4G/LTE cellular range, not a datacenter-style range where a single octet shift would be suspicious.

I don't see the big deal with device fingerprinting. how many toshiba laptops exist that have firefox 7.0 and resolution 1280x840? I bet there is thousands of them.

Probably lots, but that represents such a small fraction of your fingerprint as to be almost irrelevant.

Consider a set of vectors as below (a small sample of what a fingerprinting script is assessing) and then ask the "How many ___" question again:

  • The slight manufacturing differences in your hardware components causing variations to your rendered canvas
  • The set of drivers you have installed for audio and graphics compared to the other owners of your laptop
  • The specific fonts you have installed
  • The specific plugins you have enabled
  • Your precise geo-location & timezone
  • Your specific content-language
  • The specific version of the specific PDF reader you have installed
  • The video codecs you have enabled
  • The downlink, downlinkMax, effectiveType, etc of your Connection profile
  • Etc, etc, etc

Now match that up with a set of "behaviours" learned about you over time such as the way you gesture your mouse, and your average typing speed, etc (see https://antoinevastel.com/tracking/2018/08/25/recent-presentations.html, https://antoinevastel.com/assets/media/session9-antoinevastel-fpstalker.pdf) and you can see how statistically improbable it becomes that it's a different user, meaning the "confidence score" allocated to your combined set of vectors can approach 100%.

Additional reading:
https://blog.torproject.org/browser-fingerprinting-introduction-and-challenges-ahead
https://datadome.co/bot-management-...-prevent-fake-account-creation-websites-apps/
https://antoinevastel.com/javascript/2020/02/09/detecting-web-bots.html
https://amiunique.org/
 
Last edited:
That's expected behavior given the way most carrier's DHCP and NAT is set up. Even a change from `x.x.39.1` to `x.x.39.2` is enough that the platform you are on has to assume it's a completely different user. Especially given the resolution services they use will flag quite clearly that it's a 4G/LTE cellular range, not a datacenter-style range where a single octet shift would be suspicious.



Probably lots, but that represents such a small fraction of your fingerprint as to be almost irrelevant.

Consider a set of vectors as below (a small sample of what a fingerprinting script is assessing) and then ask the "How many ___" question again:

  • The slight manufacturing differences in your hardware components causing variations to your rendered canvas
  • The set of drivers you have installed for audio and graphics compared to the other owners of your laptop
  • The specific fonts you have installed
  • The specific plugins you have enabled
  • Your precise geo-location & timezone
  • Your specific content-language
  • The specific version of the specific PDF reader you have installed
  • The video codecs you have enabled
  • The downlink, downlinkMax, effectiveType, etc of your Connection profile
  • Etc, etc, etc

Now match that up with a set of "behaviours" learned about you over time such as the way you gesture your mouse, and your average typing speed, etc (see https://antoinevastel.com/tracking/2018/08/25/recent-presentations.html, https://antoinevastel.com/assets/media/session9-antoinevastel-fpstalker.pdf) and you can see how statistically improbable it becomes that it's a different user, meaning the "confidence score" allocated to your combined set of vectors can approach 100%.

Additional reading:
https://blog.torproject.org/browser-fingerprinting-introduction-and-challenges-ahead
https://datadome.co/bot-management-...-prevent-fake-account-creation-websites-apps/
https://antoinevastel.com/javascript/2020/02/09/detecting-web-bots.html
https://amiunique.org/

wow, that's crazy.
 
Oh and:



Perhaps not as much as a concern for Google, but a good fingerprinting script will likely test for suspicious extensions and add any strikes to a "risk score". Given VPNs have taken the mainstream market for privacy conscious users leading to proxies dropping in popularity relatively speaking, from a risk score perspective, I'd assume that FoxyProxy would be a flag, given the "spammer:realuser" ratio.

More info:

https://securityboulevard.com/2019/11/how-to-detect-browser-extensions-3/

Wait, I just want to create one account but I do not want it to be connected to my identity or any of my other info in any way. If I connected my laptop to mobile 4G hotspot is it anonymous? Or can they still track other things?
 
Back
Top