6 ms·
This kind of fingerprinting is used across the industry for anti-fraud purposes. The problem is that it used to be good enough to block "known-bad" IPs but now
by yding 7y ago
This kind of fingerprinting is used across the industry for anti-fraud purposes.
The problem is that it used to be good enough to block "known-bad" IPs but now with AWS and cloud services it's very easy for cybercriminals to get around IP blocks.
For normal users, tracking can be done with cookies, so fingerprinting isn't really needed for normal users anyways (not entirely true if you're a totally bad actor, which is why browsers have been trying to block some of the more common ways to fingerprint).
But for a script that spawns a thousand AWS instances to sign up 1000 bot accounts that can then be used to sell likes for example, it's pretty easy to tell that it's a script instance because all of them will behave in almost exactly the same way (processor performance, installed plugins, reported screen size, etc. etc.).
An "alternative" to using fingerprints would be to use captchas instead, but bots have gotten much much better at solving captchas. So in fact, ReCaptcha will also use a number of fingerprinting techniques, which is why in many cases you can just click the check box instead of solving a captcha.
- kbenson 7y ago> it's pretty easy to tell that it's a script instance because all of them will behave in almost exactly the same way (processor performance, installed plugins, reported screen size, etc. etc.). Processor performance is variable based on the particular instance you are running on and how much load it is handling. At least at the level the remote side can see. Screen size is easily configured and/or randomized to some degree, or shifted between 10-20 common values. Plugins reported or actually allowed to run can be changed per instance. All this stuff is trivial with headless chrome and puppeteer, and even abstracted away using the stealth plugin for puppeteer[1]. And headless firefox through puppeteer is experimental All this fingerprinting is ridiculous and trivial for someone with any incentive to do so to defeat. 1: https://www.npmjs.com/package/puppeteer-extra-plugin-stealth https://www.npmjs.com/package/puppeteer-extra-plugin-stealth
- saagarjha 7y ago> Screen size is easily configured and/or randomized to some degree, or shifted between 10-20 common values. I don't want my browser to keep changing its screen size. > All this fingerprinting is ridiculous and trivial for someone with any incentive to do so to defeat. I disagree. There are a number of efforts to defeat fingerprinting underway already and I think the fact that they haven't been able to eliminate it says volumes about how difficult of a problem this is.
- kbenson 7y ago> I don't want my browser to keep changing its screen size. Neither do I. I'm taking about how useless it is to use these metrics to identify bots, sine any bot can easily circumvent them, and with far more less hassle than a user. The fingerprinting is "for" fraud, but is not very useful in that context. The fallout is that all our privacy is worse though. > I disagree ... the fact that they haven't been able to eliminate it They haven't eliminated it because it still works well enough on end users, even though the narrative is that it's to prevent fraud. Fingerprinting works for users, but for any halfway competent adversary it's close to useless. Just keep that in mind when it's brought up as a solution to fraud and that's why it's worth allowing.
- sudosysgen 7y agoThe attacker would be shifting screen sizes, in the given justification of bots.
- iudqnolq 7y agoTOR makes the most usability compromising security choices of any browser and even they don't have a fixed window size to avoid any fingerprinting here. They do prevent manually resizing the window because the exact width could be used to rack you across sites in the same windows.
- dasil003 7y agoThe fingerprinting signal does not necessarily need to be revealed to the fraudulent actor in order to be useful. It’s a cat and mouse game, but it’s worth it because of the cash at stake.
- bayarrhea 7y agoAh yes, so trivial. That must explain why millions of people are doing it and we have perfect privacy online. Who knew perfect privacy was one hackathon away the whole time?
- kbenson 7y agoThe context of this is that the tracking helps prevent fraud. It's trivial for someone to circumvent it that puts some effort into it, so it doesn't work well for any but the most simple instances of fraud detection. We all, as end users, pay for this because as an end user it's much more onerous to work around because site specific tweaks to make a site work require a lot of effort.
- novok 7y agoI thought the IP blocks that most cloud service providers & VPNs have are well known, and for services that don't need their customers to talk to cloud servers, they widescale ban the IP ranges. Like netflix and many others.