Live data from Hacker News

Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

fingerprintjs.com

181–190 of 213 posts

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#181

How unique are these ids really? I imagine certain apps will be very commonly installed as well as certain groups of apps? So it's not 32bits of information. Still more information to add to the finger printing pile.. I wish we could find a way to deal with this risk that's not simply disabling all kinds of functionality. Browser APIs seem to be suffering more and more by limitations to prevent finger printing.

We will make a detailed report with some statistics, after the vulnerability is fixed

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#182

Aside from profiling, can these custom URL handlers also be used as an attack vector on other installed applications? That is, assuming any of those happens to be installed and have a (input sanitation related) vulnerability. Maybe I'm just seeing ghosts here. But the idea of a web site pushing malicious links to whatever software may also be installed on the same machine, isn't a very comforting thought.

This is possible in theory.

For example, Safari opens the Apple Music without any user prompt. The app itself is designed to handle deep links (such as opening an album or starting the song).

That means you can perform a deep link forgery, in order to force the app to perform unwilling action without user confirmation.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#183

It seem that Vivaldi have better protection against this than the rest. Running in Vivaldi will cause the demo down to crawl because I think it was trying to find the apps. It detected all of the apps but it failed to appear in the detected list. MacOS Big Sur Apple Silicon if you are wondering

We haven't tested Vivaldi so far and the demo is not designed for it. However that doesn't mean Vivaldi is secure against this attack.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#184

Tested on Windows and got two different identifiers. Firefox detected Postman, Chrome did not.

Thanks for the feedback. The accuracy is the main issue on Chrome. See also https://news.ycombinator.com/item?id=27147876

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#185
post #121

Earlier quoted context omitted.

The exploit was tested in Safari 14.0.3 and 14.1 on MacBook M1 and MacBook Pro. What version do you have?

14.1 on an M1 MBP.

Wow, that's weird.

The internet connection may be the issue here, or the custom configuration on Safari.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#186

Earlier quoted context omitted.

Note: I just tried the demo [0], and no obvious prompt showed up, instead it was a tiny window [1] on the bottom right of my screen, which only showed up for a couple seconds and is easy to miss. [0]: https://schemeflood.com/ [1]: https://imgur.com/a/YqbbfPt

I have FF set up to open all popups in new tabs. That makes it a lot more noticeable ;)

Which setting does this? Is it „Open links in tabs instead of windows“?

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#187
post #123

Earlier quoted context omitted.

You also have none of the other tested applications; I presume most of them have Word.

> You also have none of the other tested applications; I presume most of them have Word. What makes you assume I do not have Office installed? Instead of, say, considering the possibility that the fingerprinting may not be that good.

The main clue is that you are not noting that it is misdetecting anything, just that you think what it is that it is detecting is not very special.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#188
Interesting to see that browsers are still vulnerable to this; I know iOS had a very similar problem a while back (apps would check for the existence of hundreds of other applications by checking whether they could open those URL schemes) and Apple clamped down on it quickly by restricting the number of queries that could be made.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#189

Earlier quoted context omitted.

Does Skype no longer do POTS calls?

If you pay them. I say it’s not going to succeed specifically because I haven’t.

Right, but if you're not on a device with a built in phone connection then it's reasonable to open skype and similar apps that can do phone calls (even if they cost money).

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#190

I'm going to close a website as soon as I get an unprompted popup that says "Firefox is trying to open Slack." It's clever but somewhat obvious (in both a to-the-user-that-its-happening and a "well of course it's possible" sense). So it's cute, but not practical, and I won't lose sleep over it. I'll probably be more inconvenienced by the mitigations that will surely result that make it that much more painful to actua…

Note: I just tried the demo [0], and no obvious prompt showed up, instead it was a tiny window [1] on the bottom right of my screen, which only showed up for a couple seconds and is easy to miss. [0]: https://schemeflood.com/ [1]: https://imgur.com/a/YqbbfPt

Every time I run the demo, it gives me a different result? This is just on the same browser (Firefox), it generates a different code every time and claims I have random applications installed that I don't (the only one I have on that list is steam, which it does seems to consistently report at least). Not sure if one of my extensions is interfering with it.
Post reply on HN