Live data from Hacker News

Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

fingerprintjs.com

211–213 of 213 posts

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#211

Earlier quoted context omitted.

It looks like a mitigation might be that in the event you do not have the application installed, to return a "denied" status and send a prompt to the user like "Unknown application protocol". Something like that could still would be susceptible to a timing attack though.

always show the popup, but populate it "later" could work too.

Yes I believe the proper fix would be to always behave as if a popup is showing, independent of weather or not it actually shows.

Through it's maybe slightly more complex as you might need to behave as if the user clicked cancel in a way where a attacker can not easily differentiate it from an actual user clicking cancel.

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#212
post #123

Earlier quoted context omitted.

> You also have none of the other tested applications; I presume most of them have Word. What makes you assume I do not have Office installed? Instead of, say, considering the possibility that the fingerprinting may not be that good.

The main clue is that you are not noting that it is misdetecting anything, just that you think what it is that it is detecting is not very special.

I noted that it only detected Skype and nothing else and that app is installed on all Windows machines these days.

Tried again, same deal:

> That means it is 96.35% unique

Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor

#213
post #17
post #16

Does this actually work correctly for anyone? Got wrong results for Firefox and Chrome on Linux (it warns that Chrome probably won't work). I glanced through the source[0] and my about:config and I noticed I have the dom.block_external_protocol_in_iframes setting enabled. Looks like this could be the mechanism they use? I don't remember enabling it manually. Otherwise, it could be my tiling window manager messing wit…

It seems that it's not very effective in Linux.

Linux Firefox used Schemeflood! v

It's not very effective....

Post reply on HN