DPE-2026-0021

Probing the visitor's own device

A page reaches into the visitor's own machine or local network to see what is installed there.

In het NederlandsDe pagina tast je eigen apparaat afWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data webdesktop status active
Not a vulnerabilityNothing is broken into. The probe uses ordinary requests that any page may make, and the software it looks for answers as designed. The objection is that the page is looking at all.

What it is

While the page is open, requests go to the loopback address or to addresses on the visitor's own network, on a fixed set of ports and paths. What answers, how fast it answers, and whether it answers at all tells the sender which software is installed or which devices are present. The result is a characteristic of the machine that no interface exposes and the visitor never offered.

Why it is a separate entry

This is not the page describing itself, it is the page describing the visitor's equipment. The properties found are stable, they say something about the person, and the visitor has no way to see it happen: nothing appears on screen, and blocking it requires knowing it is there.

How it arises

Not to be confused with

Reading properties the browser exposes about itself, such as fonts or a canvas rendering, is Device fingerprinting. What distinguishes this entry is that the traffic leaves the page and addresses the visitor's own machine or network, which the browser does not present as a property at all.

How to establish it

Requests from the page to a loopback address or to addresses in the visitor's own network range, on a fixed set of ports or paths, present in the capture. Where they occur in every consent mode, that is part of the same observation.

method network-observedQoD 92

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itDoes anything on this page talk to the visitor's own computer, and on which ports?
In a DPIA, verify this

Verify whether any component addresses the visitor's own machine or network, and in which consent states it does so.

As a procurement clause

No page issues requests to the visitor's loopback address or local network, demonstrated by a capture that includes loopback traffic.

With a complaint, hand over

A capture including loopback requests, the port and path set, the consent state per capture, and the content security policy of the page.

Reproduction

Legal framing

Objections, and the answer

“It is for fraud prevention.”

That is a purpose, and it has to be stated, limited and justified against a scan of the visitor's own machine. It is not a reason the visitor cannot be told.

“We only check whether a helper application is running.”

Then say so, at the moment it happens, and stop when the visitor refuses. Whether the check is narrow is measurable from the port set in the capture.

“No personal data is collected.”

The provision on terminal equipment attaches to reading from the device, whether or not the result is personal data. And what software someone runs is a characteristic of that person.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0021 (Probing the visitor's own device)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0021
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0021/index.json
Full
DPE Catalogue. DPE-2026-0021: Probing the visitor's own device. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0021
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0021, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.