In modern browsers, interactive 3D graphics are enabled by the WebGL component, which also serves as a vector for browser fingerprinting. Browser fingerprinting offers the benefit of allowing web application service providers to capture data about a web user’s browsing activity and as such establish user authenticity. One drawback of fingerprinting, however, is that the data collected can reveal unique (private) details about a user’s browsing behaviours which is in contravention of digital privacy laws such as the GDPR. To address this issue, anti-browser fingerprinting solutions such as randomising or blocking WebGL parameters have been proposed. However, these solutions face challenges with detectability and web compatibility, often resulting in performance degradation and poor user experience. In this paper, we propose a performance-efficient anti-browser fingerprinting mechanism for WebGL that is robust to detectability and offers improved user experience. We achieve this by extending the JShelter browser extension by: (1) generating realistic and valid WebGL parameters, reducing the likelihood of detection while preserving the functionality of visited websites; and (2) enhancing the spoofing (randomisation) mechanism in JShelter, to ensure that the spoofed values are indistinguishable from those of real hardware configurations. The results of our empirical study indicate reduced WebGL related errors in JShelter from over 150 to zero. Additionally, the modified JShelter version transfers data more efficiently and achieves faster speeds compared to the unmodified version, thus improving privacy, usability, and compatibility.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Performance-Efficient Anti-fingerprinting for Privacy

  • Lars Tomer Yavor,
  • Anne V. D. M. Kayem

摘要

In modern browsers, interactive 3D graphics are enabled by the WebGL component, which also serves as a vector for browser fingerprinting. Browser fingerprinting offers the benefit of allowing web application service providers to capture data about a web user’s browsing activity and as such establish user authenticity. One drawback of fingerprinting, however, is that the data collected can reveal unique (private) details about a user’s browsing behaviours which is in contravention of digital privacy laws such as the GDPR. To address this issue, anti-browser fingerprinting solutions such as randomising or blocking WebGL parameters have been proposed. However, these solutions face challenges with detectability and web compatibility, often resulting in performance degradation and poor user experience. In this paper, we propose a performance-efficient anti-browser fingerprinting mechanism for WebGL that is robust to detectability and offers improved user experience. We achieve this by extending the JShelter browser extension by: (1) generating realistic and valid WebGL parameters, reducing the likelihood of detection while preserving the functionality of visited websites; and (2) enhancing the spoofing (randomisation) mechanism in JShelter, to ensure that the spoofed values are indistinguishable from those of real hardware configurations. The results of our empirical study indicate reduced WebGL related errors in JShelter from over 150 to zero. Additionally, the modified JShelter version transfers data more efficiently and achieves faster speeds compared to the unmodified version, thus improving privacy, usability, and compatibility.