1 min read

Google Chrome Extensions Used to Create Online Tracking Fingerprints

Vlad CONSTANTINESCU

June 20, 2022

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
Google Chrome Extensions Used to Create Online Tracking Fingerprints

A web developer has created a website that can generate a unique online tracking fingerprint based on Chrome extensions installed in a user’s browser.

The technique is based on fetching the extensions’ web-accessible resources, a type of file within the extension’s infrastructure that web pages can access. By detecting the combination of installed extensions on a user’s browser, the website can generate a unique tracking hash and use it to track the user online.

The procedure was previously demonstrated in 2019, but the website has only recently been created. Some extensions can evade detection by employing secret tokens required to access their web resources.

z0ccc, the web developer behind the project, discovered a novel ”resource timing comparison” technique that can bypass the secret token limitation by running some timing tests.

"Resources of protected extensions will take longer to fetch than resources of extensions that are not installed,” z0cccsaid on the project’s GitHub page. “By comparing the timing differences you can accurately determine if the protected extensions are installed."

z0ccc’s extension fingerprinting website checks for web-accessible resources in visitors’ Chrome browser extensions. Currently, the website works with over 1,000 popular extensions, but it only supports those available on Chrome’s Web Store.

It also works with extensions installed from the Chrome Web Store in Chromium browsers, such as Microsoft Edge. The same technique could detect Edge extensions from Microsoft’s dedicated store, but z0ccc’s website doesn’t support this feature.

It’s worth noting that the method doesn’t work for Firefox extensions. Firefox extension IDs are unique for each browser instance, making the web-accessible resources URL impossible to detect by third parties.

To prevent fingerprinting through browser extension detection, users can limit the number of extensions they install on their Chrome and Chromium browsers. Installing more extensions and in unique combinations increases the odds of having a distinctive tracking hash, which facilitates fingerprinting.

tags


Author



Right now

Top posts

Scam alert: Cybercrooks use shady investment domain to scam keen investors out of money and data

Scam alert: Cybercrooks use shady investment domain to scam keen investors out of money and data

May 24, 2022

3 min read
John Oliver Shows the Dark Side of Data Brokerage on Last Week Tonight

John Oliver Shows the Dark Side of Data Brokerage on Last Week Tonight

April 15, 2022

3 min read
Bitdefender Labs Warns of Phishing Scams Targeting MetaMask Users

Bitdefender Labs Warns of Phishing Scams Targeting MetaMask Users

April 14, 2022

3 min read
Why and how to hide your IP address while traveling

Why and how to hide your IP address while traveling

April 13, 2022

2 min read
How Bitdefender Can Help Restore Your Privacy in the Digital Age

How Bitdefender Can Help Restore Your Privacy in the Digital Age

April 04, 2022

3 min read
How Strong is VPN Encryption?

How Strong is VPN Encryption?

February 28, 2022

3 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Drunk worker loses USB stick containing details of every resident of his city Drunk worker loses USB stick containing details of every resident of his city
Graham CLULEY

June 27, 2022

3 min read
Researcher Discovers New MFA-bypassing Phishing Technique Based on Microsoft WebView2 Researcher Discovers New MFA-bypassing Phishing Technique Based on Microsoft WebView2
Vlad CONSTANTINESCU

June 27, 2022

2 min read
Internet Service Providers Help Spyware Vendor Infect iOS and Android Devices Internet Service Providers Help Spyware Vendor Infect iOS and Android Devices
Vlad CONSTANTINESCU

June 24, 2022

2 min read