Browserprint: Browser fingerprint tool now can guess client OS even when spoofed
browserprint.info
browserprint.info
TL;DR is that the each TCP stack has unique characteristics that are hard to spoof (you'd have to bypass the OS TCP stack and build your own that mimics another) and definitely out of reach for tools that run in sandboxed environments (like browser extensions)
edit: Also, the author of that book, Michal Zalewski, made open source tool p0f [1] that implements some of those techniques to identify spoofed user agents.
[0]: https://www.amazon.com/gp/product/1593270461
[1]: http://lcamtuf.coredump.cx/p0f3/Amazon has indeed gotten called out for these types of shenanigans in the past but that was a long time ago! https://en.wikipedia.org/wiki/Amazon.com_controversies#Diffe...
I missed this related discussion last month: The High-Speed Trading Behind an Amazon Purchase | https://news.ycombinator.com/item?id=13963743
It can be spoofed from a browser extension by messing with the results from the measurement or hooking into core APIs.
Plus you need a font list to begin with, you can't just look at the fonts the system has installed just from javascript.
I don't see how you can mess with the results of measuring successfully, though, at least not without breaking things. You'd have to make CSSOM lie all over the place to avoid it.
It wouldn't be possible to do that anyway without breaking important things like infinite scroll. Infinite scroll fundamentally requires network requests to be issued when an element is scrolled into view, but whether an element is in view depends on the results of layout, which depends on the user's installed fonts…
It'd be kind of interesting if you could only ask about the CSSOM in terms of what the page would look like if rendered with a known set of {fonts, visited links, whatever else is a security leak} rather than asking what it does actually look like—with the browser keeping two render-trees in memory for metrics (the real one, and your hypothetical one) but only actually rendering the real one.
Then, you could synchronize page-manipulation events between the two render-trees, by trying to re-synthesize things like viewport/scroll-offsets and mouse positions, such that everything "will have been" in the right position in one model to end up clicking on whatever element ended up being clicked on in the other model.
Very inefficient, but kind of interesting.
No.
Can't imagine why..?
So, the Snabb Switch sort of thing?
I'm guessing that active layer-4-or-above proxies would also ruin your fingerprinting ability (so people behind corporate firewalls would be un-fingerprint-able.)
And, possibly, API clients running on VM instances in clouds that use software-defined networking, might "look like" the SDN infrastructure, rather than like their VM.
If you are behind a NAT, the TCP/IP stack of the NAT machine will probably present some of its characteristics too.
It is also possible to modify your TCP/IP stack settings so it behaves like something else, a simple search for "defeat TCP fingerprinting" or similar will be a good place to start.
I remember reading about a few universities whose networks would, via fingerprinting, identify your OS and only Windows machines would be required to install some --- intrusive, invasive, and flaky --- additional monitoring software, while Linuxes were allowed completely open access. The solution was obviously to make your machine look like Linux, and this was not hard to do with a few registry tweaks, if I remember correctly.
We could identify malware with around 85% accuracy, which was pretty good without any other marker.
Canvas and Character Sizes are still making me fairly unique... Any ideas there?
I tried various Firefox and Chrome extensions, tried Tor...
The problem is that at a certain point with security, everything just stops working.
Wasn't able to get any sort of meaningful protection that still let me do much of anything... including run the Browserprint tool.
How far would I have to go to setup a truly legit honeypot on a Raspberry Pi? Is anyone already doing this? The following article doesn't get into userland IP stack:
https://www.redpill-linpro.com/sysadvent/2016/12/19/raspberr...
(which is corroborated in both the user agent and the javascript uname sections)
By transitivity FreeBSD is a subvariant of Windows ... or maybe not.
And yet
User agent is parsed as "Mozilla/5.0 (X11; OpenBSD amd64; rv:49.0) Gecko/20100101 Firefox/49.0 SeaMonkey/2.46". Which is actually the case.
http://browserprint.info/view?source1=UUID&UUID1UUID=fa204a9...
What is interesting is that my unspoofed user agent is 3x more rare than the spoofed one, even though the spoofed one usually throws browser versions that are out of date.
Unfortunately, my browser is still unique to the set of 25k whether spoofed or not. Enabling javascript helps a little, but then I can be audio fingerprinted which defeats the purpose.
I definitely have an exotic configuration. KVM / Firefox / No 3rd Party Cookies / Blacklisted social media sites / Addons (including NoScript) that take various steps to lock down information leaks and prevent loading of blocked resources. I don't allow web fonts which is probably fairly exotic as well.
If more would use script blockers and ad blockers maybe I wouldn't be unique, but it seems to be a trade-off between privacy and security. And I just kind of assume that privacy is off the table for now, so at least I can work towards having security.
If I have to choose between the two, I'm more concerned with malware and being tracked through 3rd party resources like Google Fonts, Google APIs (I cache them and prevent subsequent resource loading) than I am being fingerprinted.
tmalsburg2 appears to have tried to make the same point.
I was just remarking about the uniqueness of my spoofed user agent vs a non-spoofed agent. After my initial post I went back and found I was still unique even without a spoofed agent. That's really all there was to my comment, I'm not insinuating that I was surprised to find I was uniquely fingerprinted by other means like font and plugin enumeration.
It's no surprise that Browserprint arrives at the same results with only 65K tests.
I'm also using a fingerprint-blocking plugin, which seems to be doing its job!
You want single U-A that many other people use.
The may well be no additional value to that, though.
Hopefully this doesn't catch on or we have to find another way to spoof these sites.
Browserprint is a free open source project designed to
provide the same and better functionality as the original
Panopticlick.Of course, whether it's effective or just marketing is difficult to prove :)
[1] https://blogs.wsj.com/digits/2010/12/01/evercookies-and-fing...
These days the most effective use is guarding against account takeover. When logging in from an unknown device a user may go through additional authentication steps. Fraud ring counter this with man-in-the-browser attacks.
There are a couple of vendors that offer it as a standalone service or bundle it with other offerings.
We thought it was a good idea to validate the user by email (by sending an email with a unique link, that when clicked, the vote was authenticated.) We thought it was good enough as a "security measure", but we thought wrong!
Some people made disposable email accounts and sent the emails to there, so there were some people with thousands of votes, while most only had a few dozen.
When looking in the database, we were glad that we stored some basic info like IP, Agent Strings and timestamps. These people were smart enough to (sometimes) change IP's but then when looking to the timestamps and agent strings, we saw that these people were cheaters with disposable email addresses.
We removed all these votes and the "winners" didn't win anything at the end, because they had much less votes than "normal" players. They started sending angry emails to the customer, and did not leave them alone.
We are currently making another action for that customer, but this time we have added browser fingerprinting, that checks a lot of variables (like fonts, canvas rendering, webgl, screen sizes, number of monitors, device pixel ratios, ...). This way we'll going to identify cheaters much easily, ... BUT you can still spoof it, so it's never a foolproof method of identifying users, it just makes our lives a little bit easier when there's some cheating going on ;)
// EDIT: some typos
Did you have JavaScript disabled? I did.
At least Panopticlick gives me something useful w/o JS. Crickets from this site.
I'm led to assume adobe flash is the piece which actually divulges all the secrets about my machine. Not surprising.