2026-10-11 16:38 UTC

Privacy researcher AlexanderHanff claims forensic audits of 100 top consumer websites found roughly 30% using Chrome's built-in AI API for device fingerprinting and ad profiling despite Google's privacy assurances for the API; his promised November 17 paper and any Google response resolve it.

state: seedheat: lowuncertainty: mediumconvergesscott: highbrowser-ai-api device-fingerprinting web-privacyGoogleAlexanderHanff

What is this?

Privacy researcher Alexander Hanff claims forensic audits of 100 top English-language consumer websites found roughly 30% using Chrome's built-in AI API (Gemini Nano) for device fingerprinting and Google Advertising profiling, contrary to Google's public assurances that the API would not create privacy risks. Hanff announced he would publish a research paper on November 17 detailing the findings. The claim originates from a Hacker News post quoting Hanff directly; secondary coverage notes Google quietly removed on-device AI privacy assurance text from Chrome's Settings UI. Google has not publicly responded in the supplied material.

Why it matters to Scott

The claim โ€” that Chrome's built-in Gemini Nano API is being used for device fingerprinting and ad profiling despite Google's privacy assurances โ€” directly validates Scott's privacy-inversion and surveillance-creep threat models: obscurity dies when client-side AI makes assembly cheap, and approved on-device APIs incrementally expand beyond their stated purpose. It also bears on his containment frameworks (SiloOS, padded-cell, separation-of-powers, privacy-tokenized boundaries) which treat client-side model surfaces as untrusted until proven otherwise. A confirmed finding would be a dated receipt for the exact risk pattern he argues requires structural containment, not vendor promises.
ip:concept.privacy-inversionip:concept.surveillance-creepip:concept.attention-sovereigntydev:concept.privacy-tokenized-agent-boundarydev:concept.padded-cell-agent-architecturedev:concept.in-browser-student-modelip:framework.siloosip:framework.separation-of-powers-for-cognitiondev:technology.geminiradar:anarlog-private-meeting-memoryradar:android-mcp-on-device-pii-redactionradar:apple-silent-on-device-model-changesradar:agent-screenshot-data-leaksradar:abliterated-weights-agent-backdoorradar:aegis-inline-ebpf-agent-containmentradar:agentsight-ebpf-agent-observabilityradar:anthropic-claude-tracker-privacyradar:deposition-claude-code-memoryradar:chert-facetime-agent-bridge
queries asked of Scott's wikis
  • browser-ai-api local-inference privacy model
  • on-device AI fingerprinting surveillance capitalism
  • Gemini Nano Chrome API web platform
  • Google privacy assurances vs practice adtech
  • web platform APIs for local LLM inference
  • client-side AI privacy threat model

Measured heat

now 0 pts/hpeak 4 pts/hcomments 0/hpeers p14momentum: steady1 platformsage 102h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion

How the heat travelled

10-07 09:32โญ origin directly observedGoogle Chrome's AI API actively used for device fingerprinting and profiling
AlexanderHanff on hacker news
โ€”
10-07 09:32amplified on hacker news ๐Ÿ‘‘hn.story.49990335
AlexanderHanff
peak 7 ยท 0 comments ยท 99% of case engagement
10-07 10:21our radar first saw it ยท +0.8hdiscovery anchor: hn.story.49990335โ€”
pace: p33 vs 1247 stories at the 96h mark (now 102h old) โ€” ahead of 3jsbench-llm-3d-generation-benchmark (1.5x), behind agent-memory-add-search-evaluation (0.8x)

Evidence (1) โ€” โญ canonical anchor

sourceobjectauthorscorecomments
๐ŸŸง hn โญGoogle Chrome's AI API actively used for device fingerprinting and profilingAlexanderHanff70

Interpretation history

Decision trace