Virtual Machine Detection in the Browser (2019)
bannedit.github.io
bannedit.github.io
I believe there are patches that can close those holes, but I've always found the fact that such information is exposed by default and can thus make a VM obviously not look more like real hardware is puzzling. Ideally, a VM should be indistinguishable from real hardware, and in practice that ideal is difficult to achieve --- especially with timing-based detections --- but you'd think such obvious signs wouldn't appear.
Also, the amount of information that can be gathered via JS is disturbingly immense. To me, this is just further validation of the fact that JS needs to be off by default and whitelisted only for the (very few) sites that one truly trusts.
Eh, it seems to me that software ought to be cooperative by default. Plenty of programs will detect whether you have AMD or nVidia graphics and optimize itself for your hardware—why not VMWare graphics?
Where I agree is that there ought to be an easy checkbox to hide it.
Does the VM claim it's network driver was manufactured by Broadcom, or does it go with Cambridge Silicon Radio? Or does it decline to provide a vendor, and if it does, how long until software starts assuming that is the sign of a VM, except this time with potential false positives for users of niche hardware?
It would simply be whatever the virtual NIC is. Intel ones seem to be pretty common, likely due to wide availability of drivers and documentation.
Makes sense to me. There are a lot of legitimate reasons software on your computer might need to know it's in a VM or what the limits of your VR engine are.
It feels like something that needs to be asked permission for, however, so it can’t be used for nefarious purposes.
If a website ever really needs to know my hardware, it can ask me to choose from a drop-down. A lot of users won't know what hardware they have—but, those users are also unlikely to understand the implications of a hardware-detection permission prompt.
Firefox removed the battery API for this. In theory you could do something like show a stripped down site for low power users or something but it was only ever used for tracking.
While browsers have been used for a lot now, gaming seems like the one place we have seen virtually no use outside of random 2D games. I doubt there is a single web game that actually makes useful use of the gpu vendor details.
“What is hardware?”
“Should I let a game know my hardware? Should I let a news website know my hardware?”
Why? I mean, it's possible to make a VM that's indistinguishable (except for speed), but what's the purpose of doing so?
Most people who run VMs have the purpose of "I want this application to run more conveniently than having dedicated hardware for it." For that purpose, it's useful to provide abstractions (e.g., providing dedicated access to CPUs in a way normal kernels usually don't) and usually to provide sandboxing (e.g., prohibiting disk writes outside of the VM disk), but there's generally little point in lying, unless the software you want to run won't run right without lying. And it's often counterproductive to lie, because software can adapt to the ways the abstraction is leaky if you're truthful about the nature of the abstraction. (In this case, the VMware graphics driver can achieve much better performance by cooperating with the host than a normal graphics driver expecting physical hardware could get on a software emulation of that hardware.)
It's also often pointless to lie - if you pay for a VM from Amazon EC2, and you log into it and it pretends to be a 1U physical server, are you going to believe it?
The obvious case people will think about is the security angle (by using a vm you to impersonate a consumer end user, so for eaxmple malware doesn't realize it's running in a vm). But there are other cases where murphy's law will bite you.
For example I bet some WebGL apps manage to trip themselves up over this feature string because of whitelists or buggy logic in code that tries to be clever about used features vs underlying platform.
- Do network adapter MAC vendor ID's make sense?
- Does the hard drive size make sense?
- Which 3D acceleration features are supported/work correctly?
- How much graphics RAM is there?
- Timing-based methods
It's a bit like detecting private/incognito mode in a browser. Everything worked great, until websites realised there are ways to detect it, then became a game of cat and mouse.
>- Does the hard drive size make sense?
not detectable through browser APIs
>- Which 3D acceleration features are supported/work correctly?
vmware workstation has 3d acceleration support targeting directx 11, so I'd imagine most features are supported and are passed through to the host gpu for execution. I doubt you'll able to detect is a vm or not based on that. In addition, resistfingerprinting (on firefox) hides this kind of stuff.
>- How much graphics RAM is there?
vmware workstation has vram selectable from 32MB all the way to 8GB, so that covers the entire range of plausible vram sizes.
>- Timing-based methods
what else can you test that is both accessible via browser api and would yield big differences between a vm and a slow computer?
>It's a bit like detecting private/incognito mode in a browser. Everything worked great, until websites realised there are ways to detect it, then became a game of cat and mouse.
not really, it's a solved problem: make a new browser profile and then delete it after you're done. I've seen a few HN commenters post their (relatively short) scripts to make a new firefox/chromium, start it, and then automatically delete it once it exits.
Wouldn't every Qubes VM (whatever the underlying physical machine) return the same fingerprint? Something like VM Fedora version XXX running on Xen hypervisor.
Or the information provided by JS regarding the local machine should be reduced
This would however have the downside of incurring an additional latency with an additional abstraction, but if there was a way you turn this off with trusted websites and only leave it on when you're using a site you don't trust it could be more usable? It just seems better than disabling JS entirely since a lot of websites just completely break without JS.
It just seems like with the amount of information that JS can collect, even if you're using TOR or a VPN, if you crunch all the information about a particular user, like the kind of OS they're running, the version of the browser, the screen ratio, mouse click movements, time of access, number of CPU cores, type of GPU, whether or not it's a VM, etc., it just feels like you might be able to devise a pretty reasonable heuristic for where this person is and the kind of computer they're using. I can't really say I know the extent of browser and JS capabilities, but these things already seem alarming enough where I wouldn't really feel super confident that I can't be tracked even with TOR or a VPN.
Edit: Just discovered something similar to this is being worked on already! https://gpuweb.github.io/gpuweb/#malicious-use
You should have enough ropes to hang yourself, and also a few more just in case.
VMs wouldn't achieve the performance they do without paravirtualization. VMs don't meticulously emulate all attached virtual devices. Paravirtualized device drivers more or less forward the I/O request to the hypervisor which handles it in a VM-specific way. For example, it's not super useful for a VM to emulate all the bitwise register-twiddling dances needed to talk to a SATA controller, it can simply have some "backdoor" channel into the hypervisor that says "Queue request to write X to LBA Y for this VM".
Since paravirtualization requires specific drivers, it will always be detected.
At the end of the day, we all know that any kinds of unique identifiers will be used in combination. We need to reduce those to an absolute minimum. Today’s browser APIs are leaking information like a 1920s faucet.
And, really, when you download a game or desktop app as a traditional executable, the OS gives it so much access to your private data that the term "leak" isn't meaningful any more. Any video game you install as a .exe can silently access every email and online banking account you either are logged into or will log into in the future.
To your analogy, 20 years ago this bit us all in the ass just as much because every EXE brought with it all sorts of toolbars and adware. I don’t want the web to become this.
Browsers "had to" replace Java Applets and Flash. With the great side effect that users can no longer easily just disable those plugins to get rid of the malware build on top.
Imagining a grim future where sites block all ad blockers (how about some detecting if an ad blocker exists at all, rather than its usage?), VPNs, virtual machines, even incognito mode. No full trust = no website.
Seek out only sites that don't block adblock, or has no ads. This might include a paid option (for example, youtube premium, or twitch subscription for ad-free viewing).
And of course this situation has different implications if the website offers some sort of an essential service, but that's an entirely different discussion.
Unpleasant might fit better.
It doesn't break ethical rules to ensure ads are shown so income can be generated to pay for hosting.
Many people have agendas, including sometimes very positive agendas, that lead them to support online services of various types in order to further those agendas.
None of this is to say there’s no place for advertising or for paid subscriptions. I’m just saying there are often more options.
There are questions substantially more interesting than a reductionist "do I have an innate right to access private websites?"
Pretty much no social media platform will accept Protonmail as an address without also having a phone number.
Got banned from Discord within 3 hours, literally all I'd done was send three friend requests and join one discord. My IP was rotating and I then needed to have 2-factor authentication (and protonmail wasn't allowed, I needed that phone number).
So, I went out and bought a burner phone, cash, with a 1-year prepaid account. Got it setup over a wired proxy with all radios turned off. Now at least I had a Google account! (they also require a phone number)
And Discord proceeded to reject it, because I needed to have a 'real' phone number from a major carrier.
I essentially needed to craft an entirely new identity if I wanted to be truly anonymous. It was eye-opening how invasive and pervasive the 'track you down to a real identity' accounts have become.
Just as you can’t really “unsee”, you can’t fully delete data once you’re exposed to it. Something documenting its previous existence will always remain
I had to create a FB account for college, and somehow my account was suspicious according to them. They locked it and said that I needed to provide a picture of my national ID in order to unlock it.
I was baffled and just created another account to be honest.
Basically you are acting like you have something to hide which typically is something that people up to no good would do. I'm not saying you are up to no good, but your activity mirrors as such.
And, to be clear, I'm not acting like someone I'm not. I'm forthcoming that I have an identity, and I'm even willing to prove that I'm a self-consistent individual. I'm acting like someone that has purchased a month-to-month phone, and have signed up for a free email account, and values their internet privacy. It's become apparent to me that a number of companies discriminate against people for whom this is their only choice... heaven help you if you can't afford a proper phone (or don't have the credit to open a proper cellphone account).
As a transgendered person that's been discriminated against, I do indeed have valid reasons for wanting my most personal conversations to be secure from being used against me. There are other aspects of my private life that that would be wildly misinterpreted if taken out of context. I would prefer to keep my private life wholly separate from my public persona, and that's... harder to do in the age of COVID isolation where everything is online.
It's astonishing to me how many people just... don't care about their privacy these days. And that the bar is so crazy high to be anonymous. To the point that wanting to be anonymous for a few hours is indistinguishable from being up to no good?!
Hell, I'd have to _break_ the law and craft a truly new identity just to be able to be anonymous on some of these platforms that don't have real-world identities as a sign-up requirement.
The argument of "you're not doing anything wrong, so why be concerned about your privacy" is disingenuous. https://lifehacker.com/why-your-privacy-matters-even-if-your...
I would venture out even and say that categorically, there are unjust laws that people should be able to hide from - I would want to help them do that. By creating a culture that respects privacy, we insulate ourselves against a lot of the damage that can be done by a poorly managed legal system / toxic culture / opportunistic economic structure. I was just recently reading about how the military buys adtech data to track foreign nationals. I feel like we're living out a Gibson novel.
I do try to "fuzz" my presence as much as possible, because of this. However, like you mention, it ain't easy.
May your holidays be safe and rejuvenating.
In a different kind of society, websites of the sort that you describe would be unpopular, because users at large would place less value on the real-person guarantee than on the non-collection of their identifying information.
Closely related to this is the topic of end-to-end encryption. To withstand attacks that I expect will continue to be mounted on it, I think the society has to believe in privacy as a terminal good. The answer to the argument that "we could catch such and such criminals if we had key escrow" ought to be "yes, and not catching those criminals is a price we agree to pay, because privacy is just that valuable to us".
Oh! But to your question: Mullvad VPN seems to be highly regarded, and has an option to configure a recurring payment that they (claim to) decouple from your identity. Their service even supports defining multi-hop routes.
And to be clear: My goal is to obfuscate my identity from malicious individuals (think: politician that wants to be kinky, but has to resort to online interactions during COVID lockdown, and wants to avoid both simple tracert IP identification as well as a potential password breach & leak of social media platform X). Hiding my identity from governments is not my goal, so trusting Mullvad was an acceptable risk assessment. I'd add additional layers if I wanted to be more anonymous.
My next step, when I get around to it, is to try to track down a cheap anonymous virtual host to SSL into... then at least I'll have a static IP. But I'd still be up a creek if they ever wanted to do two factor for some reason.
But, if you are a citizen in a country that would employ law enforcement against you due to your minority status, I might encourage that protocol.
Otherwise browser developers would create generic classes of device that segment users into large groups based on features.
The fonts thing is proof. For years, you install a custom font on your pc. Then you are unique.
I had a really awesome storage array at home.
Yes, it means you’d get a lot more nagging, but to me, that’s good signal for what sites I should be avoiding in the first place.