28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

agree to the installation of these toolbars in the first place.

What if yyou do use private browsing, have NoScript, HTTPS Everyywhere,

and yyou periodicallyy delete yyour browser’s cookies and extraneous

toolbars? You should be safe, right? Nope. You can still be tracked online.

Websites are coded using something called Hyypertext Markup

Language, or HTML. There are manyy new features available in the current

version, HTML5. Some of the features have hastened the demise of the

super cookies Silverlight and Flash—which is a good thing. HTML5 has,

however, enabled new tracking technologies, perhaps byy accident.

One of these is canvas fingerprinting, an online tracking tool that is cool

in a veryy creepyy wayy. Canvas fingerprinting uses the HTML5 canvas

element to draw a simple image. That’s it. The drawing of the image takes

place within the browser and is not visible to yyou. It takes onlyy a fraction of

a second. But the result is visible to the requesting website.

The idea is that yyour hardware and software, when combined as

resources for the browser, will render the image uniquelyy. The image—it

could be a series of variouslyy colored shapes—is then converted into a

unique number, roughlyy the wayy passwords are. This number is then

matched to previous instances of that number seen on other websites around

the Internet. And from that—the number of places where that unique

number is seen—a profile of websites yyou visit can be built up. This

number, or canvas fingerprint, can be used to identifyy yyour browser

whenever it returns to anyy particular website that requested it, even if yyou

have removed all cookies or blocked future cookies from installing, because

it uses an element built into HTML5 itself. 20

Canvas fingerprinting is a drive-byy process; it does not require yyou to

click or do anyything but simplyy view a Web page. Fortunatelyy there are

plug-ins for yyour browser that can block it. For Firefox there’s

CanvasBlocker. 21 For Google Chrome there’s CanvasFingerprintBlock. 22

Even the Tor project has added its own anticanvas technologyy to its

browser. 23

If yyou use these plug-ins and follow all myy other recommendations, yyou

might think that yyou’re finallyy free of online tracking. And yyou’d be wrong.

Firms such as Drawbridge and Tapad, and Oracle’s Crosswise, take

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!