The latest ad tracking tricks and what to do about them
The Adobe Variant
An Adobe online service offers a different method for removing Flash cookies from your system. Go to the Setting Manager on the Macromedia website [11], click the Global Storage Settings tab, and disable the options Allow third-party Flash content to store data on your computer and Store common Flash components to reduce download times. Also, delete any existing LSO cookies below Website Storage Settings (Figure 5).
Conclusions
Although the advertising industry is doing somersaults to spy on unsuspecting web surfers, free developers are investing at least as much time and energy to guarantee data protection even against highly complex spyware. You do not need to rely on multiple browser add-ons to remove annoying pests from your system, but you can redirect these intrusion attempts to a black hole with just a few clicks.
Whatever the circumstances, it is always advisable to keep the system clean with a combination of add-ons and the Bleachbit tool, because a cleaner system means fewer loopholes for Evercookies.
Canvas fingerprints can be effectively and easily misled using the Firefox FireGloves add-on. Therefore, the advertising industry will need to come up with somewhat more sophisticated mechanisms in the future to spy on users of free software.
Interview: Canvas Fingerprinting and Evercookies
Canvas fingerprinting and Evercookies are two relatively unknown methods for spying on the surfing habits of Internet users. We asked Florian Drechsler, eCommerce expert, web designer, and co-owner of headtrip.io GbR from Nuremberg, Germany, [12], for his assessment of future developments and how to best protect yourself as an Internet surfer.
Linux Magazine: Canvas fingerprinting on web pages first attracted greater attention last summer, when researchers at the universities of Leuven and Princeton provided evidence of this tracking method on almost six percent of all surveyed web sites. Since then, public interest in this technique has again waned somewhat. Based on your experience, are there signs that canvas fingerprints are increasingly being used to identify surfers and their surfing habits on the Internet?
Florian Drechsler: Definitely, yes. The registered percentage of affected websites at that time was attributed to a large extent to advertising service provider AddThis, who apparently used canvas fingerprints to deliver personalized ads. But, AddThis quickly responded to the criticism and removed the canvasing code. In my experience, canvas fingerprinting has definitely spread – simply because many eCommerce companies and advertising platforms see it as a possibility to boost conversion rates through personalized content.
LM: The Tor Browser warns users about canvas fingerprints on many web pages. Often, also the Firefox CanvasBlocker extension indicates that canvas elements are trying to extract image files that could be used for spying on surfers. Analysis of the source code on most affected web pages show that the canvas code causing the alert was attributable to a small script introduced in WordPress 4.2 that checks to see whether emojis are available. Do such extensions that allow visitors to websites to be spied on cause any real danger?
FD: The Emoji script itself is harmless. Instead, the danger lies in the fact that the user approves this innocuous usage of the canvas element, and thus allows other potentially malicious elements.
LM: How can surfers tell, when they are notified of canvas fingerprints, whether those elements are used for tracking?
FD: If you cannot analyze the code yourself, your only option – as is so often the case in Internet security – is to rely on common sense. To do this, however, you need to know how a canvas element works. Canvas elements are used by websites for drawing, say, 3D animations or for browser games. In case of doubt, you should block the canvas element and then try to use the site: Are you missing some elaborate graphics? If so, switch the canvas back on. But if the site works without a canvas element, then it was at least superfluous, or it was actually used to track users.
LM: Evercookies are a tracking method that is as difficult to control as canvas fingerprints. How can I protect myself against Evercookies?
FD: By installing the Firefox BetterPrivacy [13] extension, which deletes Flash cookies and runs the browser in private browsing mode. If you do not need plugins like Silverlight and Flash, you should turn them off – and not only because of the Evercookies. The safest method, however, is the use of a specially hardened Linux distribution such as Tails [14].
LM: How do you see future developments: Are Evercookies and canvas fingerprints likely to spread?
FD: The final version of HTML5 is now only a few months old, and it might take some time until all clients can use canvas elements at all. The more frequently canvas elements are used, the more attractive options for using canvas fingerprinting will become. Evercookies have been around for over five years and are still in active development. Other methods that allow storage of user data might also arise through exploiting new browser technologies. Online traders, in particular, benefit from Evercookies and canvas fingerprinting, which let them trace the surfing behavior of potential customers. I would assume this option is used by increasing numbers of eCommerce companies.
Infos
- Flash cookie: https://en.wikipedia.org/wiki/Local_shared_object
- Evercookies: https://en.wikipedia.org/wiki/Evercookie
- Tor Browser: https://www.torproject.org/projects/torbrowser.html.en
- CanvasBlocker: https://addons.mozilla.org/en-us/firefox/addon/canvasblocker/
- CanvasFingerprintBlock: https://chrome.google.com/webstore/detail/canvasfingerprintblock/ipmjngkmngdcdpmgmiebdmfbkcecdndc
- Wordpress 4.2 "Powell": https://wordpress.org/news/2015/04/powell
- Disable Emojis: https://wordpress.org/plugins/disable-emojis
- FireGloves: http://fingerprint.pet-portal.eu/?menu=6
- Bleachbit: http://bleachbit.sourceforge.net/
- Ghostery: https://www.ghostery.com/our-solutions/ghostery-add-on
- Deleting Flash cookies: http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html
- headtrip.io GbR: http://headtrip.eu (in German)
- BetterPrivacy: https://addons.mozilla.org/en-US/firefox/addon/betterprivacy/
- Tails: https://tails.boum.org
« Previous 1 2 3
Buy this article as PDF
(incl. VAT)
Buy Linux Magazine
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.
News
-
Linux Kernel Reducing Long-Term Support
LTS support for the Linux kernel is about to undergo some serious changes that will have a considerable impact on the future.
-
Fedora 39 Beta is Now Available for Testing
For fans and users of Fedora Linux, the first beta of release 39 is now available, which is a minor upgrade but does include GNOME 45.
-
Fedora Linux 40 to Drop X11 for KDE Plasma
When Fedora 40 arrives in 2024, there will be a few big changes coming, especially for the KDE Plasma option.
-
Real-Time Ubuntu Available in AWS Marketplace
Anyone looking for a Linux distribution for real-time processing could do a whole lot worse than Real-Time Ubuntu.
-
KSMBD Finally Reaches a Stable State
For those who've been looking forward to the first release of KSMBD, after two years it's no longer considered experimental.
-
Nitrux 3.0.0 Has Been Released
The latest version of Nitrux brings plenty of innovation and fresh apps to the table.
-
Linux From Scratch 12.0 Now Available
If you're looking to roll your own Linux distribution, the latest version of Linux From Scratch is now available with plenty of updates.
-
Linux Kernel 6.5 Has Been Released
The newest Linux kernel, version 6.5, now includes initial support for two very exciting features.
-
UbuntuDDE 23.04 Now Available
A new version of the UbuntuDDE remix has finally arrived with all the updates from the Deepin desktop and everything that comes with the Ubuntu 23.04 base.
-
Star Labs Reveals a New Surface-Like Linux Tablet
If you've ever wanted a tablet that rivals the MS Surface, you're in luck as Star Labs has created such a device.