Английская Википедия:Canvas fingerprinting

Материал из Онлайн справочника
Перейти к навигацииПерейти к поиску

Шаблон:Short description Canvas fingerprinting is one of a number of browser fingerprinting techniques for tracking online users that allow websites to identify and track visitors using the HTML5 canvas element instead of browser cookies or other similar means.[1] The technique received wide media coverage in 2014[2][3][4][5] after researchers from Princeton University and KU Leuven University described it in their paper The Web never forgets.[6]

Description

Canvas fingerprinting works by exploiting the HTML5 canvas element. As described by Acar et al. in:[6] Шаблон:Quote

Variations in which the graphics processing unit (GPU), or the graphics driver, is installed may cause the fingerprint variation. The fingerprint can be stored and shared with advertising partners to identify users when they visit affiliated websites. A profile can be created from the user's browsing activity, allowing advertisers to target advertise to the user's inferred demographics and preferences.[4][7]

By January 2022, the concept was extended to fingerprinting performance characteristics of the graphics hardware, called Шаблон:Smallcaps by the researchers.[8]

Uniqueness

Since the fingerprint is primarily based on the browser, operating system, and installed graphics hardware, it does not uniquely identify users. In a small-scale study with 294 participants from Amazon's Mechanical Turk, an experimental entropy of 5.7 bits was observed. The authors of the study suggest more entropy could likely be observed in the wild and with more patterns used in the fingerprint. While not sufficient to identify individual users by itself, this fingerprint could be combined with other entropy sources to provide a unique identifier. It is claimed that because the technique is effectively fingerprinting the GPU, the entropy is "orthogonal" to the entropy of previous browser fingerprint techniques such as screen resolution and browser JavaScript capabilities.[9]

Much more unique identification becomes possible with Шаблон:Smallcaps, published in 2022, which was shown to boost tracking duration of individual fingerprints by 67% when used to enhance other methods.[8]

History

In May 2012, Keaton Mowery and Hovav Shacham, researchers at University of California, San Diego, wrote a paper Pixel Perfect: Fingerprinting Canvas in HTML5 describing how the HTML5 canvas could be used to create digital fingerprints of web users.[4][9]

Social bookmarking technology company AddThis began experimenting with canvas fingerprinting early in 2014 as a potential replacement for cookies. 5% of the top 100,000 websites used canvas fingerprinting while it was deployed.[10] According to AddThis CEO Richard Harris, the company has only used data collected from these tests to conduct internal research. Users will be able to install an opt-out cookie on any computer to prevent being tracked by AddThis with canvas fingerprinting.[4]

A software developer writing in Forbes stated that device fingerprinting has been utilized for the purpose of preventing unauthorized access to systems long before it was used for tracking users without their consent.[3]

As of 2014 the technique is widespread in many websites, used by at least a dozen high-profile web ads and user tracking suppliers.[11]

In 2022, the capabilities of canvas fingerprinting were much deepened by taking minute differences between nominally identical units of the same GPU model into account. Those differences are rooted in the manufacturing process, making units more deterministic over time than between identical copies.[8]

Mitigation

Файл:Typical Tor Browser notification of a canvas read attempt.png
Typical Tor Browser notification of a website attempting a canvas read.

Tor Project reference documentation states, "After plugins and plugin-provided information, we believe that the HTML5 Canvas is the single largest fingerprinting threat browsers face today."[12] Tor Browser notifies the user of canvas read attempts and provides the option to return blank image data to prevent fingerprinting.[6] However, Tor Browser is currently unable to distinguish between legitimate uses of the canvas element and fingerprinting efforts, so its warning cannot be taken as proof of a website's intent to identify and track its visitors. Browser add-ons like Privacy Badger,[10] DoNotTrackMe,[13] or Adblock Plus[14] manually enhanced with EasyPrivacy list are able to block third-party ad network trackers and can be configured to block canvas fingerprinting, provided that the tracker is served by a third party server (as opposed to being implemented by the visited website itself).Шаблон:Citation needed Canvas Defender, a browser add-on, spoofs Canvas fingerprints.[15]

The LibreWolf browser project includes technology to block access to the HTML5 canvas by default, only allowing it in specific instances green-lit by the user.

See also

  • Evercookie – a type of browser cookie that is intentionally difficult to delete
  • Local shared object – a persistent browser cookie also known as a Flash cookie
  • Web storage – web application software methods and protocols used for storing data in a web browser

References

Шаблон:Reflist

External links

  1. Шаблон:Cite journal
  2. Ошибка цитирования Неверный тег <ref>; для сносок Knibbs не указан текст
  3. 3,0 3,1 Ошибка цитирования Неверный тег <ref>; для сносок Steinberg не указан текст
  4. 4,0 4,1 4,2 4,3 Ошибка цитирования Неверный тег <ref>; для сносок Angwin не указан текст
  5. Ошибка цитирования Неверный тег <ref>; для сносок Kirk не указан текст
  6. 6,0 6,1 6,2 Ошибка цитирования Неверный тег <ref>; для сносок WebNeverForgets не указан текст
  7. Ошибка цитирования Неверный тег <ref>; для сносок Nikiforakis не указан текст
  8. 8,0 8,1 8,2 Шаблон:Cite journal
  9. 9,0 9,1 Ошибка цитирования Неверный тег <ref>; для сносок Mowery не указан текст
  10. 10,0 10,1 Ошибка цитирования Неверный тег <ref>; для сносок Davis не указан текст
  11. Шаблон:Cite web
  12. Шаблон:Cite web
  13. Ошибка цитирования Неверный тег <ref>; для сносок Kirk2 не указан текст
  14. Шаблон:Cite web
  15. Ошибка цитирования Неверный тег <ref>; для сносок multiloginapp не указан текст