Panopticlick – How Unique, and Trackable, Is Your Browser?
panopticlick.eff.org
panopticlick.eff.org
I wonder how it would fare if it included WebGL stats but excluded all plugin data, e.g. stuff from Java or Flash. Seems to be a direction browsers are moving in.
This way nobody even knows if I'm on Firefox or Chrome.
The more unique, the more trackable.
I visit this site at least once a month and every time it picks me as 'unique'. That is because each time i've either installed a plugin, installed a font, my browser version changes every 5 days with automatic updates, installed a new browser, installed a different browser, am using multiple browsers, am accessing from my phone, ipad, work computer, etc.
This makes it useless for actually tracking people.
To make browser fingerprinting anything more than useless in tracking you need an algorithm that fingerprints but doesn't capture everything - such as how hardware-locked licensing works and Windows Genuine Advantage - you can change your soundcard or any minor device and your overall ID/fingerprint is still the same (i'm struggling to remember what this technique is called).
When reading the NSA revelations I dug through everything with an eye on wanting to know if they used browser or machine fingerprints to track users. They don't. There is enough unique information in IP address, cookies and email accounts alone.
And I bet most people who are concerned by tacking online and impressive demos like this are still using their real IP address online, still accepting cookies, etc.
Yet another reason to not use flash. Its good to know that this functionality is not built into the actual browser.
Most video sites revert to html5 video. You are also telling developers who track their flash install base to update their site to be compatible by voting against flash with your browser.
More important, i've been disabling flash on the computers of non-tech friends and they don't seem to notice it either.
If you need Java for banking, setup a second or third browser where you only access that site, and by only entering in the URL directly.
> I visit this site at least once a month and every time it picks me as 'unique'. That is because each time i've either installed a plugin, installed a font, my browser version changes every 5 days with automatic updates, installed a new browser, installed a different browser, am using multiple browsers, am accessing from my phone, ipad, work computer, etc.
> This makes it useless for actually tracking people.
Not at all. This site isn't a demonstration of tracking you, it's simply a measure of how unique your browser is. Somebody who actually cared about tracking you could trivially track changes: a profile with a set of 191 particular fonts and a later profile that is identical but with 190 fonts is probably the same person.
How would one use a 'fake' IP address and expect traffic to make it back to him/her?
I'm not enough of an expert to go into more detail, but the google keyword you want is "proxy".
Back then, the proponents of that plan insisted the privacy concern was largely academic. I somewhat wonder what would've happened post-PRISM leak had they ever implemented it.
Expecting privacy-minded people to opt-out of using telephones or emails for fear of government monitoring isn't reasonable. Opting out of Stack Overflow is nowhere in the same league.
I feel like I explained the issue pretty clearly in the preceding sentence:
> Back then, the proponents of that plan insisted the privacy concern was largely academic.
We now know via the various leaks that have occurred recently, that government agencies will use any information available to them and that there is largely nothing the public can do to stop it or be made aware of it except through the occasional one-off leak like PRISM.
That is to say, the privacy concerns related to any private company tracking PII to this degree aren't academic or abstract. Information kept to prevent abuse can just as easily be repurposed for surveillance. I suspect (and would hope) many of the same people pushing for this feature back in 2011 would reconsider their support for a feature like this knowing what we know now.
> Expecting privacy-minded people to opt-out of using telephones or emails for fear of government monitoring isn't reasonable.
I'm not sure what part of my comment lead you to believe I would think otherwise, but I don't.
> Opting out of Stack Overflow is nowhere in the same league.
In the comments of the post I linked, several people were insisting that there wouldn't need to be an additional disclosure because it's information that's either public, available to other third parties (like browser makers), or already available to Stack Overflow in a different form. Not knowing that a site like a hypothetical Stack Overflow—where a feature like this was implemented—is keeping records on this level and therefore not opting out isn't informed choice.
Indeed, a significant portion of the outcry with respect to the NSA leaks is that nobody knew that the government had such a direct connection to the information stored by private companies that people could've easily opted out of using (e.g., Facebook, Apple, Google, or Paltalk).
But all I was attempting to do here was mention a past experience with Panopticlick and muse how it might've went today. I guess I've been bitten by something pg once said[1], that "you can't be concise on forums because if you leave any possible room for misinterpretation, someone will reply with it".
[1]: http://meta.stackoverflow.com/questions/113394/implement-som...
So is this good or bad?
Some time this year, I'm planning to write a browser add-on which will send random (legitimate, from real browser versions) header combinations of the user agent (+OS) and accept headers. It can be semi-random, e.g. send the same headers to the same host during one visit. Combine it with the NoScript addon, use the RequestPolicy addon, block 3-rd party cookies, tell the browser to delete the cookies and local storage on exit, use plugins only in "on-click" mode (or don't use plugins), don't send "referer"s (or send fake "referer"s), use Tor for HTTPS sites (and sites that don't need authorization), and this will make hard to track you.
Do it for chrome.
...and let me send you money.
Go here => https://stopfingerprinting.inria.fr/ Chrome + Firefox add-on.
EDIT: solved->solve, they didn't solve it yet, but this add-on helps them solve it.
Making it more widely useful would require a lot of thought, because much of the functionality of the current web is predicated on using these same vectors. There are interface issues, and fundamentally, the web would be significantly less useful for a large number of people if the privacy situation were ameliorated.
> Currently, we estimate that your browser has a fingerprint that conveys at least 21.62 bits of identifying information.
Your result sounds a lot better than mine. Simply using Opera gives me a one in 111366.28 result.
'Your browser fingerprint appears to be unique among the 3,230,650 tested so far.'
or simply enhance the mentioned method my HTML5 / CSS3 support (e.g. through http://modernizr.com/) and you will get even much better results as shown in this study (https://panopticlick.eff.org/browser-uniqueness.pdf).
The next ugly site could steal your browser history that way and show which porn sites you've visited, in example.
Go here => https://stopfingerprinting.inria.fr/ Chrome + Firefox add-on.
For the moment, there is no protection from fingerprinting. Browser extensions that change some of the parameters of your browser’s snapshot make you even more identifiable because there are often other ways to check the values of these parameters. However, some of your parameters change by themselves, for example, after your web browser updates, or simply when you travel or use external monitors. Panopticlick does not take it into account, however effective fingerprinting libraries are able to identify you because they monitor your consequent visits to the websites.
For example, use Useragent Switcher in FF, this is effective as long as you keep JS off. With JS the site can interrogate the client and report and any discrepancy would be found, and distinctive.
I've been looking at this from the avoiding-tracking and from the server side (identifying clients independently of cookies). The client is very limited in options with JS on. Users need more control of this in the browser.
In an application you could in principle track users even across some changes with a sort of "preponderance of the signals" confidence value - weighting several things like Ip, platform etc..
Next, I tested the browser I never use: IE10. It was installed with the OS. I presume it's been kept up to date, but I haven't used it let alone modified it in any way. Also unique.
This is fishy.
----------------
Update:
Okay. It makes sense now.
Part of this test gathers a list of system fonts installed. I have some pretty weird ones installed which seem sufficient to uniquely identify me.
System fonts can betray your identity online... Who knew?
However even without the fonts the combination of screen size timezone, browser and plugins list seems to be pretty unique.
Get a user-agent switcher and try several different browsers. (Use the 'Test Me' button after switching.) In the past I found IDing as IE8 made my browser 1 in 3000 or so.
Another good site for testing your settings security is grc.org.
Then, look for a new way to get information as the web has become almost unusable for you in 2013.
After some investigation I found out that one guy has infected many thousand OSX and Windows PCs and turned them into drones. Now I know how they make money, selling their bot-nets. Kinda disappointed, I thought there is more thought and work required. But you see the point, anybody with enough patience can do that today, the tools are available.
And they don't even need (and often do not have) a shred of basic IT knowledge to do any of this, let alone programming knowledge.
Flash makes it easier since you can simply enumerate all the fonts.
And yes, 1080p is still a fairly uncommon resolution in this laptop era. StatCounter estimates 7-8%, and it's somewhat likely that StatCounter and EFF are going to have different skews [2]
[1] http://www.newtimezones.com/pdfs/current_economic_crisis.pdf
[2] http://gs.statcounter.com/#resolution-na-monthly-201302-2013...
Sounds ballpark reasonable to me - Europe is twice the population of USA, and USA is split over more timezones. And Asia has more people than USA and Europe put together.
I think it mostly goes to show that it doesn't take much information to reduce the number of possibilities by 1-2 orders of magnitude.
In my case, Safari on iPad makes me 1:67,000. Chrome on the same iPad makes me 1:1.6 million.
It took me a moment to realize that means I am completely trackable.
A little surprising since I just built this computer from scratch a couple weeks ago. I'll take this more as a commentary on the popularity of Windows 8 more than anything.
I'm a snowflake!
But that makes you more unique and a better target.
"My browser firefox fingerprint appears to be unique among the 3,230,950 tested so far and 21.62 bits of identifying information, mostly acceptable to be shared." But this is just a demo, a real attacker could get much more info out of it, I'm not protected against this.
Why do you think that you have gotten that result? Did you compile Chromium with some special flags?
I suppose you might have a confidence equation based on overlap, since changes would likely be small and gradual.
Also, it might mess with overall statistics
[1] An example of this can be seen here: http://time.is
https://bugzilla.mozilla.org/show_bug.cgi?id=572650
See the bugs under "Depends on" for examples of changes they've made, or Dave Garrett's comment #59.
I've seen this link several times before and it always says I'm unique. A new discovery this time: Ubuntu is patching Firefox to gratuitously add itself to the user agent string, giving it more visibility, but also making all Linux users more trackable. That's pretty shitty, and they seem to do the same thing to the packaged version of Chromium. I don't know what to do about it, so I'm afraid my complaint isn't actionable.
3in1 Internet Bundles coming with:
* Wiretapped VoIP
* Censored and Tracked Internet
* Browser History based TV Programs and Ads
(Online-Shops already do income based pricing)What we really need is a modified ``privacy'' build of FF that reports spoofed js/css data (screen res etc), but I'm not skilled enough in web stuff to make that.
As a side note, I've been impressed with French academia lately. Between INRIA and IRCAM, I see a lot of quite practical stuff that I like coming from there.
It will not be very interesting if you don't care about computer music, but IRCAM has an ethos of producing many projects in that area. For example, the Max system that later became Max/MSP (and later the open-source version, Pd) was originally an IRCAM project. They also have a Common Lisp based visual-score system (http://repmus.ircam.fr/openmusic/home), a system for data-based resynthesis using musical corpora (http://imtr.ircam.fr/imtr/CataRT), and a number of other things, including many projects more on the music/composition side.
This seems just a wrong statement. If Firefox and Chrome are open source there must be a way to modify the fingerprint. Even if it comes in form of some "pre-loader" that blocks the sending of one fingerprint and overwrites it with another.
My suspicion is that sites coming across as super sneaky (e.g. LinkedIn) are actually using browser identification / fingerprinting to make their otherwise impossible suggestions.
Other addons may prevent certain leakages, but definitely not all.
The user signups up, connects their phone to their account and you use the fingerprint as the ID for future validation?
How do you handle changes in fonts/plugins/browser versions/timezones while travelling.
All of that data seems to be muteable over time. Unless it's a 99% match kind of thing. Also what about companies that hand out laptops with the same base OS/browser-installs (or is that the goal)?
1. Your Tracking Technique + DRM-based-License Tracking
2. One Password / ID (No username required, it's optional)
3. Typing Speed Tracking 99.5 percent accuracy [1]
4. (Bio-metric Data like Fingerprint or HD Iris Scans for Gov. Clients)
DARPA is also working on it, definitely watch this (Google alredy uses this!):http://www.youtube.com/watch?v=fgNpOzvwOiU
[1] http://csis.pace.edu/~ctappert/it691-08fall/projects/keystro...
Dude, you made me curious, I will implement this after my thesis! :)
(I'm watching you DARPA et. al /24/7/365!)
The more info you share here, the more dangerous it gets and the more people are aware of the danger it could pose, when used by the wrong hands.
You may feel that as the sample set grows others may join your party but you have not told us why you believe this to be the case. I wouldn't be too sure, I would be more hesitant in reaching that conclusion.
As it stands you are a unique snowflake and so am I.
Very good to know... will get plugin to alter browsers identifying information.
I guess it is good choice to disable JS by default
Okay... so what does that actually mean to you?
Perhaps the best way to proceed here is by comparison:
To pick out one person uniquely among the 7 billion people on Earth requires ~33 bits of information.
Each bit of information divides the search space in two, (just like with computers =p )
Which is why you can just go:
log2(searchspace) = required bits
You can also work the idea backwards. (i.e. 2^(available bits of info)) to find out what size of search space you can be found in.
It so happens I give up about 22 bits so... I can be found in a population of about 4 million.
Put another way, there are, best case scenario assuming that the distribution is random (which in practice it almost certainly isn't), around search space / uniquely identifiable pool people with a similar fingerprint to myself.
In this case we're dividing seven billion by 4 million which should give you around 1,750 similar people to myself.
So... that's pretty darned accurate - but not that worrying yet perhaps. At least if you needed to uniquely identify me.
But I'd bet a heck of a lot they do have other info.
Every bit of information under that needed to identify you uniquely in the search space doubles the potential group size you have to hide within. Every bit of extra information they have, halves it.
Not everyone in the world is online. Only 39% were predicted to be so this year, I believe.
Suddenly you're looking at only having 683 people like you on earth.
And it gets worse.
The really relevant search pool is going to be how many people connect to the sites they know about - which are probably going to be multiple sites since they can store and trade your IP address which probably isn't going to change that often. I bet most of the sites I connect to don't get anywhere near 39% of the world's population connecting to them.
How unique am I for the sites I visit? The sites I visit, if they're niche like HN, probably gives a HECK of a lot of info on me. To the point where I suspect I can be absolutely uniquely identified here by my browser fingerprint. You'll notice that of the 3 odd million people on the EFF site I provide more than enough info to be uniquely identified.
And even if they don't, the cumulative probability is the product of the sum of the individual probabilities. If someone goes on two niche sites, or three... The search space gets cut up again. Snipety snip.
So, yeah, in connection with other databases and the usual attack vectors people use when they start getting info on you - targeted adds, security profiling etc, that's pretty worrying. It's especially worrying for applications where people aren't going to have a high cost from hitting the wrong target.