I’m the author. The accuracy can be low because of: - Custom browser settings or flags - The demo was designed for the default setup, but that doesn’t mean your custom setup is not vulnerable. - Poorly performant hardware (including virtual machines) - Some timings are just hardcoded and were tested on the MacBook hardware. - Fullscreen mode - The demo will work faster and more accurate if the browser is not in a ful…
Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
91–100 of 213 posts
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#92Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#93On Linux: - in Firefox, it detected Epic Games Telegram Discord Battle.net Xcode NordVPN Sketch Teamviewer Microsoft Word WhatsApp Postman Adobe Messenger Figma Hotspot Shield ExpressVPN Notion iTunes, none of which I have installed. It didn't detect VSCode though I have VSCodium. - On Chromium, it warned it would not work well on Chrome on Linux. It incorrectly detected all the apps. It seems that the browser would…
Security through obscurity does it again!
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#94> We have generated your identifier based on 1 applications you have installed.
Skype
Then it told me I am ninety-something percent unique...I find that odd because pretty much every Windows machine has Skype.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#95Results differ wildly between browsers and even between runs within the same browser. It detects application I do not have installed and does not detect applications I do have installed. For instance it detects iTunes, XCode and Sketch, but they are Mac-only application and I am on Windows. Honestly, I believe it does not work at all.
Thanks for testing it on Windows. We mostly tested it on MacOS Big Sur because all devs on the team have that OS. With Windows different timings might be needed, we'll check into it tomorrow.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#96Curious: > We have generated your identifier based on 1 applications you have installed. Skype Then it told me I am ninety-something percent unique... I find that odd because pretty much every Windows machine has Skype.
You are likely relatively unique because you only have Skype installed, whereas a lot of visitors will have more applications out of the list. Someone who has no applications on the list installed may be even more unique, for example.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#97Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#98Did it on Chrome, Firefox, and Safari and got the same code on all three. In all three it failed to detect some apps, but the same ones failed each time. When I did it in Safari it actually caused Apple Music to open. When I did it in Chrome it popped up a small square window where I could see it doing it's thing. Firefox was the only one where it was silent. But still, that's an interesting hack. Very clever.
Interesting. In my case I saw the little pop up window in all three browsers. Otherwise same results though.
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#99It's clever but somewhat obvious (in both a to-the-user-that-its-happening and a "well of course it's possible" sense).
So it's cute, but not practical, and I won't lose sleep over it. I'll probably be more inconvenienced by the mitigations that will surely result that make it that much more painful to actually launch a URL scheme, sadly.
I've actually never checked the "Always open Slack for slack:// links" or similar checkboxes, precisely out of predicting shenanigans like this would happen eventually :)
I wouldn't be too offended if browsers changed the way they handle schemes: always open a "how would you like to handle this link" dialog for any protocol (even if unhandled - like how Windows shows the "how would you like to open this file" dialog), to disguise whether the protocol is handled or not. Not sure I have the answer for user convenience though if someone is used to things automatically opening. That's the "inconvenience" aspect of any potential mitigation, we probably have to get rid of that "remember this choice" checkbox (well, my point is that "have to" is debatable here).
Re: Vulnerability allows cross-browser tracking in Chrome, Firefox, Safari, and Tor
#100Linux/Chrome