3 ms·
One of the referenced studies (1-million study withOpenWPM, the most recent from 2016) notes that the usual fingerprinting scripts have basically disappeared si
by user17843 7y ago
One of the referenced studies (1-million study withOpenWPM, the most recent from 2016) notes that the usual fingerprinting scripts have basically disappeared since a public outcry and media attention following a lawsuit.
Prevalence:
- 1.4% for canvasfingerprinting
- 0.325% for canvasfont probing
- 0.0715% for WebRTC
- 0.0067% forAudioContext
The above were found only on the most shady of all websites, and good content blockers block all those scripts.
My bet is GDPR was the death blow for this kind of scripts. For small companies without a room full of lawyers data has become a liability.
So fingerprinting is now basically in the hands of google, amazon, etc.
- amelius 7y ago> My bet is GDPR was the death blow for this kind of scripts. Curious, was the lawsuit in that study also based on GDPR? So far I haven't seen much coverage of GDPR based lawsuits in the media. Also, I'd like to know if there have been studies that show that EU residents can now (after GDPR) browse the web without leaving a trail of information.
- user17843 7y agoNo. Quote about canvas fingerprinting: "Comparing our results with a 2014 study [1], we find three important trends. First, the most prominent trackers have by-and-large stopped using it, suggesting that the public backlash following that study was effective. Second, the overall number of domains employing it has increased considerably, indicating that knowledge of the technique has spread and that more obscure trackers are less concerned about public perception. As the technique evolves, the images used have increased in variety and complexity, as we detail in Figure 12 in the Appendix. Third, the use has shifted from behavioral tracking to fraud detection, in line with thead industry’s self-regulatory norm regarding acceptable uses of fingerprinting." [1] G. Acar,C. Eubank, S. Englehardt, M. Juarez, A. Narayanan,and C. Diaz. The web never forgets: Persistent trackingmechanisms in the wild. InProceedings of CCS, 2014. Other references: [10] W. Davis. KISSmetrics Finalizes Supercookies Settlement.http://www.mediapost.com/publications/article/191409/kissmetrics-finalizes-supercookies-settlement.html,2013 http://www.mediapost.com/publications/article/191409/kissmet.... [Online; accessed 12-May-2014]. [15] Federal Trade Commission. Google will pay $22.5 millionto settle FTC charges it misrepresented privacy assurancesto users of Apple’s Safari internet browser. https://www.ftc.gov/news-events/press-releases/2012/08/google-will-pay-225-million-settle-ftc-charges-it-misrepresented https://www.ftc.gov/news-events/press-releases/2012/08/googl..., 2012
- kalleboo 7y agoI don't think GDPR results in lawsuits - it results in complaints to a regulator resulting in (escalating) fines. The regulators are still trying to apply the legislation to the complaints they have received.
- mobjack 7y agoBrowser fingerprinting has been overhyped and is not a reliable method of tracking. If it was useful, it would be much more prevalent but too many people have the same fingerprint. IP address is a better method of tracking for comparison.
- the_jeremy 7y ago> too many people have the same fingerprint. According to whom? My browser is unique according to panopticlick.
- user17843 7y agoIt is not in use because it's basically illegal, and due to relieance on JavaScrip, a simple script blocker can take down your entire business. The industry used fingerprinters, but for one it didn't really help them make more money (because you want to track users, not systems), and there was a big backlash.