Results 1 to 7 of 7

Thread: New method of Internet tracking spreads: Canvas-Fingerprinting

  1. #1
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default New method of Internet tracking spreads: Canvas-Fingerprinting

    The tracking technology "Canvas-Fingerprinting" makes Internet users glass human. Researchers say one can hardly protecting against it. The new tracking technique can hardly be noticed by the average user. Only switching off the Java script function in browser would help, but then many pages not work properly.

    Especially the company of AddThis is responsible for the dissemination of the disputed technology, which Facebook and Twitter buttons will provide on 13 million Web pages. They hid the canvas-fingerprinting technique at least on a part of the Internet pages between the popular buttons...

    See also:

  2. The Following 4 Users Say Thank You to jwoegerbauer For This Useful Post:

    Bigfella237 (25-07-14),OSIRUS (24-07-14),pheggie (23-07-14),tristen (24-07-14)



Look Here ->
  • #2
    Senior Member
    Uncle Fester's Avatar
    Join Date
    Jan 2008
    Location
    Commonly found in a pantry or the bottom of a fridge, searching for grains, fermented or distilled
    Posts
    6,412
    Thanks
    2,292
    Thanked 4,420 Times in 2,521 Posts
    Rep Power
    2048
    Reputation
    81898

    Default

    Quote Originally Posted by jwoegerbauer View Post
    Researchers say one can hardly protecting against it. The new tracking technique can hardly be noticed by the average user. Only switching off the Java script function in browser would help, but then many pages not work properly.
    There is a Firefox plugin called Privacy Badger that is supposed to block this.
    I don't know about Evercookies though. They will keep popping up like a virus.
    Update: A deletion of features that work well and ain't broke but are deemed outdated in order to add things that are up to date and broken.
    Compatibility: A word soon to be deleted from our dictionaries as it is outdated.
    Humans: Entities that are not only outdated but broken... AI-self-learning-update-error...terminate...terminate...

  • #3
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default

    Tools that block tracking cookies won't work for Canvas-fingerprinting. Canvas-fingerprinting uses the HTML5 canvas element. If your browser displays HTML5, it is going to work regardless of the extensions and blockers you have installed. That's the point.

    As one can read at EFF's site:
    Does Privacy Badger prevent fingerprinting?

    Currently, Privacy Badger does not prevent browser fingerprinting, of the sort we demonstrated with the Panopticlick project. But we will be adding fingerprinting countermeasures in a future update!
    So Privacy Badger - an extension for Chrome and Firefox - currently isn't helpful at all.
    Last edited by jwoegerbauer; 24-07-14 at 01:27 AM.

  • #4
    Senior Member
    SCADA's Avatar
    Join Date
    Jan 2011
    Location
    Country Vic.
    Posts
    530
    Thanks
    113
    Thanked 520 Times in 197 Posts
    Rep Power
    251
    Reputation
    3635

    Default

    How about "NoScript" (Firefox add-on)? Yes it blocks JavaScript but the base page still loads and then it lets you choose what scripts to run. Yes it can be a pain but I guess it all depends on how you value your browsing experience Vs privacy. Its interesting to run just to see what trys to load.
    If a man says something in a forest and there is no woman there to hear it, will that which has been said still be wrong?

    Some people are like clouds. When they go away its a beautiful day.

  • #5
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default

    FYI:


    Which web-sites currently are using Canvas-Fingerprinting, are listed here:



    At time of this writing 5,619 sites!

    So you could check sites against that list, but it may not be updated frequently enough to catch new offenders.


    HINT:

    : I've done so.
    Last edited by jwoegerbauer; 24-07-14 at 08:27 PM. Reason: HINT added

  • #6
    Senior Member

    Join Date
    Apr 2012
    Location
    14 Wombat Cres, Goanna Heights NSW
    Posts
    1,409
    Thanks
    734
    Thanked 1,151 Times in 577 Posts
    Rep Power
    603
    Reputation
    20583

    Default

    Quote Originally Posted by jwoegerbauer View Post
    HINT:

    : I've done so.
    I believe that rather than adding 5,619 URLs from that list to your HOSTS file, you can just add the Fingerprinting Domain URLs (there are only 23 unique Domain URLs) as follows (I've already added the 0.0.0.0 for you):

    Code:
    0.0.0.0 49winners.com
    0.0.0.0 addthis.com
    0.0.0.0 amazonaws.com
    0.0.0.0 chatrooms.org.in
    0.0.0.0 cloudflare.com
    0.0.0.0 cloudfront.net
    0.0.0.0 cya2.net
    0.0.0.0 domainsigma.com
    0.0.0.0 freecall.com
    0.0.0.0 freevoipdeal.com
    0.0.0.0 hediyera.com
    0.0.0.0 insnw.net
    0.0.0.0 kitcode.net
    0.0.0.0 ligatus.com
    0.0.0.0 meinkauf.at
    0.0.0.0 nonoh.net
    0.0.0.0 pof.com
    0.0.0.0 rackcdn.com
    0.0.0.0 revtrax.com
    0.0.0.0 ringier.cz
    0.0.0.0 shorte.st
    0.0.0.0 vcmedia.vn
    0.0.0.0 voipbuster.com
    I think that should stop the other five thousand-odd URLs from being able to contact the third parties above, thereby disabling fingerprinting, but please correct me if I have it wrong?

    Andrew

  • The Following 2 Users Say Thank You to Bigfella237 For This Useful Post:

    jwoegerbauer (25-07-14),tristen (25-07-14)

  • #7
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default

    Not sure whether your proposal will do the job. Will test it, ASAP.

    UPDATE:

    1. Started FF, loaded youporn.com (IP: 31.192.116.24)
    2. Privacy Badger : No trackers found
    3. Investigated page's content: No occurrence of term AddThis (neither in upper nor in lower case)
    4. Closed FF

    Nevertheless, I'll keep you updated.

    UPDATE 2:

    1. Started WireShark
    2 Started FF, loaded youporn.com (IP: 31.192.116.24)
    3. Closed FF
    4. Closed WireShark
    5. Walked WireShark's TCP/IP packets protocolled: AddThis.com (IP: 208.49.103.220) wasn't to find in

    UPDATE 3:

    As in between I have read, YouPorn, according to their own, after becoming aware of the Canvas-Fingerprinting test, threw AddThis from their site.

    So I've wasted my time.
    Last edited by jwoegerbauer; 25-07-14 at 05:47 PM. Reason: UPDATE3 added

  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •