User-Agent shouldn't include Phone Model

On requesting a page in Brave or Chrome (with default settings) on Android the phone model is incorporated into the User-Agent string.

As well as making it possible to identify the phone model it encourages sites to filter or alter behaviour based on the string rather than the devices functionality.

I would propose not sending the phone model, and consider further restricting the content of the User Agent string. Firefox doesn’t send this information.

I noticed this using a CUBOT mobile phone when it is blocked at Elsevier sciencedirect dot com because it contains the string “BOT”, whilst they should fix their website, this seems like an unnecessary privacy leak.

This may be superseded by https://www.chromestatus.com/feature/5704553745874944
However that was due to ship by September 2020, so not holding my breathe.

3 Likes

That’s a very good idea. In fact, we have an issue tracking this: https://github.com/brave/brave-browser/issues/7758

2 Likes