The Core

Why We Are Here => Web Development => Topic started by: rcjordan on July 21, 2014, 11:11:19 PM

Title: AddThis persistent tracking
Post by: rcjordan on July 21, 2014, 11:11:19 PM
http://www.propublica.org/article/meet-the-online-tracking-device-that-is-virtually-impossible-to-block
Title: Re: AddThis persistent tracking
Post by: Rooftop on July 22, 2014, 07:32:55 AM
Interesting one. I wonder how more or less precise that is to the general browser fingerprint stuff. The article makes it sound like it would be less precise but easier to work with.

In the case of addthis I'd imagine it is pretty easy to just block their script.

Fingerprinting is likely to get huge unless something is done. At the moment google and apple hold all the cards in a cookieless world. There is a lot of money riding on that not being the case.
Title: Re: AddThis persistent tracking
Post by: JasonD on July 22, 2014, 04:48:52 PM
Does anyone know any patent lawyers? :)
Title: Re: AddThis persistent tracking
Post by: rcjordan on July 22, 2014, 04:54:27 PM
>patent

Ping Bill Slawski. He'd be the place to start.
Title: Re: AddThis persistent tracking
Post by: JasonD on July 22, 2014, 04:54:58 PM
Yes, thank you!
Title: Re: AddThis persistent tracking
Post by: Brad on July 22, 2014, 05:20:24 PM
Are there countermeasures?

Could you clone the fingerprint thingy and pass it on or infect others with the clone (chaff and flares)  to confuse and decoy the tracker?
Title: Re: AddThis persistent tracking
Post by: JasonD on July 22, 2014, 05:28:19 PM
There are many countermeasures you can deploy on your own machine, such as artificially throwing some randomness into certain functions and  but as they use standard components of the html spec it would need to be incorporated at the browser level to be truly defeated.

That's not unheard of but in this instance I think it's unlikely. Time to wait and see.

Personally I'd just Blacklist add this in ABP or equivalent but that will only go so far and to be frank, I gave in to the various borgs eons ago., I've also taken the view that not being seen "on the net" is as much a red flag as anything and I'd rather simply blend and merge into the greyness of normalness.
Title: Re: AddThis persistent tracking
Post by: JasonD on July 22, 2014, 06:16:00 PM
I'd also expect similar to be revealed at BH next month with this talk, although I also expect the features bugs to be closed in a much easier manner

https://www.blackhat.com/us-14/briefings.html#svg-exploiting-browsers-without-image-parsing-bugs