Fingerprinting Web Users Through Font Metrics

Fingerprinting Web Users Through Font Metrics
复制标题

通过字体指标对 Web 用户进行指纹识别

DOI:
--
复制
发表时间:
2015
期刊:
Financial Cryptography
影响因子:
--
通讯作者:
Serge Egelman
Serge Egelman
中科院分区:
--
文献类型:
--
作者:
D. Fifield;Serge Egelman

文献摘要

被引文献

相似文献

我们描述了一种基于测量字体字形屏幕尺寸的Web浏览器指纹识别技术。Web浏览器中的字体呈现受到许多因素的影响--浏览器版本、安装了什么字体、提示和抗锯齿设置等等--这些因素都是最终用户系统中指纹识别差异的来源。我们发现,即使是相对粗糙的测量字形边界框的工具也会产生强烈的指纹,这对用户的隐私构成了威胁。通过对1000多个浏览器的用户实验和对Unicode分配空间的详尽调查,我们发现字体度量比User-Agent字符串更加多样化,能够唯一识别34%的参与者,并将其他参与者归入较小的匿名集合。指纹识别很容易,只需要几毫秒。我们表明,在检查的超过125,000个代码点中,只需测试43个代码点就足够了,以便解释我们实验中看到的所有变化。字体度量与许多其他指纹技术是正交的,可以增强和锐化这些其他技术。
We describe a web browser fingerprinting technique based on measuring the onscreen dimensions of font glyphs. Font rendering in web browsers is affected by many factors—browser version, what fonts are installed, and hinting and antialiasing settings, to name a few—that are sources of fingerprintable variation in end-user systems. We show that even the relatively crude tool of measuring glyph bounding boxes can yield a strong fingerprint, and is a threat to users’ privacy. Through a user experiment involving over 1,000 web browsers and an exhaustive survey of the allocated space of Unicode, we find that font metrics are more diverse than User-Agent strings, uniquely identifying 34 % of participants, and putting others into smaller anonymity sets. Fingerprinting is easy and takes only milliseconds. We show that of the over 125,000 code points examined, it suffices to test only 43 in order to account for all the variation seen in our experiment. Font metrics, being orthogonal to many other fingerprinting techniques, can augment and sharpen those other techniques.