Show HN: Your Social Media Fingerprint (maybe NSFW)
robinlinus.github.io
robinlinus.github.io
Having one profile, or even an entire dedicated browser just for Twitter/FB ensures the login is not spilled over into other sites. If you're surfing the web heavily, I would recommend spawning a new private window so cookies, and other artefacts are not bleeding into your session.
It sounds like common sense, but many people have cookies and login information persisting for years at a time in their browsing sessions. The Mozilla Firefox team are planning to introduce a feature which makes compartmented surfing sessions a lot more user-friendly by separating sessions into tabs. Currently, the 'profiles' feature of Firefox is not user friendly and requires a bit of tinkering with the filesystem.
Chain OUTPUT (policy ACCEPT 6309 packets, 599K bytes)
pkts bytes target prot opt in out source destination
330 19800 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 match-set block-facebook-ips dst reject-with icmp-port-unreachable
I have an ipset that matches FB networks.In effect you are "using" Facebook whether you want to or not; this is the issue some people have with shadow FB profiles.
So going to facebook would go to the facebook set automatically and isolate facebook. But I don't have to manually open the "facebook profile" to do the switch. Same with twitter, amazon, google*, youtube, apple, etc.
If you have multiple accounts, you can have the interface pop up a "choose your subcontainer" automatically with the new google container or whatever. All browsing in that container would then stay in that subcontainer until you close it.
You might also want to consider using a different theme[2] in each profile to help avoid mixing them up if your running multiple instances simultaneously.
My initial use case for this was adding the lets encrypt staging certificate authority to the trusted root certificate authorities in a profile only used for testing.
[1] https://developer.mozilla.org/en-US/docs/Mozilla/Command_Lin... [2] https://addons.mozilla.org/en-US/firefox/themes/
https://addons.mozilla.org/sv-SE/firefox/addon/self-destruct... together with https://addons.mozilla.org/sv-se/firefox/addon/i-dont-care-a...
There are a lot of fingerprinting tricks which transcend cookie restrictions and user profiles. The battery percent/value one will reconcile all accounts on one device (as will several other like fonts). If you log into one bucket on multiple devices, it becomes possible to traverse devices and reconcile one-device profiles via the shared profile. If I were truly paranoid, I would only trust "separation" if it involved a clean account on a clean device on a clean network.
None of which is to say that you shouldn't do this! I do lots of privacy things which aren't bulletproof, and I think other people should also. Fighting common tracking structures is still progress, and tools like bucketing and Privacy Badger are great ways to do this.
It's just also worth noting that dedicated profiling will break all but the most pathological defensive measures.
Another trick is to change or settle for one very common user-agent across all browsers, and to run them with differently sized windows.
That was pretty much my point: this is a "nice" profile. One that targets unintentionally identifying image like browser window dimensions can easily track you despite all of those precautions.
I guess my point is that it depends on what you view as pathological? I surmise that this is the kind of thing that needs an algorithmic countermeasure, such that systematic deception by user agents is no more difficult for the end user than browsing the web is currently.
Of course, if you're not pissing off state actors, you're probably fine with qubes/tails.
Thank you, this seems to be a point that is often ignored. Most of us don't need to hide our trail from a full wing of CIA analysts, just drive-by snooping and the like. (It of course doesn't help the Snowdens of the world)
It's interesting to work through the case of an absurdly rich private actor, because it works out differently for diferent companies; for some, they can just get a "man on the inside" to leak out your data easily enough, while for others (e.g. Gmail) the employees themselves aren't trusted to access user data, and have been firewalled/ACLed away from it to prevent just such intrusions. State actors get pretty much the same "help" from every service (save for the rare Lavabits of the world) but corporate actors get a rather unpredictable response landscape.
I think Qubes closes most of the low hanging fruit in this space, but completely preventing fingerprinting is very hard and there are probably ways to leak identifying info.
