Forgot your password?

typodupeerror
Privacy Your Rights Online

EFF Says Forget Cookies, Your Browser Has Fingerprints 175

Posted by CmdrTaco
from the you-are-not-unique dept.
alphadogg writes "Even without cookies, popular browsers such as Internet Explorer and Firefox give websites enough information to get a unique picture of their visitors about 94 percent of the time, according to research compiled over the past few months by the Electronic Frontier Foundation. [The Research] puts quantitative assessment on something that security gurus have known about for years, said Peter Eckersley, the EFF senior staff technologist who did the research. He found that configuration information — data on the type of browser, operating system, plugins, and even fonts installed — can be compiled by websites to create a unique portrait of most visitors. This means that most Internet users are a lot less anonymous than they believe, Eckersley said. 'Even if you turn off cookies and you use a proxy to hide your IP address, you could still be tracked,' he said."
This discussion has been archived. No new comments can be posted.

EFF Says Forget Cookies, Your Browser Has Fingerprints

Comments Filter:
  • by IYagami (136831) on Tuesday May 18 2010, @09:40AM (#32252022)

    From TFA:

    "There are some effective countermeasures, however. A uniquely identifiable IDG News Service Windows XP computer running Firefox could not be identified with the NoScript [noscript.net] safe browsing extension turned on. Adding the Tor [torproject.org] Internet anonymization software also works, Eckersley said."

  • Original ./ article (Score:5, Informative)

    by Mouldy (1322581) on Tuesday May 18 2010, @09:41AM (#32252026)
  • Old News (Score:1, Informative)

    by ronmon (95471) on Tuesday May 18 2010, @09:41AM (#32252036)
    This was covered in January [slashdot.org].
  • Don't worry (Score:5, Informative)

    by mangu (126918) on Tuesday May 18 2010, @09:48AM (#32252108)

    All you have to do is change your fingerprint to "Googlebot/2.1 (+http://www.googlebot.com/bot.html)". OK, perhaps this needs updating, but you get the general idea.

    You'll be amazed at the information some sites will be willing to give you. Even paysites will let you in for free if they believe you are Google.

  • by fuzzyfuzzyfungus (1223518) on Tuesday May 18 2010, @10:00AM (#32252254) Journal
    The trouble is, you only need to fuck up once(or, perhaps more realistically, a few times to let the algorithms bump their confidence in the ID high enough) for that information to become personally identifiable. And, once gathered, a body of "non-personally identifiable" information can persist for a time limited only by the plummeting costs of storage and can, at any future time, be linked with enough new data to make it personally identifiable.

    Some percentage, varying by person(and by whether or not your ISP is selling you out to anybody like Phorm), of site visits are personally identifying with a fairly high degree of confidence. For a substantial number of people, that's probably just facebook. In other cases, patterns of activity across a few websites make inferring your identity with fairly high confidence reasonably plausible. Because things like 3rd-party ad networks and whatever "I can't believe its not beacon" tech facebook is using today, have cross site reach, often remarkably broad, it is by no means unrealistic to expect that, over time, at least one of your personally identifiable visits or visit clusters will overlap with the reach of one or more ad networks with extensive "non-personally identifiable" knowledge of what your browser fingerprint has been up to. At that point, the previously "non-personally identifiable" is suddenly personally identified.

    Most people aren't even paying attention. Even the ones that are are likely imperfect in their execution, and keeping up with the scope and sophistication of what a competent data-miner could infer would practically be a full time job. Unless you are a truly bland person, you can probably be identified with fair confidence on surprisingly little data. Worse, as TFA notes, a lot of the common "privacy" measures and extensions and so forth actually make your browser substantially more unusual than it would otherwise be.
  • Cookies (Score:4, Informative)

    by chipperdog (169552) on Tuesday May 18 2010, @10:02AM (#32252260) Homepage
    Cookies are at least a "honest" way to track. you can easily see them in your cookie jar (or whatever term is used by your browser), and you have at least some information about who wrote it. Cookies are not always bad - hidden images, browser/OS fingerprinting, and other 'hidden' means are much worse for privacy.
  • BFD (Score:4, Informative)

    by rwa2 (4391) * on Tuesday May 18 2010, @10:07AM (#32252298) Homepage Journal

    Don't let the mass media scare you.

    Step 1: Install Wireshark [wireshark.org]
    Step 2: Leave Wireshark running and observe what kind of information people are gleaning from you over the network. It's educational!
    Step 3: There is no step 3.

    I don't see why people expect anonymity on the internet any more than they do driving around in their car with the license plate showing.
    I just pretend there's an FBI agent always watching over my shoulder. His name is Fred. I explain to him everything I'm doing.

  • Re:Old News (Score:5, Informative)

    by caerwyn (38056) on Tuesday May 18 2010, @10:13AM (#32252370)

    This article relates to the publishing of the *results* of the experiment announced in the first article. This is not (for once) a dup. Hence the "compiled over the past few months" bit in the summary.

  • Re:Don't worry (Score:5, Informative)

    by darthflo (1095225) on Tuesday May 18 2010, @10:16AM (#32252408)

    That's just the User-Agent string. The actual fingerprint consists of that and a big bunch of other headers your browser sends out with each request. Language, preferred encoding, plugins; screen resolution, your installed fonts and so on.Changing your standard browser's user-agent to something like you quoted above is a surefire way to be even more unique.
    Check the panopticlick page [eff.org] for your details. Keep in mind their "bits of identifying information" only apply to a single header. A bit of work and identifying over all of these fields is easily done. Throw in a bit of extra work and users can be singled out even after they change one or two of 'em.
    Summing all the lines together, I can get some 70 bits of identifying info out of my (almost worst-case) setup: Ubuntu 9.10 running a snapshot of Opera 10.54 with a couple of extra fonts and a weird screen resolution.Cut away user-agent and plugins and we're still at some 35, more than IPv4 addresses out there.

  • Re:no shit (Score:3, Informative)

    by grumbel (592662) <grumbel@gmx.de> on Tuesday May 18 2010, @10:28AM (#32252584) Homepage

    It goes far beyond just the OS. With Flash for example you can get a list of all the fonts the user has installed. If you ever installed some custom fonts, chances are you are close to 100% uniquely identifiable. You can also trace which pages the user has visited with some dirty CSS tricks (load an image in a:visited {}, track that, and you know if the user has visited the link).

    I seriously doubt that most users are away of that trickery on how much information it is really giving away.

  • by jittles (1613415) on Tuesday May 18 2010, @12:03PM (#32253858)

    Try allowing Noscript on that site? I was listed as 1 in 4 too until I enabled scripting on that website and ran the test again. Then I came out to be 1 in 1,000,000. I'd say that's more unique than I'd like to be.

    Test yourself here [eff.org] if you haven't already.

Why not go out on a limb? Isn't that where the fruit is?

Working...