4 ms·
This appears to depend on user interactivity. How would you silently (and accurately) use this technique to fingerprint a system for cross-browser tracking?
by johnvaluk 5y ago
This appears to depend on user interactivity. How would you silently (and accurately) use this technique to fingerprint a system for cross-browser tracking?
- valve1 5y agoOn Tor we show a fake captcha on the demo, which allows to collect multiple key presses and use each as a user-provided trigger.
- Ansil849 5y agoThis is a really clever way to coerce interactivity!
- nulbyte 5y agoClever indeed; I only suspected this the second go-round, after I noticed the reload button flicker as I typed. I also noticed you don't have to press Enter or even type the correct phrase to get past the fake prompt. In hindsight, the easy to guess text should have been a dead give-away, but it wasn't.
- johnvaluk 5y agoDoes that bypass any alerts that would be presented to the user by the browser?
- shadowgovt 5y agoIt would be trickier, but it's not as hard as one might want to get a user to click in such a way that the protections in place against automated behaviors can be side-stepped. I'd bet good money that this trick would be useful for anyone running either a meme generator website or a file host, for example. It'd be pretty solid in the file host in particular, because you could hide some of the obvious weird behavior behind the "We're downloading your file" delay.