Live data from Hacker News

Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

fingerprintjs.com

171–180 of 213 posts

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#171
post #156

Earlier quoted context omitted.

I have FF set up to open all popups in new tabs. That makes it a lot more noticeable ;)

this should be the default behaviour imho - there should never really be a situation where a new window popup is going to be better than a tab.

I have to disagree there. It makes paypal payments really ugly, that is most certainly not what a normal user wants ;)

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#172
post #66
post #12

On Linux: - in Firefox, it detected Epic Games Telegram Discord Battle.net Xcode NordVPN Sketch Teamviewer Microsoft Word WhatsApp Postman Adobe Messenger Figma Hotspot Shield ExpressVPN Notion iTunes, none of which I have installed. It didn't detect VSCode though I have VSCodium. - On Chromium, it warned it would not work well on Chrome on Linux. It incorrectly detected all the apps. It seems that the browser would…

Thanks for testing it on Linux. We only tested it on these browser + OS combinations: https://github.com/fingerprintjs/external-protocol-flooding#...

if you need more info: Firefox 88.0.1 (64 bits), Chromium 90.0.4430.93, on openSUSE Tumbleweed

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#173
post #98

Earlier quoted context omitted.

> When I did it in Chrome it popped up a small square window where I could see it doing it's thing. Interesting. In my case I saw the little pop up window in all three browsers. Otherwise same results though.

I just verified this on my machine and it was able to uniquely identify across Brave browser, Firefox and Epic browser (based on Chromium). I didn't check Safari because that's the browser I use the most and don't want to test on that. The Epic browser one was interesting. That browser comes with a built in proxy for routing connections through other countries. I use it to get around geolocked content and sometimes f…

Firefox somewhat famously doesn't use the same Chromium engine.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#176

> Add a script on a website that will test each application from your list. This means exploitation requires Javascript, right? Tor browser users should have it disabled at all times.

Not in the default configuration

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#177
post #12

On Linux: - in Firefox, it detected Epic Games Telegram Discord Battle.net Xcode NordVPN Sketch Teamviewer Microsoft Word WhatsApp Postman Adobe Messenger Figma Hotspot Shield ExpressVPN Notion iTunes, none of which I have installed. It didn't detect VSCode though I have VSCodium. - On Chromium, it warned it would not work well on Chrome on Linux. It incorrectly detected all the apps. It seems that the browser would…

Yup, it was broken for me too on Linux unless I somehow have managed to install both Xcode and MS Word. :)

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#178

I’m the author. The accuracy can be low because of: - Custom browser settings or flags - The demo was designed for the default setup, but that doesn’t mean your custom setup is not vulnerable. - Poorly performant hardware (including virtual machines) - Some timings are just hardcoded and were tested on the MacBook hardware. - Fullscreen mode - The demo will work faster and more accurate if the browser is not in a ful…

Interesting work. It didn't work between firefox and chromium on my linux desktop, even trying the chromium branch. But my linux desktop already puts me into a pretty small bucket of users to begin with, so someone who's doing this may not see any joy in trying to fix that.

Thanks.

Linux is tricky. Mostly because Chrome opens applications through `xdg-open`. Custom configuration on Firefox may also affect the result.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#179

I’m the author. The accuracy can be low because of: - Custom browser settings or flags - The demo was designed for the default setup, but that doesn’t mean your custom setup is not vulnerable. - Poorly performant hardware (including virtual machines) - Some timings are just hardcoded and were tested on the MacBook hardware. - Fullscreen mode - The demo will work faster and more accurate if the browser is not in a ful…

The issue on Chromium bug tracker is reported by @microsoft.com. So testing on Chromium Edge would be nice.

Edge 90 is also affected. We tested it on Windows 10.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#180

Why does this page declare Safari to be the easiest browser to exploit, when it also says it uses the same technique as it does in Firefox (and does not describe any scheme flooding protection in Firefox)?

Mostly because it took hours to make an exploit on Safari compared to days on Firefox, however the final approach ended up the same. Only Chromium has a built-in scheme anti-flooding protection.
Post reply on HN