As a part of the various options webmasters have for displaying content in your browser, something called “canvas” can also be used for tracking. In essence, the webpage can instruct your browser to draw a picture that is not displayed. That picture tends to be unique with each user because of the various combinations of browser, fonts, screen resolution and other similar factors. The picture can be analyzed and a unique signature can be created from it. Every time you visit a website with similar code (provided by advertisers), that same unique ID can be generated afresh. Thus, simply visiting the various sites using that same browser guarantees you can be tracked even if you clean your cache totally between the various sites. The fingerprint is unique to your browser and can be recognized by servers wherever you go.
I’m sure someone could write a JScript that could block this function, but I know next to nothing about writing JScript. I suppose you could also write your own CSS code that blocks such use of canvas, but again, I know too little about that. I’ve seen it used to block various other kinds of elements, but I don’t know enough to use it as more than a very blunt instrument. Something like this:
img[src*=”gif”] { display: none !important; }
in a user stylesheet that loads in your browser would simply block all GIF images from displaying. I don’t think there’s a way to refine that so that it only blocks, say, animated GIF images. If someone knows how to craft CSS or JScript to block those hidden canvas fingerprinting elements, I’d love to know.
Meanwhile, I note that using browsers incapable of running JScript will go a long way to blocking this tracking trick, but it also makes some websites hard to read. For the most part, I read almost all websites using Lynx, which is plain text. If some crazy webmaster blocks Lynx, I find Elinks often works in its place, another kind of plaint text web browser. The linked article from RT notes that someone is working on a special Chrome browser extension called “Chameleon” that would block such privacy threats. I suppose if you know how to use things like AdBlock or other tools for blocking specific sources, you could block the primary domains from which the canvas fingerprinting bits are injected.
It’s not like we can blame anyone in particular. Users demand more eye-candy and browser developers deliver, working in concert with webmasters to come up with more ways to please the eye. Each new trick carries vulnerabilities in the sense that more complications add more weaknesses. The basic rule of CompSec has always been that user convenience and entertainment always comes at the price of greater vulnerability. It’s always convenience versus security; increase one and you lose the other. So the most secure email, for example, is webmail viewed in a plain text browser. The most secure browser is plain text only. The most secure OS has no GUI.
The war on privacy continues unabated.
Addenda: Compliments of a Slashdot commenter, another thought that hadn’t occurred to me —
Depending on what you mean by “block”, there may or may not be a properly satisfactory answer: “Block” as in “make this specific mechanism fail” is the relatively easy question. If the attacker can’t manipulate a canvas element and read the result, it won’t work. So the usual javascript blockers or more selective breaking of some or all of the canvas element (the TOR browser apparently already does this for methods that can be used to read back the contents of a canvas element, so you can still draw on one but not observe your handiwork) will do the job. Unfortunately the attacker doesn’t actually care about making your browser draw a picture, they care about achieving as accurate a UID as they can. Given that, you might actually make yourself more distinctive if your attempt to break a given fingerprinting mechanism succeeds. In the case of the TOR browser, for instance, attempts to read a canvas will always be handled as though the canvas is all opaque white. This does prevent the attacker from learning anything useful about font rendering peculiarities or other quirks of your environment’s canvas implementation; but it’s also a behavior that, for the moment at least, only the TOR browser has. Relatively uncommon. Possibly less common than the result that you’d receive from an unmodified browser. That’s the nasty thing about fingerprinting attacks. Fabricating or refusing to return many types of identifying information is relatively easy (at least once you know that attackers are looking for them); but unless you lie carefully, your fake data may actually be less common (and thus more trackable) than your real data.
So the trick is to block in such a way that makes you indistinguishable from enough other users that you are lost. Then again, maybe the question needs to take a different direction. If you can’t prevent fingerprinting, what can you do to avoid some of the negative consequences?