5 ms·
Fingerprinting by detecting installed fonts is certainly interesting, esp since it could be used by both offense and defense. Digging in deeper, I’m wonderi
by chrsstrm 4y ago
Fingerprinting by detecting installed fonts is certainly interesting, esp since it could be used by both offense and defense.
Digging in deeper, I’m wondering if it would be possible to craft a font that consists of Javascript fragments which could be rendered and eval’ed when a page loads. There must be something in the browser’s rendering process that would block this, right?
- function_seven 4y agoI'm not following your scenario here. How would a font be able to create these fragments at all? I can imagine a font rendering a glyph as a line of code. But under the hood it would still be just a byte or bytes corresponding to that codepoint.
- chrsstrm 4y agoI’m not sure, but I suppose you would be correct.
- mFixman 4y agoYou just need a program that registers the `'; DROP TABLE 'users` font and voilá.
- tobyjsullivan 4y agoI don't think this is what OP was talking about but fonts are Turing-complete and can introduce all manner of exploits.[0] However, getting the font installed seems like the hard bit - I don't see how loading it or detecting it in a website makes anything new possible. [0] https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/microsoft-alerts-users-about-critical-font-related-remote-code-execution-vulnerability-in-windows https://www.trendmicro.com/vinfo/us/security/news/vulnerabil...
- snapcaster 4y agoSeems like everything is turing complete these days. Good share, didn't know any of this stuff
- plorntus 4y agoI was actually wondering if you could use this as another form of authentication (ignoring that WebAuthN and other such standards exists). For example create a font dynamically that when printing a specific string just outputs some form of data (eg. JWT encoded in a font glyph) that can be drawn to a canvas and read by the page. Could be some form of incredibly sticky authentication, unless the user removes the font will never go away. Nefarious and not sure there would ever be a legitimate usecase but sounds doable.
- moqmar 4y agoI think TLS client certificates are basically the equivalent to this approach.