TeamViewer installs suspicious font only useful for web fingerprinting
ctrl.blog
ctrl.blog
The invitation url looks like this (where XXXXXXXX is the session code).
https://get.teamviewer.com/v15/en/sXXXXXXXX
The website will check if a teamviewer font is installed (using javascript). If the font is found, the web site assumes that teamviewer is installed. The teamviewer installer also registers a protocol handler in the operating system.
The website (javascript code) will thus try to launch teamviewer directly using a url like the following: teamviewer8://instantsupport/?sid=XXXXXXXX
Otherwise, if the font is not found, it will prompt the user to download and install the teamviewer application.Source: Font detection routine:
https://get.teamviewer.com/get/res/scripts/fontdetect.js
Connect routine: https://get.teamviewer.com/get/res/scripts/connect.jsOf course, it would be better still if there was a standard way of setting up specific URL patterns under specific domains to automatically launch an associated desktop app if that app is installed. iOS can already do this through the "/.well-known/apple-app-site-association" URL on the domain. It's why Zoom and Teams links, when opened on an iOS device, always go straight into the native app once that app is installed.
Edit to add: BTW, the file at the well-known Apple path also gives me a way of detecting a Zoom invite URL in one of my own products, even though Zoom URLs can have custom domains.
https://zoom.us/.well-known/apple-app-site-association - 200 OK
https://www.microsoft.com/.well-known/apple-app-site-associa... - 404 Not Found
If you go to the actual Teams site, it does have the apple-app-site-association link.
https://teams.microsoft.com/.well-known/apple-app-site-assoc...
The "PWA" standard for "/.well-known/apple-app-site-association" is "related_applications" [0] in the Web App Manifest standard and specifically here where "prefer_related_applications" [1] is set to true.
[0] https://developer.mozilla.org/en-US/docs/Web/Manifest/relate...
[1] https://developer.mozilla.org/en-US/docs/Web/Manifest/prefer...
Don't assume malice, but do consider side effects of your decisions.
This does add an extra bit to web-fingerprinting, it's only 1 bit. Someone intentionally trying to add fingerprinting could do much more malicious things. Unique font names or uniquely generated font w varying letter widths could completely de-anonymize a user. This seems scoped to identifying team-viewer users, not identifying/fingerprinting individuals.
Just knowing you have a font or TeamViewer, like just knowing your IP or viewport size, isn't fingerprinting your device.
Eventually, everything will be collected using an actual use case — contacts, photos etc. — and the AI will process it and make deepfakes of anything.
We won’t be able to trust any video evidence. The future is about watermarking and signing stuff using your own private keys. And even then, someone can just announce their private keys somewhere and have plausible deniability after that. Too many such renunciations though would be suspicious.
The world is going to be as unfamiliar to us, breaking enough of our assumptions, as when people didn’t know about gramophones and televisions and instant communication, assuming that it would take time for a messenger to get a message out. Today we expect a ton of info to flow over always-on connections. Similarly our assumptions about identity and privacy and democracy are going to be totally smashed by AI and bots soon.
Swarms of bots using GPT-4 and deepfakes will be able to drown out the vanishingly tiny amount of information that all the humans writing online produce, and adversarial networks will make them far more effective at convincing a crowd of humans thay X event happened or to support Y policy, or even rewrite history and science. The sams way that AlphaZero defeated AlphaGo which defeated human players, because it had far more combinations than all humanity combined did, and then downloaded the learnings to each node (Leela and others do the same).
All that is missing is decentralized swarms of bots, that have no single point of failure, and can update their weights autonomously.
I will go even further and say that CAPTCHAs will become irrelevant. Humans won’t be the primary economic actor for online services, because botnets will control far more capital and everyone will do some work for a botnet, such as being a caretaker etc. No one will even know or care who is giving the assignment or writing to them anymore.
The sad part about this is that botnets based on GPT3 and deepfakes are simply bullshittes that don’t understand things like Cyc — they literally throw bullshit at a wall and see what sticks. It’s sad but this will collectively outperform collective human reasoning at convincing humans because ALL our systems are vulnerable to be subverted that way.
Just wait for the deepfakes to utterly destroy video as a means of common representation of reality when it crosses the threshold of too often faked to be generally believed without independent attestation.
And even then people will question subconsciously.
The action of taking your fingerprint to identify you is fingerprinting. Providing you a handrail without a purpose of identifying you, even though it happens to take your fingerprint for anyone else, is not fingerprinting. Changing your fingerprint is not fingerprinting.
This is an abuse of a technology with more harm then benefit if you ask me. Calling it "fingerprinting" is still a category error.
Here's what the Electronic Frontier Foundation says about fingerprinting.
"""Digital fingerprinting is the process where a remote site or service gathers little bits of information about a user's machine, and puts those pieces together to form a unique picture, or "fingerprint," of the user's device"""
From: https://ssd.eff.org/en/module/what-fingerprinting
Here what TeamViewer is doing isn't fingerprinting. it's not combining unrealated bits of information to uniquely identify a user/computer. it's looking at literally one bit of information to identify whether the current non-uniquely-known user is in a -large- group or not, the group of "computers with teamviewer installed".
it can be claimed that this is adding to the bits that can improve a third party's ability to uniquely identify a user/computer, but that's a different claim, that's not what teamviewer is doing.
The forest for the tree here
Headline says "fingerprinting"
If it's public information exposed through a browser and uniquely provides a bit of info, it's good for fingerprinting.
End of line.
Which is not fingerprinting.
> Headline says "fingerprinting"
Which is obvious clickbait.
Learn the terms.
_Any_ website can tell whether or not you have TeamViewer installed. Ad networks could theoretically target you based on whether or not you have TeamViewer installed.
I’m not assuming malice, but it’s a much bigger privacy hole than just increasing fingerprinting by a few bits.
We must assume malice and push back on the invasion of our rights.
Besides, the constant negativity is just exhausting for all involved. I'm glad intellectual curiosity won out on this thread, at least for now.
In this case, I think it IS malice. The font encodes way more data that you'd expect.
Assuming malice from corporations should be the default in today's society.
Sometimes it is the case that no one behind the decisions is being malicious - e.g., perhaps just trying to accomplish a task at hand on a tight timeline.
As such, the default in today's society, where we are more or less 'on our own' on this issue, should be to assume that even while that vehicle over there is indeed about to plow into the crowd, there is often no one behind the wheel.
We should default to an even more suspicious approach.
Every single bit doubles the value so 1 bit could still be a lot.
Per-site font lists don't seem to be a common feature in browsers nor extensions, however.
Teamviewer versions are not backwards-compatible
> It would be totally sufficient to use the protocol handler
The error when it's not installed could be confusing to the user. Remember this is a remote support product, you must the assume the user is not tech literate. You must also assume the user is on IE5 or something.
Honestly if this could only be detected from a TeamViewer-owned domains it would be basically a non-issue. The more concerning bit is that this can be used to build a cross-site fingerprint.
GDPR is concerned with all personal data processing, cookie or not is even more irrelevant to it applying.
What that email does not tell you is that unless you cancel your subscription at least 30 days (ie on that very day) before your sub expires they will renew you automatically and demand a full year's subscription under threat of legal proceedings.
Personally I believe that the purpose of this email is to lull you into a false sense of security that you can just let your subscription lapse instead of renewing when that is far from the case.
I bet you if one of these tricks was a problem for the donors that run our government it would be taken care of.
My role is part Developer Experience Engineer (making sure our developers are happy and productive), part Roving Troubleshooter, and part whatever else needs to get done.
One of our most important metrics is obviously how many orders we complete on our own without crew intervention. So I spend a lot of time looking at our chat logs from the stores to figure out why we had to escalate to the crew - or why they decided to take over the order.
"Welcome to McDonald's. What can I get for you?"
The running joke on our team as that most of us don't eat at McDonald's that often. But there is one sandwich I really like, you just have to customize it a bit.
"I'd like a fish filet, no cheese, with lettuce and pickles"
They use real fish in this, wild caught Alaskan pollock.
"Got it. Anything else?"
"A guava pie and that's it."
The guava cream cheese pie is really nice. A friend suggested we try it, and I was skeptical. But I would order it again any time. Not overly sweetened like I feared, and good flavor.
Disclosure: I work for IBM on this and currently our exclusive customer is McDonald's. (And it should be obvious that I don't get paid extra when you order one of my recommendations.)
I think it's pretty weird to jump right to "the olds know nothing" when the problem is a niche and relatively new scam. Scammers are always finding new scams. Would I like the lag time between scam creation and scam elimination to be faster? Sure. But I'd guess that legislator age is well down the list of factors causing that.
Give the nature of their previous work and their credentials, a good number of them have probably written contracts that have one variant or another of this trick in them.
It's a shame because I occasionally need something with that functionality and would otherwise have happily renewed when I need it.
Of course FTC is going after apple for their ‘terrible’ App Store policies
Both subreddits are full of users helping grandma only to get banned for commercial use, for example.
I gave RustDesk (FOSS) a try and it was nice but slow and I don’t currently have the time or resources to self host near me to see if that makes a difference.
There is a need in this space for a good home use Remote Desktop that’s easy to use and if touted as free for non-commercial use, doesn’t end up banning you later without hard evidence (or just limit free users to 1 session, etc).
Right now they all seem to be chasing medium/large/enterprise money which makes sense I suppose due to the current state of remote work.
Same with Apple offering an awesome PDF manipulating program with Preview and print to PDF, and Microsoft taking many more years to come up with just print to PDF.
I really wish there was a way to set up an RDP gateway without Microsoft server or other complicated setups. There's an open source project rdpgw[0] that provides an RDP gateway, however it requires the use of docker, a web server, and other software. It's not suitable for small use cases like mine (once a month or so, I need to start wsl while away from home, or restart BubbleUPnP service). VPNs and docker add quite a bit of overhead to a system that's already running close to capacity.
The big advantage TeamViewer and AnyDesk offers is the ease of installation for non-technical users.
Besides, that article is outdated. As far as I can tell, every complaint has been fixed.
Windows Store adds one extra step(either a complicated link or search in store)
Yes it is a trivial step for most users but those needing the help most will struggle.
https://apps.microsoft.com/store/detail/quick-assist is not exactly shining with positive reviews.
That said I will evaluate QuickAssist and see if it actually meets my needs.
Not even styled, it's just a HTTP 400 page with some cookies and that message. No HTML.
Yay Microsoft...
The actual link is https://apps.microsoft.com/store/detail/quick-assist/9P7BP5V...
That is about as easy for grandma as 0118 999 881 99 9119 7253 phone number..
Or because:
- you don't know it exists
- you don't know what version of Windows someone is on, and figuring that out is painful
- they can't figure out the Microsoft Store to install it (since apparently it's moved to the Store now)
- or because you don't have a Windows machine to connect from.
My AD use was three home computers to either view them (LAN) or to assist my parents with various questions occasionally. Never any server OS used or on the network. No domain controllers, no email servers, heck at the time I didn’t even have any Linux or BSD machines.. physical or virtual. It was baffling and forever soured my view of AD.
Personally I've been very happy with AnyDesk after migrating 3 years ago from Teamviewer. Seems a bit more performant too.
I've had no commercial nagging from AnyDesk despite using it on about 20 computers. (15 of my own + tech support for friends and family)
TeamViewer got nasty quite quickly.
RDP is nice when it is available but surprisingly less performant on more intensive graphics.
There are a variety of open source VNC solutions but they suffer from the lack of firewall punch through and setup issues.
I agree given the two options I’d choose and recommend AnyDesk first.
Over a 50/50 commercial wireless link RDP over wireguard was best for most users that I had test. AD/TV a close second and VNC was so perceptually laggy that it was a no go from the start.
It's user hostile, and only recent legislation is trying to fix this.
If your contract extends because you forgot to cancel it, you still have to pay, since it's completely legal. If your payment information is not correct, they may even charge you a reasonable surcharge for the failed payment.
After a few warning, you can be sent to a legal collection service, which you either pay, or challenge in two weeks, and it case of challenge it goes automatically to court. Then you will need to pay the contract plus court expenses, since there's 100% chance that extension of your contract is valid.
If you are outside of Germany, and unreachable to the German state, then it may work, since they could decide it's too much hassle for them to collect.
It turns out that, if you refuse to simply let me throw money at you in exchange for software and instead demand an ongoing relationship, I'm almost certain to just nope out and find a different way to fix my problem.
Intentionally baking a bad offboarding experience gives the game away - companies who do this think you're a chump and will happily fuck with you for another nickel rather than build a better product.
1. Browsers should ship with a set of fonts used just in the web browser that web designers can count on. Right now, there isn't a font I can count on finding in Chrome on all platforms. This especially matters for non-English languages, where a different system font can lead to a website that looks very different.
2. Browsers should not load fonts installed in the operating system. It's a fingerprinting vulnerability. And it also causes issues where the system-installed font is unexpectedly different from platform to platform. For example, Arial is different across platforms, especially once you consider non-English languages.
Already in the works, and some browsers don’t today (eg Safari). They permit the default system fonts (eg Helvetica) but nothing more from user space.
In the future it will be a permission you grant a site: https://wicg.github.io/local-font-access/
It’s a great move. The benefits of local fonts are negligible and the downsides are clearly enormous
Surely there would be issues with such a scheme.
Many other features that safari has been late with have basically no fingerprinting usefulness like web push.
It would be lovely if all web developers could just assume that the entirety of google fonts is at their disposal in a native way without having to resort to webfonts and the overhead that brings.
It takes a lot of work to draw a reasonable large set of all the Unicode characters for a given language. Time is money and fonts are ridiculously expensive.
That being said, Firefox has funded a few fonts over the years but they don’t bundle them with the browser. Google has a huge collection but doesn’t bundle them either. It makes more sense with Google as it can collect user data from its WebFont as a service system.
Not like they have any ulterior motives to ensure your users have to ping Googles font service every time they open a page. None at all.
The local cache is, unfortunately, also an unintended source of fingerprinting and cross-origin communication.
It becomes a fingerprinting vulnerability only after the browser (or a script with the permission of the browser) sends information to a 3rd party about which fonts are used on your computer to display text.
The efforts to prevent vulnerabilities must focus on preventing undesirable communication between browsers/scripts and other parties, and not on how the Web pages are displayed, which should be done according to the user preferences.
And how would you do so? Probably I lack in fantasy, but I really don't see a way to distinguish _necessary_ traffic from traffic that is useful only for exfiltrating data.
But it's that tension:
I, as a consumer, am happy with simplicity
They, as producers, want branding and differentiation (not to mention tracking and all sorts of other things)
Ultimately, and we mustn't forget this, they the producers are the ones investing effort they need a return on; and we the consumers are lousy when it comes to voting with our feet, dollars, scrolling thumbs and back buttons.
(Web fonts can be quite space-effective, if the site can serve a trimmed-down version that doesn't have the whole unicode space in them. CSS even has support for breaking the font into pieces so if a bit of unicode does slip through on some page you can still go get "the rest" of the font.)
And in the future, Incremental Font Transfer will make this even easier: https://www.w3.org/TR/IFT/
You can't derive the intention from the page behaviour.
I ignore its updates, because they're large and quite frequent.
https://github.com/archlinux/svntogit-packages/commits/packa...
This means that you get to choose from ttf-liberation, ttf-bitstream-vera, ttf-droid, gnu-free-fonts, noto-fonts, ttf-croscore, ttf-ibm-plex, ttf-dejavu or even all the stuff in the AUR.
it's now difficult to remove that capability without affecting sites (display-wise, not fingerprinting-wise). reality sucks.
As for how to fix it: When the cost for technical measures to ensure security gets too high we need legal measures to ensure a higher-trust society where such technical measures are not needed. We don't all live in locked down fortresses with bullet proof windows and filtered air and water supplies either even though technically that makes us more vulnerable.
In the meantime, there is a Firefox addon called Font Fingerprinting Defender that attempt to mitigate this attack: https://mybrowseraddon.com/font-defender.html
This would help notice things like that earlier
I use this: https://processhacker.sourceforge.io/ gives me notifications whenever a process create/delete services, also has a nice CPU graph in the system tray, thanks to that i noticed Windows will eat your CPU/DISKs whenever you AFK, some telemetry/update thing running in the background.. even when you just idle watching a video.. inefficient telemetry software.. sweet.. what a time to be alive
Could be automatic maintenence https://www.tenforums.com/tutorials/40119-enable-disable-aut... , updates to programs, the windows store updates or windows update service...
What says it is Telemetry?
Yet "Everything" indexes my disk in a minute and spits out results instantly.
Even if windows indexing aint malicious, it certainly behaves as if it is.
The problem is that closing files takes a lot of time on Windows. https://www.youtube.com/watch?v=qbKGw8MQ0i8
You could potentially leak any small piece of information by encoding it in glyph shapes. Should be enough capacity for something like MachineGUID.
All it takes is 2 ip:s and two downloads of their installer and compare checksums.
https://download.teamviewer.com/download/TeamViewer_Setup.ex...
4440facac7b7bf11478a0368ce448adc732d97ae TeamViewer_Setup.exe
I don't have Windows near me to rub tests myself.
Makes them more decent than the others, in my book.
Sure, the installer ships a font file, and sure, the most obvious answer is that it's just installed as is.
But my app also ships a bunch of templates, and it doesn't mean users will always see the same thing when they're loaded. The font binary could have some magic number that's replaced with a fingerprint ID.
Most likely it isn't, but the work to verify would actually involve installing TV in two different machines, and comparing the installed files.
If you think they're going through the hassle to ship a font file but sleight-of-hand install a different font, then why do you think they wouldn't also go through the hassle of further hide what they're doing? For instance, replace a preexisting font you wouldn't think to look at?
If you think it's honest-to-god malware, then provide evidence that it's malware. Installing a font does not make software malware. Checking for the presence of an installed font is not malware.
I don’t recommend TeamViewer anymore. My opinion is that they are janky as hell.
Here's the ref in case anyone else wants to watch it also:
I tend to avoid it unless I'm fairly certain the product / company will last for longer than it would cost me per year of a subscription (to make sure my "investment" is worth it), and that I'll use it extensively.
Nothing is truely forever, and moreso in the world of software.
You will also need to connect to hosts with IPs and open your ports; it doesn't have the ability to punch through firewalls like TeamViewer can.
But the fact is that, since its inception, NoMachine was intended as an "advanced communication and remote desktop tool", more a "professional tool", not intended for the "wide public", especially because you had to "know" and be able to configure things like "an IP address", which is more in the "professional space".
To make NoMachine apt for widespread adoption, we need NoMachine Network, the infrastructure that will allow people to connect by just knowing a "machine id", the same TeamViewer does, and we are working on it. Expect this very soon.
But that said...
We would love to know form you where we can improve the NoMachine UI, to make it more usable, more friendly less "confusing" (if it is) and less intimidating. If you like, you can obviously also contact us directly. Do as you like, but we would love to hear from you.
Edit: contacted you with ticket# WU07T00092
privacy.resistFingerprinting
should impede it («Not all fonts installed on your computer are available to webpages»), but I am not sure, as I do not know the exact "which fonts to expose" rule.Edit: in theory, it should allow only "«base»" fonts and not user installed. In practice, more details would be useful.
More details (the lists of whitelisted fonts per OS) are here: https://bugzilla.mozilla.org/show_bug.cgi?id=1336208
Privacy is at odds with usability, sometimes.
TeamViewer is a long way from the only software being used for this, but it's kind of a cool opportunity.
My current workflow is -> Connect to HomeVPN -> Turn on Gaming PC with WakeOnLAN -> Connect with TeamViewer to start Steam -> Start gaming with Steam RemotePlay. I did not find a way for Steam to autostart without logging into Window, that's the only reason I currently use TeamViewer, essentially to login and start Steam.
Yeah, my use-case is very specific, I know. I don't even game remote myself, but if I'm on holidays or at work and my partner wants to game from their home, I need a way to be able to power on my PC and everything necessary for it to work. A complete niche, first-world problem :)
I use Parsec and remote to my desktop from my shitty laptop and get much better performance than I would just gaming with an integrated chipset and it's portable. Also, plugging in a usb controller into my laptop automatically controls the desktop without any setup.
Only bad thing I can say is that they got bought by Unity last year and Unity is now merging with IronSource :/
MeshCentral looks promising, but RustDeck, which another comment recommended, seems to do the same thing in a more attractive way.
Thanks!
You can replace it with NoMachine NX or just with some variant of VNC.
That's exactly my issue :)
Or if you don't use an MS account to logon then just configure Autologon and shove Steam link to the Autostart
[0] https://docs.microsoft.com/en-us/sysinternals/downloads/auto...
If I remember correctly, it had some "weird" design decisions (disabling your Wayland install and replacing it with x, being one of them haha).
Edit: here's a link that tells you how to do that. It's a bit involved since you have to mess with Registry keys, but it should be possible https://www.alphr.com/how-to-enable-auto-login-in-windows-10...
https://arstechnica.com/information-technology/2013/03/the-w...
As with anything though, it could be abused by tech support scammers. Overall, I wish such things weren't implemented.
That seems the most likely explanation. That it was once used somewhere in TeamViewer, no longer is, but is still packaged. I don't think there's a real conspiracy involved.
Just a shill for Brave.
*Edit: well, I didn't know randomization or the plain use of Brave itself is a useful fingerprint point.
As usual on HN, people is speculating and guessing rather than studying the subject.