Also, if you're paranoid about your VPN provider spying on you, you can install HTTP nowhere: https://addons.mozilla.org/en-US/firefox/addon/http-nowhere/ to further compartmentalize the risk of spying. DNS, however is tricky to obfuscate, so I would recommend surfing under broad and generic domains, like TWITTER.com and places like REDDIT.com which often scrape and proxy the content from other sites so you don't need to visit those sites explicitly.
Of course if your threat model is such that nation states are targeting you, either passively, or actively, then TOR is fitting in most cases, but TOR can prove to be overkill in most cases.
For example, if I'm surfing a website which blocks TOR, I can use a JonDoFox[1] profile to visit a website with a VPN, and achieve better-than-most anonymity for my needs, albeit not as rigorous as what TOR provides, but at least my connection has rudimentary protection from passive eavesdropping.
Keep in mind, VPNs are a countermeasure only and do not provide perfect privacy, but you can lessen the information gathered using the techniques I outlined. Surf under generic domains, and block traffic downloaded en clair
It's a tradeoff, you can overdo it and certainly end up less anonymous than before.
A bigger fingerprint might make it easier to identify you but if there are more fingerprints, there might also be more fingerprints that are exactly the same, thus being drowned by the mass.
This would depend upon how the browser implements its 3rd party cookie blocking. If it only blocks setting cookies, but still allows existing cookies to be sent, then there would be no protection.
If it requires quite a bit of domain knowlege (almost everything in security does), it's not 'common sense'.
Someday maybe I'll get around to setting it up. Maybe.
So any website (even your own company's internal one) can check stuff like this. And you can't do anything about it. Other than always using private browsing for anything you don't want your company/anyone else to know about.
Personally I view this as a browser and/or protocol issue (the kind that has trickled down from the origins of the web) and really can't fault the author for it. In fact I think it's appropriate the author left these requests in as it reflects an actual attack scenario better perhaps.
Then again, businesses in general aren't exactly paragons of intelligence either, so I wouldn't be surprised if someone made a fuss about it...
If I worked for such a company, all my traffic would be flowing over a VPN, full-stop.
When you work for such a company, all VPNs are blocked and prohibited, full-stop.
Source: worked for such a company
All direct Internet access is blocked and prohibited, with all attempts to access the Internet (tcp/80, tcp/443) transparently proxied via Bluecoat/Websense/Forcepoint/etc proxies, which filter based on URL categorisation. WSS generally doesn't work in this kind of environment. Everything else is dropped.
Any attempts to bypass filtering is a violation of IT policy and is sackable. Visiting sites that are blocked gets logged, doesn't generally get flagged up unless is a daily occurrence, and the first assumption is usually malware.
Source: Worked for several such companies, was responsible for perimeter security in some.
http://codepen.io/anon/pen/ALdqox/right/
This version connects to squareup.com, twitter.com, www.facebook.com, accounts.google.com, accounts.google.com, plus.google.com, login.skype.com, www.flickr.com, www.spotify.com, www.reddit.com, www.tumblr.com, www.expedia.de, www.dropbox.com, www.amazon.com, www.pinterest.com, www.netflix.com, de.foursquare.com, eu.battle.net, store.steampowered.com, www.academia.edu, stackoverflow.com, accounts.google.com, github.com, medium.com, news.ycombinator.com, carbonmade.com, courses.edx.org, www.spiegel.de, slack.com, www.khanacademy.org, www.paypal.com
After enabling this filter, 0942v8653's version also failed.
I mean I think its too much to ask for a tool to be able to block everything right without a little human assistance.
FWIW, Spotify doesn't seem to get recognized properly. I am definitely logged in and it should show up when all my browser protections are disabled. HN showed up when I disabled everything, but not Spoitfy.
"very NSFW" and "serverS" were overstatements.
IT team then calls in air support
Additionally they're also also working on a more customizable version of that called contextual identities[1], which eventually will also be manageable by extensions[2]
And of course addons that block cookies in cross-origin requests or cross origin requests in general such as µmatrix[3] also plug this hole.
[0] https://bugzilla.mozilla.org/show_bug.cgi?id=1260931
[1] https://blog.mozilla.org/tanvi/2016/06/16/contextual-identit...
Also set 'Send a "Do Not Track" request with your browsing traffic'
And install uBlock Origin, ofc.
I have pretty minimal customizations and plugins on browsers—very few plugins, no ad-blocking, no security or privacy enhancements.
I've had third-party cookies blocked for a long time now and there aren't any sites or logins that break down with them disabled (that I've encountered).
On the plus side, though, you don't have to worry about this crap. I'm logged into several of these sites and none of them show as leaked.
You have no way of knowing if any sites are actually going to comply, and it actually provides an extra datapoint to fingerprint you with.
Looking at the request headers is the simplest way of fingerprinting.
After many years of blocking 3rd party cookies the only thing that's broken for me is my bank's bill pay system, which is an iframe of a 3rd party service.
Also, complain to your bank.
[1] https://support.mozilla.org/en-US/kb/disable-third-party-coo...
uBlock Origin looks way better than Ghostery, which I was using until now.
Chrome, Safari, Firefox, IE9, IE10, and IE11 all use different APIs for Do Not Track [1], so a front-end developer has to do a lot of extra leg work to check if the user has the preference set.
I find it highly unlikely that most companies would go through the effort of respecting Do Not Track.
[1] https://developer.mozilla.org/en-US/docs/Web/API/Navigator/d...
I know a bit off topic but I can't find how this case ended. Anyone with better Google skills??
<img onload="alert('logged in to fb')" onerror="alert('not logged in to fb')" src="https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Ffavicon.ico">[0] https://en.wikipedia.org/wiki/Cross-site_scripting
[1] (This is not my area of expertise. If I'm not correct... please let me know!)
The interesting thing here is that third-party cookies usually allow a central site (e.g. an ad server) to track a user across many other sites. It's almost the other way around here: "other sites" can track status on a "central site".
Some interesting (an unethical) potential marketing opportunities here. For example, at the bottom of articles only show share actions for social platforms they are logged into.
I'm 100% sure that they designed it that way to please Google. The pull requests to change it were ignored. And then they claim to be your partner in keeping your privacy.
AFAIK only Safari has 3rd party cookies disabled by default. There are only very few sites that require 3rd party cookies. I use none of them.
And why would that be, if their deal with Google ended in 2014?
Safari's "3rd party cookies disabled" behavior is not the same as the Firefox one. Firefox's blocks third-party cookies (though it's hard to tell whether it just blocks _setting_ or also blocks _sending). Safari does something where they send the in some cases, but I'm having a hard time determining which cases, possibly because they've changed behavior a few times. At one point they blocked third-party cookies, _unless_ the third-party site has previously been visited as a first-party site. What this meant in practice is that Safari wouldn't block third-party cookies for things like Facebook or Google that you probably have visited as a first party.
At this point they _may_ be doing double-keying of cookies instead (top domain and third-party domain as key, not just the third-party domain). As I said, it's a bit hard to tell from the documentation out there, which is conflicting and contradictory, and I have no time right now to go read the source. And even then they might only be doing double-keying in the "never visited as first party" case...
The point of all of which is, "blocking third party cookies" is not a well-defined thing and different browsers mean quite different things, with different web compat impact and site breakage, when they say they do it.
While it correctly identified me being logged into HN, Medium, and Amazon, it completely missed reddit, GitHub, Twitter, Facebook, etc. I'm assuming it missed them because of me running Privacy Badger, but I'm kind of negatively surprised that Privacy Badger failed to protect me from those three I mentioned.
Other subcomments here mention it, but every time this comes up it seems most people (including the article) aren't aware that blocking 3rd party cookies is a super easy fix and IMHO should be the default of browsers.
I've only ever had issues with this at my banking site because they use a third party to host their solution (Work around is opening the iframe). But I am now going to ask them to fix this (I guess all it requires is a sudomain pointing to the third party?).
Please help spread the message and ask trouble web sites to fix their shit or if I'm completely wrong, educate me and let's move things forward.
Virtually every application I have built will render a simple response saying "You are already logged in" if you GET the login URL with an active session. As I understand the exploit, if a non-image is returned, the script assumes you are not logged in.
What value is there in redirecting a GET if you're already logged in? You redirect when the login form is submitted as a POST.
or
2 tabs open, I follow links to login page on both. Login in one, F5 the other.
What would you propose instead?
Furthermore, how would you monitor the HTTP traffic of suspected terrorists? After all, anyone can embed an image to "www.isis.com/blackflag.jpg" into any webpage, so shouldn't we stop monitoring all such traffic?
Your original assertion was that "it's a pretty crappy check", but I think what you are missing here is that it's the only possible check, minor irrelevant flaws and all.
Lots of fearmongering here, if you want to monitor your employees browsing behavior then you're going to have to supply them with the hardware they do the browsing on, lock that hardware down and install some nannyware to do the monitoring. That way you won't have to MITM each and every connection and you'll have a more secure setup overall.
I do not appreciate being tricked into running your exploit proof of concept, especially when you put content in it that I otherwise would not have clicked.
I think I get the basic concept of calling redirects to various sites from the page, probably back-end like with php, CURL maybe?
I just don't get how you'd keep track of where it goes after the redirect (trying a link) since you would now be on Facebook's site for example
This is because the critical resource is named "/socialmedia-leak/socialmedia-leak.js".
It's not very complete, though.
Disabling 3rd-party cookies in your browser is what protects people against Social Media Fingerprinting.
I always advise to disable 3rd-party cookies -- unfortunately this is not enabled by default in browsers. Even without this Social Media Fingerprinting issue, anyone looking at cookie payload (which also include local and session storage) on common top sites will be horrified at the result of not blocking 3rd-party cookies.
I found it's quite rare to find a site broken because 3rd-party cookies are blocked.
https://github.com/easylist/easylist/commit/d39f815c794a89e4...
For example:
if(!auth) {
setCookie('next', '/url-here', 1h);
}
redirect(login);
Login page action: if(cookieExists('next')) {
next = getCookie('next');
deleteCookie('next');
redirect(next);
} else {
redirect('dashboard');
}https://github.com/ryanbr/fanboy-adblock/commit/2385fb0b2b28...
EDIT: Following diegorbaquero's advice[0] solved it
A better solution would be to disable third-party cookies in your browser settings.
Sending the do not track request generally increases the ability to fingerprint you, as adversaries tend to ignore its purpose anyway.
I tried opening different facebook pages and it detects that I am logged out but the tool still thinks I am logged in.
Any guesses why?
"You are logged in to: Github, Hacker News"
Interestingly, I have a legitimate use for the hack behind this idea.
On the other side, it doesn't detect Facebook. Only got Twitter right.
It got Facebook, Gmail, Youtube, Dropbox right.
Using default browser IE 11 on Win7
>No platform
>(or you're using something like Privacy Badger)
I'm using uMatrix and uBlock Origin :)
Or at least not for me.
Nobody knows you exist because everything is working? Better go yell at somebody.
Everybody thinks you aren't working because something is broken? Better go yell at somebody.
It'll be fun explaining it.
Our IT department LOVES complaining about users using the network inappropriately, so I can look forward to a discussion with HR about this. I guess I should have checked the comments first.
The system is working. Let it do its job.
Says im logged to FB and nothing more. I dont even have a bookface account, but I do have gmail/YT/github/reddit and few other open in the adjacent tabs and fully logged in.
Untrue. I have given my consent. Why are these privacy posts always using some kind of nefarious and negative language?