Panopticlick – How Unique, and Trackable, Is Your Browser?
panopticlick.eff.org
panopticlick.eff.org
Suppose you had a list of options and could selectively disable, for example, monitoring of mouse movements on one site, or ajax on another. And for this in particular, something that would feed the site random values from a particular range for fonts installed, plugins installed, screen size and other such information.
Using that data in development would still work because 99% would keep the default "true" values, and the few geeks who would change them would get what they should/would expect on sites that rely on those values. But everyone should have the power to control what info they're giving out, and what Javascript is allowed to do on their own device.
Sending incorrect information for Java or Flash fonts is an interesting idea, and likely would not affect user experience, as non-standard fonts are often served with the animations. Sending the wrong screen size might get you a mobile site served when you were wanting non-mobile or vice-versa. IP address and ISP are valuable bits of identifying information as well, and those are more difficult to address without using a proxy. But I would bet that randomizing your screen size for each request would break most fingerprinting code, since that would be assumed to be static.
Then what are the five "no javascript" messages I see?
The list of installed plugins is retrieved via JS: window.navigator.plugins.
Not sure about fonts, though.
I am uniquely identifiable out of the 3.7 million samples because of my system fonts.
Also, they aren't particularly picky about keeping you, the trackee, forever uniquely-identifiable.
Consider this: when was the last time you (the non-average) or your grandmother (the average) installed a font?
Even when you do make a change, you could still easily be tracked in many cases. If I see a new signature that I have never seen before that differs from an existing signature only by the version of a plugin, I can probably safely assume it's the same person, especially if I see that the plugin was updated between the last time I saw the existing signature and now.
I have a feeling that web developers are extra vulnerable to this type of tracking because we tend to install several useful developer extensions, and many of us have our own unique combination of extensions.
On top of that, if you use a resource that had only previously been used by your previous fingerprint, your identity can probably be smeared that way too. This is only measuring client-side entropy, but there is also server-side entropy that can be used to make inferences about clients.
Importantly, we can assume that the fingerprint will change incrementally, and remain mostly constant (eg., upgrade plugin OR install new fonts, but probably not everything at once). Therefore, closely-spaced repeat visits could be algorithmically matched, even if the fingerprint changes. This could be especially effective when including other "unstable" (short term) information, such as IP or geolocation, something the authors did not attempt (because these are generally unstable).
From the paper (page 13):
"We ran our algorithm over the set of users whose cookies indicated that they were returning to the site 1-2 hours or more after their first visit, and who now had a divergent fingerprint. Excluding users whose fingerprints changed because they disabled javascript (a common case in response to visiting panopticlick. eff.org, but perhaps not so common in the real world), our heuristic made a correct guess in 65% of cases, an incorrect guess in 0.56% of cases, and no guess in 35% of cases. 99.1% of guesses were correct, while the false positive rate was 0.86%. Our algorithm was clearly very crude, and no doubt could be signifcantly improved with effort."
AFAIK the project it's still active, but no definitive conclusion has been obtained.
But what if you have the same IP address, user-agent, and plugins for a week, and midway through the week your font fingerprint changed? Then they just go and tie both fingerprints, or repalce the old one with the new one.
In reality this is not going to be a problem for any web service that seriously attempts to track users, and there are multiple such companies that are doing so and don't let this stop them. Usually only one fingerprint will change at a time, which makes it easy for them to account for it.
The only good solution is to prevent them from capturing that information in the first place, and the only way to prevent it is to block Javascript and Flash, which is most easily done with NoScript.
But simply installing a font, changing screen resolutions, upgrading Java or Flash ("Browser Plugin details") or entering/leaving daylight savings time will result in the fingerprint changing.
So the browser fingerprint, as presented, isn't really a great way for websites to track users.
(And removing the aspects of the fingerprint subject to change, such as resolution and Browser Plugins etc., would then result in the fingerprint being less unique.)
Let's now imagine an entity that scrapes most of the internet traffic and has connections within facebook, google, etc. This company could easily figure out what pages you visit using a combination of browser fingerprint from the request header and IP. This can be tied to a person using accounts. They can even identify who within a household with the same IP visits which website.
You are quite right, this is true, however it's not really about that.
Firstly this is one technique that when combined with other information becomes more valuable.
Secondly it's not for websites to track users, it's for tracking companies to track browsers across multiple websites.
For example: A credit scoring / user tracking company that your bank uses. You log into the bank system. You visit other websites which have a tracking system. The bank gets a profile of the types of websites you visit, to better profile the types of customers it has. The tracking service has a profile of the types of users that it sees, to better place advertisements for their other customers.
Thirdly, a fingerprint of this kind is more of a multi-dimensional nature, than just a hash of the results. It allows for some variation, it will also update itself based on other information. For example "oh it looks like they have added a new font, but the other information is the same, and their behaviour across all the sites we track them is the same"...
> Your browser fingerprint appears to be unique among the 3,726,837 tested so far.
I may be using an outdated version of Tor. Did they reset their data at some point? I can't believe I'm the first person to have tried the test using the Tor browser in my time zone.
That goal is absolutely impossible if you don't use NoScript, though. Tor browser includes NoScript by default, as well as many other extensions, but NoScript is initially set in "globally allow" mode which means it won't block any JS or Flash.
I would also recommend upgrading, as the bundle no longer ships with Vidalia.[2]
1. https://www.torproject.org/projects/vidalia.html.en2
2. https://blog.torproject.org/blog/tor-browser-bundle-35-relea...
Most of the bits of identifiable information listed there has a reason to leak since 99.999% of front-end developers have no reason to need that information to create an acceptable cross-browser experience for all users.
EDIT: Maybe it is even better for browsers to broadcast the most common settings if EFF discloses this information.
All it takes is a new release of Firefox (different version in the User-Agent string) a new font or any plugin update.
So with that fingerprint you can possibly identify me now, but you cannot track me over time.
[1] For example, see "evercookie": http://samy.pl/evercookie/
For a purpose like ad tracking, the period of time you need to track people is likely pretty short, as in from when they click on a banner or text link until they complete a purchase, so you can compare lots of data points to identify them. If you need to track for longer periods, like to retarget an ad to people who have completed purchases for x, then you would need to compare fewer, more stable points and hope you find a unique match.
With cookies/js/plugins enabled I get: 1 in 3,719,197.
With cookies/js/plugins disabled I get: 1 in less than 160,100
Extension: https://github.com/gorhill/httpswitchboard
EDIT: redid the tests with clearing cache before.
- Use an addon and change your useragent to something common (I use Firefox Nightly, so changing it to a Firefox stable release would make my browser less unique. Blender is a firefox addon that does that)
- Remove as many plugins you can (click2play won't help here, a site can still see the plugin you have installed).
- Enable click2play for the plugin that you still have installed (avoid allowing the site to fetch information with those plugins)
- Disable cookies (If you want to keep a whitelist, I suggest Cookie Controller for Firefox)
- Disable javascript (NoScript for Firefox)
Note that those could actually make your browse more unique, since most people allow cookies and javascript.
As a quick example of that, my browser has ~20 bits of information (one in 1.242.524) with Flash enabled, but ~22 bits with flash disabled (unique).
Use throw away virtual machines if you must, otherwise there is no easy workaround