Identification through the analysis of external protocol handlers in the browser

The developers of the fingerprintjs library, which allows for passive generation of browser identifiers based on indirect signs such as screen resolution, WebGL features, and lists of installed plugins and fonts, have introduced a new identification method based on assessing the standard applications installed by the user. This works by checking for support in the browser for additional protocol handlers. The script code implementing this method is published under the MIT license.

The verification is based on analyzing the binding of handlers to 32 popular applications. For instance, identifying the presence of URL handlers such as telegram://, slack://, and skype:// in a browser allows one to conclude that applications telegram, slack, and skype are present in the system. This information can then be used as a criterion when generating the system identifier. Since the list of handlers is the same across all browsers on the system, the identifier does not change when switching browsers and can be applied in Chrome, Firefox, Safari, Brave, Yandex Browser, Edge, and even Tor Browser.

This method generates 32-bit identifiers, which individually do not yield high precision but serve as an additional criterion when combined with other parameters. A significant drawback of the method is its visibility to the user — when generating an identifier on the proposed demonstration page, a small but clearly noticeable window opens in the lower right corner, where the handlers are iterated for a considerable time. This drawback does not manifest in Tor Browser, where the identifier can be computed unobtrusively.

To determine the presence of an application, the script attempts to open a link associated with an external handler in a pop-up window. The browser then displays a dialog suggesting opening the content in the related application if the checked application is present or shows an error page if the application is not found in the system. By sequentially iterating through standard external handlers and analyzing the error returned, one can infer the presence of the checked programs in the system.

In Chrome 90 for Linux, the method did not work, and the browser displayed a standard confirmation dialog for all verification attempts (the method works in Chrome for Windows and macOS). In Firefox 88 for Linux, both in normal and incognito mode, the script detected the presence of installed extensions from the list, with an identification accuracy rated at 99.87% (35 matches out of 26,000 tests conducted). In the Tor Browser running on the same system, an identifier was generated that matched the test in Firefox.

Interestingly, the additional protection in the Tor Browser turned out to be a double-edged sword, allowing identification without the user's awareness. Due to the disabling of confirmation dialogs for using external handlers in the Tor Browser, it became possible to open verification requests in an iframe instead of a popup (the same-origin rules are used to separate the presence or absence of handlers, blocking access to error pages while allowing access to about:blank pages). Due to flood protection, checks in the Tor Browser take noticeably longer (10 seconds per application).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster