9 ms·
Virtual Machine Detection in the Browser (2019)
- userbinator 6y agoquickly realized that some of the fingerprinting information could be useful for VM detection because vendor names were exposed. In this particular instance the string "VMWare" was contained within the WebGL information. After some more testing I also discovered that VirtualBox reported the same kind of information. I believe there are patches that can close those holes, but I've always found the fact that such information is exposed by default and can thus make a VM obviously not look more like real hardware is puzzling. Ideally, a VM should be indistinguishable from real hardware, and in practice that ideal is difficult to achieve --- especially with timing-based detections --- but you'd think such obvious signs wouldn't appear. Also, the amount of information that can be gathered via JS is disturbingly immense. To me, this is just further validation of the fact that JS needs to be off by default and whitelisted only for the (very few) sites that one truly trusts.
- xxpor 6y agoThere's a lot of paravirtualized devices even within an HVM type of VM. This is necessary for performance. You don't want to have to emulate a lot of things if you don't have to. https://wiki.libvirt.org/page/Virtio https://wiki.libvirt.org/page/Virtio
- Wowfunhappy 6y ago> I've always found the fact that such information is exposed by default and can thus make a VM obviously not look more like real hardware is puzzling. Eh, it seems to me that software ought to be cooperative by default. Plenty of programs will detect whether you have AMD or nVidia graphics and optimize itself for your hardware—why not VMWare graphics? Where I agree is that there ought to be an easy checkbox to hide it.
- zensavona 6y agoAnd most importantly, it should be checked by default IMO
- Wowfunhappy 6y ago...no, that's where I don't agree. Again, software should attempt to be truthful by default. There's a reason we allow programs to detect the hardware they're running on—it allows for all sorts of optimizations. Does the VM claim it's network driver was manufactured by Broadcom, or does it go with Cambridge Silicon Radio? Or does it decline to provide a vendor, and if it does, how long until software starts assuming that is the sign of a VM, except this time with potential false positives for users of niche hardware?
- yjftsjthsd-h 6y agoI think a key distinction is whether we're in an adversarial context or not. And I think loading untrusted applications over network connection from arbitrary third parties is absolutely a position to be distrustful.
- elcomet 6y agoIt could report the host's hardware.
- Wowfunhappy 6y agoBut now you're leaking information about the host, which I would think is worse given the purpose of a VM.
- ruslanbogan 6y agoIt would have to emulate the host hardware to do that because the fingerprint is only going to report what's listed in Device Manager for instance.
- userbinator 6y agoDoes the VM claim it's network driver was manufactured by Broadcom, or does it go with Cambridge Silicon Radio? It would simply be whatever the virtual NIC is. Intel ones seem to be pretty common, likely due to wide availability of drivers and documentation.
- ogre_codes 6y agoI agree with this in most cases, but when it comes to Javascript and fingerprinting, I think systems should be as generic as possible. This isn't even a VM versus bare metal thing.
- Wowfunhappy 6y agoRight, and so browsers need to fix this! Not because of VMs but because a web page, unlike desktop software, has no business knowing my graphics card.
- ogre_codes 6y ago> Right, and so browsers need to fix this! Makes sense to me. There are a lot of legitimate reasons software on your computer might need to know it's in a VM or what the limits of your VR engine are.
- grimli333 6y agoWell, presumably there may be valid use cases for WebGL applications or games behaving differently according to specific vendors/drivers. It feels like something that needs to be asked permission for, however, so it can’t be used for nefarious purposes.
- Wowfunhappy 6y ago...I don't know. I realize this is an entirely subjective view of what a web page should be, but I just don't think any website should know the intricacies of my hardware. The web is a low-friction, low-trust environment; installing a desktop app has more friction, but it also acts as a signal of greater trust. If a website ever really needs to know my hardware, it can ask me to choose from a drop-down. A lot of users won't know what hardware they have—but, those users are also unlikely to understand the implications of a hardware-detection permission prompt.
- yjftsjthsd-h 6y ago
- geofft 6y ago> Ideally, a VM should be indistinguishable from real hardware Why? I mean, it's possible to make a VM that's indistinguishable (except for speed), but what's the purpose of doing so? Most people who run VMs have the purpose of "I want this application to run more conveniently than having dedicated hardware for it." For that purpose, it's useful to provide abstractions (e.g., providing dedicated access to CPUs in a way normal kernels usually don't) and usually to provide sandboxing (e.g., prohibiting disk writes outside of the VM disk), but there's generally little point in lying, unless the software you want to run won't run right without lying. And it's often counterproductive to lie, because software can adapt to the ways the abstraction is leaky if you're truthful about the nature of the abstraction. (In this case, the VMware graphics driver can achieve much better performance by cooperating with the host than a normal graphics driver expecting physical hardware could get on a software emulation of that hardware.) It's also often pointless to lie - if you pay for a VM from Amazon EC2, and you log into it and it pretends to be a 1U physical server, are you going to believe it?
- deleted 6y ago[deleted]
- sm4rk0 6y agoRight question. I'm also missing the "Why" from this article.
- fulafel 6y agoI guess the line of thinking is "the more differences there are, the leakier the abstraction is". The obvious case people will think about is the security angle (by using a vm you to impersonate a consumer end user, so for eaxmple malware doesn't realize it's running in a vm). But there are other cases where murphy's law will bite you. For example I bet some WebGL apps manage to trip themselves up over this feature string because of whitelists or buggy logic in code that tries to be clever about used features vs underlying platform.
- mmwelt 6y agoWhile changing the reported device names can just make the VM a little less obvious, I suspect there will always be clues that indicate a VM. For example: - Do network adapter MAC vendor ID's make sense? - Does the hard drive size make sense? - Which 3D acceleration features are supported/work correctly? - How much graphics RAM is there? - Timing-based methods It's a bit like detecting private/incognito mode in a browser. Everything worked great, until websites realised there are ways to detect it, then became a game of cat and mouse.
- gruez 6y ago>- Do network adapter MAC vendor ID's make sense? >- Does the hard drive size make sense? not detectable through browser APIs >- Which 3D acceleration features are supported/work correctly? vmware workstation has 3d acceleration support targeting directx 11, so I'd imagine most features are supported and are passed through to the host gpu for execution. I doubt you'll able to detect is a vm or not based on that. In addition, resistfingerprinting (on firefox) hides this kind of stuff. >- How much graphics RAM is there? vmware workstation has vram selectable from 32MB all the way to 8GB, so that covers the entire range of plausible vram sizes. >- Timing-based methods what else can you test that is both accessible via browser api and would yield big differences between a vm and a slow computer? >It's a bit like detecting private/incognito mode in a browser. Everything worked great, until websites realised there are ways to detect it, then became a game of cat and mouse. not really, it's a solved problem: make a new browser profile and then delete it after you're done. I've seen a few HN commenters post their (relatively short) scripts to make a new firefox/chromium, start it, and then automatically delete it once it exits.
- _trampeltier 6y agoI didn't know WebGL leaks so much information about my machine. I already open a browser just in ingokigno/private mode 90% of the time. Maybe is time to start just each time a different VM for browsing.
- jmnicolas 6y agoI tried it, it's highly inconvenient. Maybe QubesOS would help, not sure.
- gruez 6y agoThat wouldn't really help. The containers/VMs might be separated from each other, but they're running on the same hardware/software stack, so they'll behave the same should you decide to fingerprint it.
- jmnicolas 6y agoI meant for convenience since launching VM is part of the OS. Wouldn't every Qubes VM (whatever the underlying physical machine) return the same fingerprint? Something like VM Fedora version XXX running on Xen hypervisor.
- gruez 6y agoDepends how they do 3d rendering. If it's passed through to the host gpu, then it's fingerprintable. If it's using some sort of software renderer that might be fine, but the performance is going to be garbage.
- gruez 6y agoIt's not limited to just webgl, there's a whole suite of browser features that can be used to "fingerprint" your browser. see: https://news.ycombinator.com/item?id=25166703 https://news.ycombinator.com/item?id=25166703
- twelvechairs 6y ago> JS needs to be off by default and whitelisted only for the (very few) sites that one truly trusts. Or the information provided by JS regarding the local machine should be reduced
- kaashmonee 6y agoI feel like this might be a better and more feasible solution. Is there a reason that JS can collect as much data as it does about our hardware? I feel like I always hear the mantra, "The browser is a sandbox," but reading articles like this make me really unconfident that that is true. I don't really have too much of an idea of how WebGL works, but I wonder if there's a way to create some sort of additional abstraction layer between a website and the hardware? So JS just has access to "hardware interfaces" like a CPU and a GPU but can only interact with via this interface. That way, even if a site wanted to, the best it could do is determine that your computer has a GPU or a CPU but not how many cores or what type of GPU? This would however have the downside of incurring an additional latency with an additional abstraction, but if there was a way you turn this off with trusted websites and only leave it on when you're using a site you don't trust it could be more usable? It just seems better than disabling JS entirely since a lot of websites just completely break without JS. It just seems like with the amount of information that JS can collect, even if you're using TOR or a VPN, if you crunch all the information about a particular user, like the kind of OS they're running, the version of the browser, the screen ratio, mouse click movements, time of access, number of CPU cores, type of GPU, whether or not it's a VM, etc., it just feels like you might be able to devise a pretty reasonable heuristic for where this person is and the kind of computer they're using. I can't really say I know the extent of browser and JS capabilities, but these things already seem alarming enough where I wouldn't really feel super confident that I can't be tracked even with TOR or a VPN. Edit: Just discovered something similar to this is being worked on already! https://gpuweb.github.io/gpuweb/#malicious-use https://gpuweb.github.io/gpuweb/#malicious-use
- zzo38computer 6y agoThe user should have full control over everything. For example, if the user want to configure it so that all JavaScript time reporting reports that everything takes zero time, then that is what it should do in that case. If the user wants all timeouts to expire immediately (so that JavaScript-based animations will take zero time), that can also be done, then. You should have enough ropes to hang yourself, and also a few more just in case.
- tenebrisalietum 6y ago> Ideally, a VM should be indistinguishable from real hardware VMs wouldn't achieve the performance they do without paravirtualization. VMs don't meticulously emulate all attached virtual devices. Paravirtualized device drivers more or less forward the I/O request to the hypervisor which handles it in a VM-specific way. For example, it's not super useful for a VM to emulate all the bitwise register-twiddling dances needed to talk to a SATA controller, it can simply have some "backdoor" channel into the hypervisor that says "Queue request to write X to LBA Y for this VM". Since paravirtualization requires specific drivers, it will always be detected.
- bob1029 6y agoFor timing based attacks, couldn't we start looking at injecting random jitter into the JS runtime? You could source the timing entropy from a CSPRNG so that attackers would be unable to distinguish from random noise. Obviously, this would have an impact on performance, but it could be something that is controlled on a per-host basis as required.
- emptyparadise 6y agoYou already get banished from half of the internet for hiding your IP address, I hope this wouldn't be used to make our lives even worse. Imagining a grim future where sites block all ad blockers (how about some detecting if an ad blocker exists at all, rather than its usage?), VPNs, virtual machines, even incognito mode. No full trust = no website.
- chii 6y agoThen do go to those websites. It's not a right that you have access to a website. Seek out only sites that don't block adblock, or has no ads. This might include a paid option (for example, youtube premium, or twitch subscription for ad-free viewing).
- emptyparadise 6y agoI may not have the right to have access to most of these websites but I do have the right to complain about how unethical I find it. And of course this situation has different implications if the website offers some sort of an essential service, but that's an entirely different discussion.
- judge2020 6y agoOP is just suggesting you vote with your 'wallet' by not using those sites - they're not saying you should stop complaining.
- xfitm3 6y agoLong time ago a popular storage vendor automatically put their software into dev or test mode when it detected a vmware bios. I had a really awesome storage array at home.
- koluna 6y agoI am honestly more surprised by the fact that we let these kinds of APIs creep into our browsers. What’s the scenario where a website needs to know how much RAM or what kind of video adapter I have? I get it for a game or a desktop app, but a website? At the end of the day, we all know that any kinds of unique identifiers will be used in combination. We need to reduce those to an absolute minimum. Today’s browser APIs are leaking information like a 1920s faucet.
- geofft 6y agoSometimes people put games and desktop apps in websites. And, really, when you download a game or desktop app as a traditional executable, the OS gives it so much access to your private data that the term "leak" isn't meaningful any more. Any video game you install as a .exe can silently access every email and online banking account you either are logged into or will log into in the future.
- koluna 6y agoA video game installation is a conscious choice that I can make depending on whether I trust the vendor or not. Me visiting New York Times and getting 58 trackers scraping my device configuration and preferences is not a choice.
- pishpash 6y agoIt is as much a choice as installing an .exe. Treat the web browser like the OS of old, because that's exactly what browser makers think of it.
- upbeat_general 6y agoTrue in theory but good luck explaining this to my grandma/99% of internet users. People click links freely even if they shouldn’t,
- 6y ago
- drifkin 6y agoRelated: a 2014 paper on using timing side channels to detect being in a VM from within browsers https://www.usenix.org/system/files/conference/woot14/woot14-ho.pdf https://www.usenix.org/system/files/conference/woot14/woot14...
- zimaalsu 6y agouh, I've been using GoLogin.com for a long time and no one detects me xD
- imagine99 6y agoThat looks very interesting indeed! But it's so absurdly expensive that you have to wonder who the target audience for this service is? From their "Use Cases" page it seems that this is geared towards (shady?) online marketers (which would explain the price) rather than privacy-conscious individuals. Would be awesome if they offered a plan for normal users priced similar to a normal VPN service...
- phist_mcgee 6y agoI understand the technical challenge here, but pay a thought to students who are subjected to online proctoring software that takes a huge amount of onerous control over a student's computer [1]. This kind of software means that students running a vm to mask their computer from heavy-handed software may make it harder for a person to remain in control of their own system. I don't think this knowledge is bad to share, but a person using a virtual machine should never be penalised their degree. 1.https://www.proctoru.com/ https://www.proctoru.com/
- Jonnax 6y agoThe fact that browsers allow websites to see whatgpu you have installed, driver version and enumerate your fonts is clearly put there for the benefit of tracking people. Otherwise browser developers would create generic classes of device that segment users into large groups based on features. The fonts thing is proof. For years, you install a custom font on your pc. Then you are unique.
- gruez 6y agoNot really. Some GPU/driver implementations are simply broken, and can't be trivially detected via feature detection. That's why gpu blacklists are a thing https://wiki.mozilla.org/Blocklisting/Blocked_Graphics_Drivers https://wiki.mozilla.org/Blocklisting/Blocked_Graphics_Drive....
- historyremade 6y agoThis is just tip of ice burg. I aware of more advanced tricks involve no browser at all.
- rbirkby 6y agoFor those that have access to Menlo Security’s safe browsing saas service, it’s worthwhile analysing what client side JavaScript can tell you about the runtime environment. Device aspect ratio is just one of the strange things reported.
- ninkendo 6y agoThe browser should ask permission from the user to divulge hardware information like this (something that looks like “This website wants to display 3D graphics, but this may divulge information used to track you”, etc.) We already have this for divulging your GPS location and notifications, why not add this too? Yes, it means you’d get a lot more nagging, but to me, that’s good signal for what sites I should be avoiding in the first place.
- gruez 6y agoI think you severely overestimate the resolve of the average user. They'd be very easily socially engineered into clicking yes, especially when the website is holding the content hostage. Not to mention, there's a wide array of fingerprinting techniques, and many of them have legitimate/common uses in normal sites. eg. window size, browser timezone, canvas.