Featured Research

from universities, journals, and other organizations

Several top websites use device fingerprinting to secretly track users

Date:
October 10, 2013
Source:
KU Leuven
Summary:
A new study has uncovered that 145 of the Internet’s 10,000 top websites track users without their knowledge or consent. The websites use hidden scripts to extract a device fingerprint from users’ browsers. Device fingerprinting circumvents legal restrictions imposed on the use of cookies and ignores the Do Not Track HTTP header. The findings suggest that secret tracking is more widespread than previously thought.

A new study by KU Leuven-iMinds researchers has uncovered that 145 of the Internet's 10,000 top websites track users without their knowledge or consent. The websites use hidden scripts to extract a device fingerprint from users' browsers. Device fingerprinting circumvents legal restrictions imposed on the use of cookies and ignores the Do Not Track HTTP header. The findings suggest that secret tracking is more widespread than previously thought.

Device fingerprinting, also known as browser fingerprinting, is the practice of collecting properties of PCs, smartphones and tablets to identify and track users. These properties include the screen size, the versions of installed software and plugins, and the list of installed fonts. A 2010 study by the Electronic Frontier Foundation (EFF) showed that, for the vast majority of browsers, the combination of these properties is unique, and thus functions as a 'fingerprint' that can be used to track users without relying on cookies. Device fingerprinting targets either Flash, the ubiquitous browser plugin for playing animations, videos and sound files, or JavaScript, a common programming language for web applications.

This is the first comprehensive effort to measure the prevalence of device fingerprinting on the Internet. The team of KU Leuven-iMinds researchers analysed the Internet's top 10,000 websites and discovered that 145 of them (almost 1.5%) use Flash-based fingerprinting. Some Flash objects included questionable techniques such as revealing a user's original IP address when visiting a website through a third party (a so-called proxy).

The study also found that 404 of the top 1 million sites use JavaScript-based fingerprinting, which allows sites to track non-Flash mobile phones and devices. The fingerprinting scripts were found to be probing a long list of fonts -- sometimes up to 500 -- by measuring the width and the height of secretly-printed strings on the page.

Do Not Track

The researchers identified a total of 16 new providers of device fingerprinting, only one of which had been identified in prior research. In another surprising finding, the researchers found that users are tracked by these device fingerprinting technologies even if they explicitly request not to be tracked by enabling the Do Not Track (DNT) HTTP header.

The researchers also evaluated Tor Browser and Firegloves, two privacy-enhancing tools offering fingerprinting resistance. New vulnerabilities -- some of which give access to users' identity -- were identified.

Device fingerprinting can be used for various security-related tasks, including fraud detection, protection against account hijacking and anti-bot and anti-scraping services. But it is also being used for analytics and marketing purposes via fingerprinting scripts hidden in advertising banners and web widgets.

To detect websites using device fingerprinting technologies, the researchers developed a tool called FPDetective. The tool crawls and analyses websites for suspicious scripts. This tool will be freely available at http://homes.esat.kuleuven.be/~gacar/fpdetective/ for other researchers to use and build upon.

The findings will be presented at the 20th ACM Conference on Computer and Communications Security this November in Berlin.


Story Source:

The above story is based on materials provided by KU Leuven. Note: Materials may be edited for content and length.


Cite This Page:

KU Leuven. "Several top websites use device fingerprinting to secretly track users." ScienceDaily. ScienceDaily, 10 October 2013. <www.sciencedaily.com/releases/2013/10/131010091427.htm>.
KU Leuven. (2013, October 10). Several top websites use device fingerprinting to secretly track users. ScienceDaily. Retrieved September 15, 2014 from www.sciencedaily.com/releases/2013/10/131010091427.htm
KU Leuven. "Several top websites use device fingerprinting to secretly track users." ScienceDaily. www.sciencedaily.com/releases/2013/10/131010091427.htm (accessed September 15, 2014).

Share This



More Computers & Math News

Monday, September 15, 2014

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Frustration As Drone Industry Outpaces Regulation In U.S.

Frustration As Drone Industry Outpaces Regulation In U.S.

Newsy (Sep. 14, 2014) U.S. firms worry they’re falling behind in the marketplace as the FAA considers how to regulate commercial drones. Video provided by Newsy
Powered by NewsLook.com
iPhone 6 Sales Mark Yet Another Year Of Records, Glitches

iPhone 6 Sales Mark Yet Another Year Of Records, Glitches

Newsy (Sep. 13, 2014) Customers looking to preorder the iPhone 6 on Friday experienced a few hiccups thanks to record demand for the device overnight. Video provided by Newsy
Powered by NewsLook.com
Is Photo-Sharing App Tiiny Really A Snapchat Competitor?

Is Photo-Sharing App Tiiny Really A Snapchat Competitor?

Newsy (Sep. 13, 2014) Tiiny, a photo-sharing app, is being called a Snapchat competitor. But after testing it ourselves, we'd have to disagree. Video provided by Newsy
Powered by NewsLook.com
Ebola Batters Sierra Leone Economy Too

Ebola Batters Sierra Leone Economy Too

Reuters - Business Video Online (Sep. 12, 2014) The World Health Organisation warns that local health workers in West Africa can't keep up with Ebola - and among those countries hardest hit by the outbreak, the economic damage is coming into focus, too. As David Pollard reports, Sierra Leone admits that growth in one of the poorest economies in the region is taking a beating. Video provided by Reuters
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:

Breaking News:
from the past week

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

    Technology News



    Save/Print:
    Share:

    Free Subscriptions


    Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

    Get Social & Mobile


    Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

    Have Feedback?


    Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
    Mobile: iPhone Android Web
    Follow: Facebook Twitter Google+
    Subscribe: RSS Feeds Email Newsletters
    Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins