{"id":5751,"date":"2014-07-23T09:31:33","date_gmt":"2014-07-23T01:31:33","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=5751"},"modified":"2014-07-23T21:34:05","modified_gmt":"2014-07-23T13:34:05","slug":"share-button-may-share-browsing-history","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2014\/07\/23\/share-button-may-share-browsing-history\/","title":{"rendered":"That &#8216;share&#8217; button may share your browsing history, too"},"content":{"rendered":"<p><strong>Are you one of those people that like to share content on Facebook, Twitter, Instagram or other social networks? If so, you could be a victim of cybercrime right now.<\/strong><\/p>\n<p>1 in 18 of the world\u2019s top 100,000 websites track users without their consent using a previously undetected cookie-like tracking mechanism embedded in \u2018share\u2019 buttons. A new study by researchers at KU Leuven and Princeton University provides the first large-scale investigation of the mechanism and is the first to confirm its use on actual websites.<\/p>\n<p>The mechanism, called \u201ccanvas fingerprinting\u201d, uses special scripts \u2013 the coded instructions that tell your browser how to render a website \u2013 to exploit the browser\u2019s so-called \u2018canvas\u2019, a browser functionality that can be used to draw images and render text.<\/p>\n<p>When a user visits a website with canvas fingerprinting software, a first script tells the user\u2019s browser to print an invisible string of text on the browser\u2019s canvas. Another script then instructs the browser to read back data about the pixels in the (invisibly) rendered image.<\/p>\n<p>These data contains important information about the user\u2019s browser type, graphics card, system fonts and even display properties. Because this grouping of data is highly likely to be unique for each user, it can be reliably associated to individual users, like a fingerprint.<\/p>\n<p><strong>Cookies<\/strong><br \/>\nOnce a website has determined a device\u2019s fingerprint, it can easily recognize the user on subsequent site visits, much in the same way cookies do.<\/p>\n<p>But while unwanted cookies can be flagged or blocked to enhance a user\u2019s online privacy, there is no available solution for doing so with fingerprints.<\/p>\n<p>In this study, the researchers used automated \u2018crawlers\u2019 to scan the world\u2019s top 100,000 websites for canvas fingerprinting scripts. They found canvas fingerprinting scripts on 5,542 of the internet\u2019s top 100,000 websites, a prevalence of 5.5 percent.<\/p>\n<p>Previous studies on related browser fingerprinting techniques reported a prevalence of 0.4 percent and 1.5%, respectively, although they are not directly comparable to the current study since they measured different types of fingerprinting techniques.<\/p>\n<p>While researchers demonstrated the feasibility of canvas fingerprinting as a tracking mechanism in 2012, this is the first time it has been observed on real websites and traced back to specific provider domains. Analyses of the real-world scripts reveal that fingerprinters are going beyond the techniques known by the academic research community.<\/p>\n<div id=\"attachment_5752\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-5752\" class=\"size-medium wp-image-5752\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo-300x225.jpg\" alt=\"Researchers traced 95 percent of canvas fingerprinting scripts back to a single company:  AddThis.\" width=\"300\" height=\"225\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo-300x225.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo-1024x768.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo-600x450.jpg 600w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo-210x158.jpg 210w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2014\/07\/photo-390x293.jpg 390w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-5752\" class=\"wp-caption-text\">Researchers traced 95 percent of canvas fingerprinting scripts back to a single company: AddThis.<\/p><\/div>\n<p><strong>AddThis<\/strong><br \/>\nSurprisingly, the researchers traced 95 percent of canvas fingerprinting scripts back to a single company:\u00a0 AddThis. AddThis is the world\u2019s largest content sharing platform and provides free website plugins such as share buttons, follow buttons and content recommendation features. The company reaches an estimated 97.2% of Internet users in the United States and receives 103 billion page views each month.<\/p>\n<p>Can users protect themselves against canvas fingerprinting? Acar and his colleagues studied the effect of ad-industry opt-out tools offered by the Network Advertising Initiative (NAI) and the European Interactive Digital Advertising Alliance. No websites included in the opt-lists stopped collecting canvas fingerprints after activating the opt-out option.<\/p>\n<p>At present, only one browser, Tor, can prevent canvas fingerprinting scripts, but this added security comes with major trade-offs in performance, functionality and content availability.<\/p>\n<p>Many websites, including sensitive sites such as health and government websites, contain canvas fingerprinting without ever realizing it \u2013 by using one of AddThis\u2019 free plug-ins for example.<\/p>\n<p>The researchers are concerned by the growing prevalence of canvas fingerprinting , says Gunes Acar, the first author of the study: \u201cThis is an advanced tracking mechanism that misuses browser features to enable the circumvention of users\u2019 tracking preferences. We hope that our results will lead to better defenses, increase accountability for companies deploying sticky tracking techniques and an invigorated and informed public and regulatory debate on increasingly resilient tracking techniques.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Are you one of those people that likes to share content on Facebook, Twitter, Instagram or other social networks? If so, you could be a victim of cybercrime right now.<\/p>\n","protected":false},"author":6,"featured_media":5752,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,19],"tags":[1885,1886,495,286],"class_list":["post-5751","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apps","category-headlines","tag-addthis","tag-canvass-fingerprinting","tag-cybersecurity-and-cybercrime","tag-it-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/5751","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=5751"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/5751\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/5752"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=5751"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=5751"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=5751"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}