// Workers AI · dad joke modeWhat did the device fingerprint say? I've got a grip on your data.
A device fingerprint or machine fingerprint is information collected about the software and hardware of a remote computing device for the purpose of identification. The information is usually assimilated into a brief identifier using a fingerprinting algorithm. One of the most common types of such is a browser fingerprint, which depends on information collected specifically by interaction with the web browser of the device.[1]: 1
Device fingerprints can be used to fully or partially identify individual devices even when persistent cookies (and zombie cookies) cannot be read or stored in the browser, the client IP address is hidden, or one switches to another browser on the same device.[2] This may allow a service provider to detect and prevent identity theft and credit card fraud,[3]: 299 [4][5][6] but also to compile long-term records of individuals' browsing histories (and deliver targeted advertising[7]: 821 [8]: 9 or targeted exploits[9]: 8 [10]: 547 ) even when they are attempting to avoid tracking—raising a major concern for internet privacy advocates.[11]
History
[edit]This section needs to be updated. (March 2020) |
Basic web browser configuration information has long been collected by web analytics services in an effort to measure real human web traffic and discount various forms of click fraud. Since its introduction in the late 1990s, client-side scripting has gradually enabled the collection of an increasing amount of diverse information, with some computer security experts starting to complain about the ease of bulk parameter extraction offered by web browsers as early as 2003.[12]
In 2005, researchers at the University of California, San Diego showed how TCP timestamps could be used to estimate the clock skew of a device, and consequently to remotely obtain a hardware fingerprint of the device.[13]
In 2010, the Electronic Frontier Foundation (EFF) launched a website where visitors could test their browser fingerprint.[14] After collecting a sample of 470,161 fingerprints, they measured at least 18.1 bits of entropy possible from browser fingerprinting,[15] but that was before the advancements of canvas fingerprinting, which claims to add another 5.7 bits. Panopticlick, a tool run by EFF, showed that 83.6% of fingerprints were unique, reaching 94.2% when combined with Flash or Java.[16]
In 2012, Keaton Mowery and Hovav Shacham, researchers at University of California, San Diego, showed how the HTML5 canvas element could be used to create digital fingerprints of web browsers.[17][18]
In 2013, at least 0.4% of Alexa top 10,000 sites were found to use fingerprinting scripts provided by a few known third parties.[10]: 546
In 2014, 5.5% of Alexa top 10,000 sites were found to use canvas fingerprinting scripts served by a total of 20 domains. The overwhelming majority (95%) of the scripts were served by AddThis, which started using canvas fingerprinting in January that year, without the knowledge of some of its clients.[19]: 678 [20][17][21][4]
In 2015, a feature to protect against browser fingerprinting was introduced in Firefox version 41,[22] but it has since been left in an experimental stage, not enabled by default.[23] The same year, a feature named Enhanced Tracking Protection was introduced in Firefox version 42 to protect against tracking during private browsing[24] by blocking scripts from third-party domains found in the lists published by Disconnect Mobile.
In 2016, an AmIUnique study found that 89.4% of fingerprints were unique, and attributes used to identify them were constantly evolving.[16]
At WWDC 2018, Apple announced that Safari on macOS Mojave "presents simplified system information when users browse the web, preventing them from being tracked based on their system configuration."[25] A 2018 study, Hiding in the Crowd, found that only 33.6% of fingerprints were unique; on mobile devices the difference was even larger, as 18.5% of mobile fingerprints were unique compared to 81% from earlier data. This study also showed that fingerprints on desktop computers are mostly unique due to combinations of attributes, while mobile devices present attributes with unique values.[16]
In 2019, starting from Firefox version 69, Enhanced Tracking Protection was turned on by default for all users during standard non-private browsing.[26] The feature was first introduced to protect private browsing in 2015 and was extended to standard browsing as an opt-in feature in 2018.
Diversity and stability
[edit]Motivation for the device fingerprint concept stems from the forensic value of human fingerprints.
In order to uniquely distinguish devices over time through their fingerprints, the fingerprints must be both sufficiently diverse and sufficiently stable. In practice, neither diversity nor stability is fully attainable, and improving one tends to adversely impact the other. For example, the assimilation of an additional browser setting into the browser fingerprint would usually increase diversity, but it would also reduce stability: if a user changes that setting, the browser fingerprint changes as well.[1]: 11 However, in the absence of user opposition, fingerprints are not difficult to identify, especially since they can be based on a wide variety of data. For example, research indicates that 56.86% of users have unique extensions, and 34% of the population can be identified by the 43 characters of the fonts used.[16]
A certain degree of instability can be compensated for by linking together fingerprints that, although partially different, likely belong to the same device. This can be accomplished by a simple rule-based linking algorithm (which, for example, links together fingerprints that differ only in browser version as it increments over time) or machine learning algorithms.[27]
Entropy is one of several ways to measure diversity.
Sources of identifying information
[edit]Applications that are locally installed on a device are allowed to gather a substantial amount of information about the software and hardware of the device, often including unique identifiers such as the MAC address and serial numbers assigned to machine hardware. Programs that employ digital rights management (DRM) use this information for the express purpose of uniquely identifying the device.
Even if not designed to gather and share identifying information, local applications may unintentionally expose identifying information to remote parties with which they interact. The most prominent example is web browsers, which have been shown to expose diverse and stable information in amounts sufficient to allow remote identification (see § Browser fingerprinting).
Diverse and stable information can also be gathered below the application layer by leveraging the protocols used to transmit data. Sorted by OSI model layer, examples of protocols that can be utilized for fingerprinting include:
- OSI Layer 7: SMB, FTP, HTTP, Telnet, TLS/SSL, DHCP[28]
- OSI Layer 5: SNMP, NetBIOS
- OSI Layer 4: TCP (see TCP/IP stack fingerprinting)
- OSI Layer 3: IPv4, IPv6, ICMP
- OSI Layer 2: IEEE 802.11[29], CDP[30]
Passive fingerprinting techniques merely require the fingerprinter to observe traffic originating from the target device, while active fingerprinting techniques require the fingerprinter to initiate connections to the target device. Techniques that require interaction with the target device over a connection initiated by the latter are sometimes referred to as semi-passive.[13]
Browser fingerprinting
[edit]The collection of a large amount of diverse and stable information from web browsers is enabled primarily by client-side scripting languages introduced in the late 1990s. Several open-source browser fingerprinting libraries exist, such as FingerprintJS, ImprintJS, and ClientJS, with FingerprintJS being the most actively maintained and widely replacing earlier tools.[31]
Browser version
[edit]Browsers provide their name and version, along with compatibility information, in the User-Agent request header.[32][33] Being a self-reported statement by the client, it cannot be inherently trusted for identity verification. Instead, the browser type and version can be inferred by observing quirks in behavior: for example, the order and number of HTTP header fields is unique to each browser family,[34]: 257 [35]: 357 and each browser family and version differs in its implementation of HTML5,[9]: 1 [34]: 257 CSS,[36]: 58 [34]: 256 and JavaScript.[10]: 547,549–50 [37]: 2 [38][39] Such differences can be remotely tested using JavaScript. A Hamming distance comparison of parser behaviors has been shown to effectively fingerprint and differentiate a majority of browser versions.[9]: 6
Browser extensions
[edit]A unique combination of extensions or plugins can be added to a fingerprint directly.[10]: 545 Extensions may also modify the behavior of other browser attributes, increasing fingerprint complexity.[40]: 954 [41]: 688 [8]: 1131 [42]: 108 Adobe Flash and Java plugins were widely used to access user information prior to their deprecation.[35]: 3 [10]: 553 [39]
Hardware properties
[edit]User agents may provide system hardware information, such as phone model, in the HTTP header.[42]: 107 [43]: 111 Properties regarding the operating system, screen size, screen orientation, and display aspect ratio can be retrieved using JavaScript to observe the results of CSS media queries.[36]: 59–60
Browsing history
[edit]A fingerprinter could previously determine which sites in a provided list a browser had visited by querying the list with JavaScript using the CSS selector :visited.[44]: 5 A list of 50 popular websites was often sufficient to generate a unique browsing history profile and infer user interests.[44]: 7,14 Modern web browsers have since mitigated this tracking vector.[45]
Font metrics
[edit]Bounding box dimensions of letters differ between browsers based on anti-aliasing and font hinting configurations, which can be measured via JavaScript.[46]: 108
Canvas and WebGL
[edit]Canvas fingerprinting uses the HTML5 canvas element—also utilized by WebGL to render 2D and 3D graphics in a browser—to gain identifying information about the installed device driver, video card, or graphics processing unit (GPU).[47] Canvas-based techniques may also be used to identify installed computer fonts.[43]: 110 If no dedicated GPU is available, CPU rendering information can be extracted instead.
A canvas fingerprinting script draws text of a specified font, size, and background color. The rendered image is recovered via the `ToDataURL` Canvas API method, and the resulting hashed text-encoded data serves as the user's fingerprint.[19][18]: 2–3,6 Canvas fingerprinting methods produce approximately 5.7 bits of entropy. Because this technique extracts GPU-specific characteristics, the information gained is orthogonal to entropy obtained from traditional browser fingerprinting techniques such as screen resolution or JavaScript capabilities.[18]
Hardware benchmarking
[edit]Benchmark tests can determine whether a CPU utilizes AES-NI or Intel Turbo Boost by comparing the CPU time required to execute specific simple or cryptographic algorithms.[48]: 588
Specialized APIs can also be leveraged, such as the Battery Status API (which constructs a short-term fingerprint based on battery charge state)[49]: 256 or `OscillatorNode` (which can produce audio waveforms influenced by system audio processing entropy).[50]: 1399
A hardware ID—a cryptographic hash function specified by a device vendor—can also be queried to construct a fingerprint.[43]: 109,114
Mitigation methods
[edit]Approaches exist to mitigate browser fingerprinting and enhance user privacy, though no single method completely prevents fingerprinting while maintaining full functionality for modern web applications.
Offering a simplified fingerprint
[edit]
Users may attempt to reduce fingerprintability by selecting a web browser that minimizes available identifying information, such as system fonts, device IDs, canvas element rendering, WebGL data, and local IP addresses.[43]: 117
In 2017, Microsoft Edge was evaluated as the most fingerprintable browser, followed by Firefox, Google Chrome, Internet Explorer, and Safari.[43]: 114 Among mobile browsers, Google Chrome and Opera Mini were found to be most fingerprintable, followed by mobile Firefox, mobile Edge, and mobile Safari.[43]: 115
Tor Browser disables fingerprintable features, including canvas and WebGL APIs, and alerts users to fingerprinting attempts.[19] To reduce diversity, Tor Browser restricts webpage viewport dimensions to predefined increments, resulting in a slightly letterboxed interface.[51]
As of 2020, major privacy-focused browsers, including Brave, Firefox, and Tor Browser, built-in anti-fingerprinting defenses, whereas default configurations of Google Chrome provided limited protection.[52]
Offering a spoofed fingerprint
[edit]Spoofing exposed parameters (such as the User-Agent) can reduce fingerprint diversity,[53]: 13 though poorly implemented spoofing may unintentionally make a user more identifiable if the spoofed configuration is rare.[10]: 552
Varying spoofed details across site visits—such as introducing subtle random noise into audio and canvas rendering—reduces fingerprint stability.[7]: 820,823 This randomized fingerprinting defense was integrated into the Brave browser in 2020.[54]
Blocking scripts
[edit]Blocking client-side scripts from third-party or first-party domains (e.g., by disabling JavaScript entirely or using extensions like NoScript) can prevent tracking, though it may break website functionality. A common approach is selective blocking of tracking domains via blocklists (used by ad blockers) or behavior analysis (used by tools like Privacy Badger).[55][20][56][57]
Using multiple browsers
[edit]Using different browsers on the same machine generates distinct browser fingerprints. However, if neither browser is protected against fingerprinting, underlying hardware-level attributes may still allow cross-browser linkability.[58]
See also
[edit]References
[edit]- 1 2 Eckersley P (2010). "How Unique Is Your Web Browser?". In Atallah MJ, Hopper NJ (eds.). Privacy Enhancing Technologies. Lecture Notes in Computer Science. Vol. 6205. Springer Berlin Heidelberg. pp. 1–18. ISBN 978-3-642-14527-8.
- ↑ Cao Y, Li S, Wijmans E (February 2017). (Cross-)Browser Fingerprinting via OS and Hardware Level Features (PDF). 24th Annual Network and Distributed System Security Symposium. San Diego, CA, USA: Internet Society. Archived (PDF) from the original on 2017-03-07. Retrieved 2017-02-28.
- ↑ Alaca F, van Oorschot PC (December 2016). Device Fingerprinting for Augmenting Web Authentication: Classification and Analysis of Methods. 32nd Annual Conference on Computer Security. Los Angeles, CA, USA: Association for Computing Machinery. pp. 289–301. doi:10.1145/2991079.2991091. ISBN 978-1-4503-4771-6.
- 1 2 Steinberg, Joseph (2014-07-23). "You Are Being Tracked Online By A Sneaky New Technology -- Here's What You Need To Know". Forbes. Retrieved 2020-01-30.
- ↑ "User confidence takes a Net loss". InfoWorld. 2005-07-01. Archived from the original on 2015-10-04. Retrieved 2015-10-03.
- ↑ "7 Leading Fraud Indicators: Cookies to Null Values". Simility. 2016-03-10. Archived from the original on 2016-10-03. Retrieved 2016-07-05.
- 1 2 Nikiforakis N, Joosen W, Livshits B (May 2015). PriVaricator: Deceiving Fingerprinters with Little White Lies. WWW '15: The 24th International Conference on World Wide Web. Florence, Italy: International World Wide Web Conferences Steering Committee. pp. 820–830. doi:10.1145/2736277.2741090. ISBN 978-1-4503-3469-3.
- 1 2 Acar G, Juarez M, Nikiforakis N, Diaz C, Gürses S, Piessens F, Preneel B (November 2013). FPDetective: Dusting the Web for Fingerprinters. 2013 ACM SIGSAC Conference on Computer & Communications Security. Berlin, Germany: Association for Computing Machinery. pp. 1129–1140. doi:10.1145/2508859.2516674. ISBN 978-1-4503-2477-9.
- 1 2 3 Abgrall E, Le Traon Y, Monperrus M, Gombault S, Heiderich M, Ribault A (2012-11-20). "XSS-FP: Browser Fingerprinting using HTML Parser Quirks". arXiv:1211.4812 [cs.CR].
- 1 2 3 4 5 6 Nikiforakis N, Kapravelos A, Joosen W, Kruegel C, Piessens F, Vigna G (May 2013). Cookieless Monster: Exploring the Ecosystem of Web-Based Device Fingerprinting. 2013 IEEE Symposium on Security and Privacy. Berkeley, CA, USA: IEEE. pp. 541–555. doi:10.1109/SP.2013.43. ISBN 978-0-7695-4977-4.
- ↑ "EFF's Top 12 Ways to Protect Your Online Privacy". Electronic Frontier Foundation. 2002-04-10. Archived from the original on 2010-02-04. Retrieved 2010-01-28.
- ↑ "MSIE clientCaps "isComponentInstalled" and "getComponentVersion" registry information leakage". CERT Uni-Stuttgart. 2003-11-03. Archived from the original on 2011-06-12. Retrieved 2010-01-28.
- 1 2 Kohno T, Broido A, Claffy K (2005-03-01). "Remote Physical Device Detection". University of Washington. Archived from the original on 2010-01-10. Retrieved 2010-01-28.
- ↑ "About Panopticlick". eff.org. Electronic Frontier Foundation.
- ↑ Eckersley, Peter (2010-05-17). "How Unique Is Your Web Browser?" (PDF). Electronic Frontier Foundation. Archived (PDF) from the original on 2016-03-09. Retrieved 2016-04-13.
- 1 2 3 4 Laperdrix P, Bielova N, Baudry B, Avoine G (2019). "Browser Fingerprinting: A survey". arXiv:1905.01051 [cs.CR].
- 1 2 Angwin, Julia (2014-07-21). "Meet the Online Tracking Device That is Virtually Impossible to Block". ProPublica. Retrieved 2020-01-30.
- 1 2 3 Mowery K, Shacham H (2012). Pixel Perfect: Fingerprinting Canvas in HTML5 (PDF) (Technical report). University of California, San Diego. Retrieved 2020-01-21.
- 1 2 3 Acar G, Eubank C, Englehardt S, Juarez M, Narayanan A, Diaz C (November 2014). The Web Never Forgets: Persistent Tracking Mechanisms in the Wild. 2014 ACM SIGSAC Conference on Computer & Communications Security. Scottsdale, AZ, USA: Association for Computing Machinery. pp. 674–689. doi:10.1145/2660267.2660347. ISBN 978-1-4503-2957-6.
- 1 2 Davis, Wendy (2014-07-21). "EFF Says Its Anti-Tracking Tool Blocks New Form Of Digital Fingerprinting". MediaPost. Retrieved 2014-07-21.
- ↑ Knibbs, Kate (2014-07-21). "What You Need to Know About the Sneakiest New Online Tracking Tool". Gizmodo. Retrieved 2020-01-30.
- ↑ "meta: tor uplift: privacy.resistFingerprinting". GitHub. 2017-06-11. Retrieved 2018-07-06.
- ↑ "Firefox's protection against fingerprinting". Mozilla Support. Retrieved 2018-07-06.
- ↑ "Firefox 42.0 release notes". Mozilla. 2015-11-03. Retrieved 2018-07-06.
- ↑ "Apple introduces macOS Mojave". Apple Inc. 2018-06-04. Retrieved 2018-07-06.
- ↑ "Firefox 69.0 release notes". Mozilla. 2019-09-03. Retrieved 2020-01-21.
- ↑ Vastel A, Laperdrix P, Rudametkin W, Rouvoy R (May 2018). FP-STALKER: Tracking Browser Fingerprint Evolutions. 2018 IEEE Symposium on Security and Privacy. San Francisco, CA, USA: IEEE. pp. 14–31. doi:10.1109/SP.2018.00008.
- ↑ "Chatter on the Wire: A look at DHCP traffic" (PDF). Archived (PDF) from the original on 2014-08-11. Retrieved 2010-01-28.
- ↑ "Wireless Device Driver Fingerprinting" (PDF). Sandia National Laboratories. Archived from the original (PDF) on 2009-05-12. Retrieved 2010-01-28.
- ↑ "Chatter on the Wire: A look at excessive network traffic and what it can mean to network security" (PDF). Archived from the original (PDF) on 2014-08-28. Retrieved 2010-01-28.
- ↑ Sjosten A, Hedin D, Sabelfeld A (2021). EssentialFP: Exposing the Essence of Browser Fingerprinting (PDF). Chalmers University of Technology. Retrieved 2021-07-27.
- ↑ "User-Agent - HTTP". MDN Web Docs. 2023-04-10. Retrieved 2023-05-01.
- ↑ Andersen, Aaron (2010-09-03). "History of the browser user-agent string". WebAIM. Retrieved 2023-04-10.
- 1 2 3 Unger T, Mulazzani M, Frühwirt D, Huber M, Schrittwieser S, Weippl E (September 2013). SHPF: Enhancing HTTP(S) Session Security with Browser Fingerprinting. 2013 International Conference on Availability, Reliability and Security. Regensburg, Germany: IEEE. pp. 255–261. doi:10.1109/ARES.2013.33. ISBN 978-0-7695-5008-4.
- 1 2 Fiore U, Castiglione A, De Santis A, Palmieri F (September 2014). Countering Browser Fingerprinting Techniques: Constructing a Fake Profile with Google Chrome. 17th International Conference on Network-Based Information Systems. Salerno, Italy: IEEE. pp. 353–360. doi:10.1109/NBiS.2014.102. ISBN 978-1-4799-4224-4.
- 1 2 Takei N, Saito T, Takasu K, Yamada T (November 2015). Web Browser Fingerprinting Using Only Cascading Style Sheets. 10th International Conference on Broadband and Wireless Computing, Communication and Applications. Krakow, Poland: IEEE. pp. 57–63. doi:10.1109/BWCCA.2015.105. ISBN 978-1-4673-8315-8.
- ↑ Mulazzani M, Reschl P, Huber M, Leithner M, Schrittwieser S, Weippl E (2013). Fast and Reliable Browser Identification with JavaScript Engine Fingerprinting (PDF). SBA Research. Retrieved 2020-01-21.
- ↑ Mowery K, Bogenreif D, Yilek S, Shacham H (2011). Fingerprinting Information in JavaScript Implementations (PDF) (Technical report). University of California, San Diego. Retrieved 2020-01-21.
- 1 2 Upathilake R, Li Y, Matrawy A (July 2015). A classification of web browser fingerprinting techniques. 7th International Conference on New Technologies, Mobility and Security. Paris, France: IEEE. pp. 1–5. doi:10.1109/NTMS.2015.7266460. ISBN 978-1-4799-8784-9.
- ↑ Starov O, Nikiforakis N (May 2017). XHOUND: Quantifying the Fingerprintability of Browser Extensions. 2017 IEEE Symposium on Security and Privacy. San Jose, CA, USA: IEEE. pp. 941–956. doi:10.1109/SP.2017.18. ISBN 978-1-5090-5533-3.
- ↑ Sanchez-Rola I, Santos I, Balzarotti D (August 2017). Extension Breakdown: Security Analysis of Browsers Extension Resources Control Policies. 26th USENIX Security Symposium. Vancouver, BC, Canada: USENIX Association. pp. 679–694. ISBN 978-1-931971-40-9.
- 1 2 Kaur N, Azam S, Kannoorpatti K, Yeo KC, Shanmugam B (January 2017). Browser Fingerprinting as user tracking technology. 11th International Conference on Intelligent Systems and Control. Coimbatore, India: IEEE. pp. 107–112. doi:10.1109/ISCO.2017.7855963. ISBN 978-1-5090-2717-0.
- 1 2 3 4 5 6 Al-Fannah NM, Li W (2017). "Not All Browsers are Created Equal: Comparing Web Browser Fingerprintability". In Obana S, Chida K (eds.). Advances in Information and Computer Security. Lecture Notes in Computer Science. Vol. 10418. Springer International Publishing. pp. 105–120. arXiv:1703.05066. ISBN 978-3-319-64200-0.
- 1 2 Olejnik L, Castelluccia C, Janc A (July 2012). Why Johnny Can't Browse in Peace: On the Uniqueness of Web Browsing History Patterns. 5th Workshop on Hot Topics in Privacy Enhancing Technologies. Vigo, Spain: INRIA. Retrieved 2020-01-21.
- ↑ "Privacy and the :visited selector". MDN Web Docs. 2023-02-21. Retrieved 2023-05-01.
- ↑ Fifield D, Egelman S (2015). "Fingerprinting Web Users Through Font Metrics". In Böhme R, Okamoto T (eds.). Financial Cryptography and Data Security. Lecture Notes in Computer Science. Vol. 8975. Springer Berlin Heidelberg. pp. 107–124. doi:10.1007/978-3-662-47854-7_7. ISBN 978-3-662-47854-7.
- ↑ Obaidat, Muath (2020). "Canvas Deceiver - A New Defense Mechanism Against Canvas Fingerprinting". Journal of Systemics, Cybernetics and Informatics. 18 (6): 66–74.
- ↑ Saito T, Yasuda K, Ishikawa T, Hosoi R, Takahashi K, Chen Y, Zalasiński M (July 2016). Estimating CPU Features by Browser Fingerprinting. 10th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing. Fukuoka, Japan: IEEE. pp. 587–592. doi:10.1109/IMIS.2016.108. ISBN 978-1-5090-0984-8.
- ↑ Olejnik L, Acar G, Castelluccia C, Diaz C (2016). "The Leaking Battery". In Garcia-Alfaro J, Navarro-Arribas G, Aldini A, Martinelli F, Suri N (eds.). Data Privacy Management, and Security Assurance. Lecture Notes in Computer Science. Vol. 9481. Springer, Cham. pp. 254–263. doi:10.1007/978-3-319-29883-2_18. ISBN 978-3-319-29883-2.
- ↑ Englehardt S, Narayanan A (October 2016). Online Tracking: A 1-million-site Measurement and Analysis. 2016 ACM SIGSAC Conference on Computer & Communications Security. Vienna, Austria: Association for Computing Machinery. pp. 1388–1401. doi:10.1145/2976749.2978313. ISBN 978-1-4503-4139-4.
- ↑ Cimpanu, Catalin (2019-03-06). "Firefox to add Tor Browser anti-fingerprinting technique called letterboxing". ZDNet. Retrieved 2022-06-10.
- ↑ Sankin, Aaron (2020-09-22). "I Scanned the Websites I Visit with Blacklight, and It's Horrifying. Now What?". The Markup. Retrieved 2026-01-03.
- ↑ Yen TF, Xie Y, Yu F, Yu R, Abadi M (February 2012). Host Fingerprinting and Tracking on the Web: Privacy and Security Implications (PDF). 19th Annual Network and Distributed System Security Symposium. San Diego, CA, USA: Internet Society. Retrieved 2020-01-21.
- ↑ "What's Brave Done For My Privacy Lately? Episode #3: Fingerprint Randomization". Brave Software. 2020-03-06. Retrieved 2021-02-15.
- ↑ Merzdovnik G, Huber M, Buhov D, Nikiforakis N, Neuner S, Schmiedecker M, Weippl E (April 2017). Block Me If You Can: A Large-Scale Study of Tracker-Blocking Tools. 2017 IEEE European Symposium on Security and Privacy. Paris, France: IEEE. pp. 319–333. doi:10.1109/EuroSP.2017.26. ISBN 978-1-5090-5762-7.
- ↑ Kirk, Jeremy (2014-07-25). "'Canvas fingerprinting' online tracking is sneaky but easy to halt". PC World. Retrieved 2014-08-09.
- ↑ Smith, Chris (2014-07-23). "Adblock Plus: We can stop canvas fingerprinting, the 'unstoppable' new browser tracking technique". BGR. PMC. Archived from the original on 2014-07-28.
- ↑ Newman, Drew (2007). "The Limitations of Fingerprint Identifications". Criminal Justice. 22 (1): 36–41.
Further reading
[edit]- Fietkau, Julian (2020-12-28). "The Elephant In The Background: Empowering Users Against Browser Fingerprinting". Chaos Communication Congress 2020.
- Angwin, Julia; Valentino-DeVries, Jennifer (2010-11-30). "Race Is On to 'Fingerprint' Phones, PCs". The Wall Street Journal. Retrieved 2018-07-10.
- Segal, Ory; Fridman, Aharon; Shuster, Elad (2017-06-05). Passive Fingerprinting of HTTP/2 Clients (PDF) (Technical report). BlackHat Europe. Retrieved 2022-02-09.
External links
[edit]- Panopticlick by the Electronic Frontier Foundation
- Am I Unique by INRIA and INSA Rennes