Free Newsletters - Space - Defense - Environment - Energy
..
. Farming News .




CYBER WARS
Several top websites use device fingerprinting to secretly track users
by Staff Writers
Leuven, Belgium (SPX) Oct 15, 2013


File image.

A new study by KU Leuven-iMinds researchers has uncovered that 145 of the Internet's 10,000 top websites track users without their knowledge or consent. The websites use hidden scripts to extract a device fingerprint from users' browsers. Device fingerprinting circumvents legal restrictions imposed on the use of cookies and ignores the Do Not Track HTTP header. The findings suggest that secret tracking is more widespread than previously thought.

Device fingerprinting, also known as browser fingerprinting, is the practice of collecting properties of PCs, smartphones and tablets to identify and track users. These properties include the screen size, the versions of installed software and plugins, and the list of installed fonts.

A 2010 study by the Electronic Frontier Foundation (EFF) showed that, for the vast majority of browsers, the combination of these properties is unique, and thus functions as a 'fingerprint' that can be used to track users without relying on cookies. Device fingerprinting targets either Flash, the ubiquitous browser plugin for playing animations, videos and sound files, or JavaScript, a common programming language for web applications.

This is the first comprehensive effort to measure the prevalence of device fingerprinting on the Internet. The team of KU Leuven-iMinds researchers analysed the Internet's top 10,000 websites and discovered that 145 of them (almost 1.5%) use Flash-based fingerprinting.

Some Flash objects included questionable techniques such as revealing a user's original IP address when visiting a website through a third party (a so-called proxy).

The study also found that 404 of the top 1 million sites use JavaScript-based fingerprinting, which allows sites to track non-Flash mobile phones and devices. The fingerprinting scripts were found to be probing a long list of fonts - sometimes up to 500 - by measuring the width and the height of secretly-printed strings on the page.

Do Not Track
The researchers identified a total of 16 new providers of device fingerprinting, only one of which had been identified in prior research. In another surprising finding, the researchers found that users are tracked by these device fingerprinting technologies even if they explicitly request not to be tracked by enabling the Do Not Track (DNT) HTTP header.

The researchers also evaluated Tor Browser and Firegloves, two privacy-enhancing tools offering fingerprinting resistance. New vulnerabilities - some of which give access to users' identity - were identified.

Device fingerprinting can be used for various security-related tasks, including fraud detection, protection against account hijacking and anti-bot and anti-scraping services. But it is also being used for analytics and marketing purposes via fingerprinting scripts hidden in advertising banners and web widgets.

To detect websites using device fingerprinting technologies, the researchers developed a tool called FPDetective. The tool crawls and analyses websites for suspicious scripts. This tool will be freely available here for other researchers to use and build upon.

The findings will be presented at the 20th ACM Conference on Computer and Communications Security this November in Berlin.

.


Related Links
KU Leuven
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle




Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News





CYBER WARS
Brazil to create its own email system after protesting U.S. spying
Brasilia, Brazil (UPI) Oct 14, 2013
Brazil says it will develop its own in-house email system to strengthen privacy and avoid spying it blames on the United States. The country will ditch Microsoft Outlook and develop its own new, custom platform, CNET reported Monday. The move comes following revelations that communications between Brazilian President Dilma Rousseff and her key aides have been monitored by the U.S ... read more


CYBER WARS
DroneMetrex Accomplishes Another Mapping Project Using Its Unique Topodrone-100

Flood maps from satellite data can help emergency response

Japan takes issue with Google maps over islands: reports

Australia's new prototype vehicle to improve Earth observation satellites' accuracy

CYBER WARS
Plan maps development of China's sat-nav industry

Raytheon completes critical design review for GPS OCX software

Tracking devices to go toe-to-toe with smartwatches

Orbcomm Acquires The SENS Asset Tracking Operation

CYBER WARS
Historic trends predict future global reforestation unlikely

Forests most likely to continue shrinking

Death of a spruce tree

Alarming suicide rates among Brazil's Guarani Indians

CYBER WARS
Metabolically engineered E. coli producing phenol

Team uses a cellulosic biofuels byproduct to increase ethanol yield

Working together: bacteria join forces to produce electricity

UCLA engineers develop new metabolic pathway to more efficiently convert sugars into biofuels

CYBER WARS
Minimum price on solar to protect South Australian consumers

SolarBOS announces official release of Circuit Breaker Solutions

KYOCERA Solar Gives Small Business an Edge with Energy Savings

KYOCERA Supplies Solar Modules for "Kizuna" Solar Park

CYBER WARS
Installation of the first AREVA turbines at Trianel Windpark Borkum and Global Tech 1

Trump's suit to halt wind farm project to be heard in November

Ireland connects first community-owned wind farm to grid

Moventas significantly expands wind footprint

CYBER WARS
Two China miners saved 10 days after flood, 10 confirmed dead

Calculating the true cost of a ton of mountaintop coal

Ukraine designates 45 coal mines for sale in privatization push

German coal mine turns village into ghost town

CYBER WARS
Chinese official sacked after piggyback to protect his shoes

US doctor detained on bid to see China activist: group

US report says little progress on China rights

Mexican officials won't meet Dalai Lama: Tibetan group




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement