How unique are these ids really? I imagine certain apps will be very commonly installed as well as certain groups of apps? So it's not 32bits of information. Still more information to add to the finger printing pile.. I wish we could find a way to deal with this risk that's not simply disabling all kinds of functionality. Browser APIs seem to be suffering more and more by limitations to prevent finger printing.
Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
181–190 of 213 posts
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#182Aside from profiling, can these custom URL handlers also be used as an attack vector on other installed applications? That is, assuming any of those happens to be installed and have a (input sanitation related) vulnerability. Maybe I'm just seeing ghosts here. But the idea of a web site pushing malicious links to whatever software may also be installed on the same machine, isn't a very comforting thought.
For example, Safari opens the Apple Music without any user prompt. The app itself is designed to handle deep links (such as opening an album or starting the song).
That means you can perform a deep link forgery, in order to force the app to perform unwilling action without user confirmation.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#183It seem that Vivaldi have better protection against this than the rest. Running in Vivaldi will cause the demo down to crawl because I think it was trying to find the apps. It detected all of the apps but it failed to appear in the detected list. MacOS Big Sur Apple Silicon if you are wondering
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#184Tested on Windows and got two different identifiers. Firefox detected Postman, Chrome did not.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#185Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#186Earlier quoted context omitted.
Note: I just tried the demo [0], and no obvious prompt showed up, instead it was a tiny window [1] on the bottom right of my screen, which only showed up for a couple seconds and is easy to miss. [0]: https://schemeflood.com/ [1]: https://imgur.com/a/YqbbfPt
I have FF set up to open all popups in new tabs. That makes it a lot more noticeable ;)
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#187Earlier quoted context omitted.
You also have none of the other tested applications; I presume most of them have Word.
> You also have none of the other tested applications; I presume most of them have Word. What makes you assume I do not have Office installed? Instead of, say, considering the possibility that the fingerprinting may not be that good.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#188Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#189Earlier quoted context omitted.
Does Skype no longer do POTS calls?
If you pay them. I say it’s not going to succeed specifically because I haven’t.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#190I'm going to close a website as soon as I get an unprompted popup that says "Firefox is trying to open Slack." It's clever but somewhat obvious (in both a to-the-user-that-its-happening and a "well of course it's possible" sense). So it's cute, but not practical, and I won't lose sleep over it. I'll probably be more inconvenienced by the mitigations that will surely result that make it that much more painful to actua…
Note: I just tried the demo [0], and no obvious prompt showed up, instead it was a tiny window [1] on the bottom right of my screen, which only showed up for a couple seconds and is easy to miss. [0]: https://schemeflood.com/ [1]: https://imgur.com/a/YqbbfPt