X-Client-Data Header as a Method for Identifying Chrome Users

In discussions of the Google initiative to unify the HTTP User-Agent header content, the developer of the Kiwi browser pointed out the remaining HTTP header in Chrome 'X-Client-Data', which potentially violates the General Data Protection Regulation (GDPR) currently in force in the European Union (GDPR). During the discussion the duality of Google's actions was also criticized, as on one hand it promotes methods to block hidden identification and tracking of users' actions, but on the other hand is slow to remove support for the X-Client-Data header in Chrome, which can be used to identify browser instances when accessing Google services.

The X-Client-Data header is not a hidden feature, and its behavior is described in the documentation. Through X-Client-Data, Google collects data on the activity of certain experimental capabilities in Chrome tied to its websites (for instance, during an experiment, Google can activate specific test features in YouTube if they are supported by the browser or attempt to correlate issues that arise with the activation of experimental functions).

The header is sent only for requests to Google sites matching the patterns '*.doubleclick.net', '*.googlesyndication.com', 'www.googleadservices.com', '*.google.<TLD>' and '*.youtube.<TLD>', sent via HTTPS. In incognito mode, the header is not populated, but when switching from an authenticated Google user profile to a guest profile or performing a data clearing operation, the header is not reset and continues to be sent with the previous value.

X-Client-Data Header as a Method for Identifying Chrome Users

It is stated that the header does not contain personally identifiable information, but only describes the state of the Chrome installation and active experimental capabilities. If telemetry reporting on browser usage and crash reports is disabled in settings, the base value of the X-Client-Data header uses only 13 bits of entropy (8000 different combinations), which is insufficient for identification.

Considering that the header also encodes some settings and system parameters, the contents of X-Client-Data are quite suitable as an additional data source for indirectly identifying users over a short period (experimental capabilities are periodically enabled and disabled, leading to changes in the value of X-Client-Data).

However, in addition to the initial entropy when forming the value of X-Client-Data, a seed sequence returned by Google servers is also used, which depends on the country, IP address, and other criteria that Google deems important (for example, nothing prevents the return of a large random sequence that would serve as an exact identifier).
Moreover, the domain mask check by Google when sending X-Client-Data does not eliminate the possibility of an attacker registering a domain like "youtube.xn--55qx5d" and beginning to collect identifiers.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster