All Projects → jonasstrehle → Supercookie

jonasstrehle / Supercookie

Licence: mit
💭 Inspiration

Programming Languages

javascript
184084 projects - #8 most used programming language
typescript
32286 projects
HTML
75241 projects
shell
77523 projects

Projects that are alternatives of or similar to Supercookie

Lazy
Kule Lazy4 / CSS Framework
Stars: ✭ 147 (-95.95%)
Mutual labels:  edge, chrome, browser, firefox, safari
Extension Create
Create modern cross-browser extensions with no build configuration.
Stars: ✭ 167 (-95.4%)
Mutual labels:  edge, chrome, browser, firefox, safari
Scriptsafe
a browser extension to bring security and privacy to chrome, firefox, and opera
Stars: ✭ 434 (-88.04%)
Mutual labels:  tracking, privacy, chrome, browser, firefox
Browser Sec Whitepaper
Cure53 Browser Security White Paper
Stars: ✭ 251 (-93.09%)
Mutual labels:  edge, privacy, chrome, browser
Known Css Properties
List of standard and browser specific CSS properties.
Stars: ✭ 89 (-97.55%)
Mutual labels:  edge, chrome, firefox, safari
Hackbrowserdata
Decrypt passwords/cookies/history/bookmarks from the browser. 一款可全平台运行的浏览器数据导出解密工具。
Stars: ✭ 3,864 (+6.45%)
Mutual labels:  edge, chrome, browser, firefox
Searchwithmybrowser
Open Cortana searches with your default browser.
Stars: ✭ 285 (-92.15%)
Mutual labels:  edge, chrome, browser, firefox
Octotree
Browser extension that enhances GitHub code review and exploration. You can download Octotree for your browser from our website.
Stars: ✭ 21,726 (+498.51%)
Mutual labels:  edge, chrome, firefox, safari
Fingerprintjs
Browser fingerprinting library with the highest accuracy and stability.
Stars: ✭ 15,481 (+326.47%)
Mutual labels:  fingerprint, browser, identification, browser-fingerprint
Librefox
License: Mozilla Public License 2.0
Stars: ✭ 1,574 (-56.64%)
Mutual labels:  privacy, browser, firefox
Kdeconnect Chrome Extension
A browser extension to send pages and content from your browser to connected KDE Connect devices.
Stars: ✭ 124 (-96.58%)
Mutual labels:  chrome, browser, firefox
Forensic Tools
A collection of tools for forensic analysis
Stars: ✭ 204 (-94.38%)
Mutual labels:  cookie, chrome, firefox
Retrotxt
RetroTxt is the WebExtension that turns ANSI, ASCII, NFO text into in-browser HTML
Stars: ✭ 93 (-97.44%)
Mutual labels:  edge, chrome, firefox
Blocker Database
A global domain based database for NoScript, uBlock, uMatrix & ScriptSafe
Stars: ✭ 127 (-96.5%)
Mutual labels:  privacy, chrome, firefox
Freedom
The Freedom to Open URLs in Third-Party Browsers on iOS with Custom UIActivity Subclasses.
Stars: ✭ 85 (-97.66%)
Mutual labels:  chrome, firefox, safari
Keepassbrowserimporter
KeePass 2.x plugin which imports credentials from various browsers.
Stars: ✭ 139 (-96.17%)
Mutual labels:  chrome, browser, firefox
Offline Qr Code
📱 Browser add-on allowing you to quickly generate a QR code offline with the URL of the open tab or other text!
Stars: ✭ 193 (-94.68%)
Mutual labels:  privacy, browser, firefox
Automator
Various Automator and AppleScript workflow and scripts for simplifying life
Stars: ✭ 68 (-98.13%)
Mutual labels:  chrome, firefox, safari
Surfingkeys Conf
A SurfingKeys configuration which adds 130+ key mappings for 20+ sites & OmniBar search suggestions for 50+ sites
Stars: ✭ 137 (-96.23%)
Mutual labels:  chrome, browser, firefox
All In One Customized Adblock List
An all-in-one adblock list that thoroughly blocks trackers, popup ads, ads, unwanted cookies, fake news, cookie warning messages, typosquatters, unwanted comment sections, crypto-coin mining, YouTube clutter, Twitter guff and social network hassles.
Stars: ✭ 217 (-94.02%)
Mutual labels:  cookie, privacy, browser

supercookie

Documentation

Website Status License

Fingerprint index N Redirects

Supercookie uses favicons to assign a unique identifier to website visitors.
Unlike traditional tracking methods, this ID can be stored almost persistently and cannot be easily cleared by the user.

The tracking method works even in the browser's incognito mode and is not cleared by flushing the cache, closing the browser or restarting the operating system, using a VPN or installing AdBlockers. 🍿 Live demo.

About

💭 Inspiration

🪧 Purpose

This repository is for educational and demonstration purposes only!

The demo of "supercookie" as well as the publication of the source code of this repository is intended to draw attention to the problem of tracking possibilities using favicons.

📕 Full documentation

Installation

🔧 Docker

requirements: Docker daemon

  1. Clone repository
git clone https://github.com/jonasstrehle/supercookie
  1. Update .env file in supercookie/server/.env
HOST_MAIN=yourdomain.com #or localhost:10080
PORT_MAIN=10080

HOST_DEMO=demo.yourdomain.com #or localhost:10081
PORT_DEMO=10081
  1. Run container
cd supercookie/server
docker-compose up

-> Webserver will be running at https://yourdomain.com

🤖 Local machine

requirements: Node.js

  1. Clone repository
git clone https://github.com/jonasstrehle/supercookie
  1. Update .env file in supercookie/server/.env
HOST_MAIN=localhost:10080
PORT_MAIN=10080

HOST_DEMO=localhost:10081
PORT_DEMO=10081
  1. Run service
cd supercookie/server
node --experimental-json-modules main.js

-> Webserver will be running at http://localhost:10080

Workwise of supercookie

📖 Background

Modern browsers offer a wide range of features to improve and simplify the user experience. One of these features are the so-called favicons: A favicon is a small (usually 16×16 or 32×32 pixels) logo used by web browsers to brand a website in a recognizable way. Favicons are usually shown by most browsers in the address bar and next to the page's name in a list of bookmarks.

To serve a favicon on their website, a developer has to include an attribute in the webpage’s header. If this tag does exist, the browser requests the icon from the predefined source and if the server response contains an valid icon file that can be properly rendered this icon is displayed by the browser. In any other case, a blank favicon is shown.

<link rel="icon" href="/favicon.ico" type="image/x-icon">

The favicons must be made very easily accessible by the browser. Therefore, they are cached in a separate local database on the system, called the favicon cache (F-Cache). A F-Cache data entries includes the visited URL (subdomain, domain, route, URL paramter), the favicon ID and the time to live (TTL). While this provides web developers the ability to delineate parts of their website using a wide variety of icons for individual routes and subdomains, it also leads to a possible tracking scenario.

When a user visits a website, the browser checks if a favicon is needed by looking up the source of the shortcut icon link reference of the requested webpage. The browser initialy checks the local F-cache for an entry containing the URL of the active website. If a favicon entry exists, the icon will be loaded from the cache and then displayed. However, if there is no entry, for example because no favicon has ever been loaded under this particular domain, or the data in the cache is out of date, the browser makes a GET request to the server to load the site's favicon.

💣 Threat Model

In the article a possible threat model is explained that allows to assign a unique identifier to each browser in order to draw conclusions about the user and to be able to identify this user even in case of applied anti-fingerprint measures, such as the use of a VPN, deletion of cookies, deletion of the browser cache or manipulation of the client header information.

A web server can draw conclusions about whether a browser has already loaded a favicon or not: So when the browser requests a web page, if the favicon is not in the local F-cache, another request for the favicon is made. If the icon already exists in the F-Cache, no further request is sent. By combining the state of delivered and not delivered favicons for specific URL paths for a browser, a unique pattern (identification number) can be assigned to the client. When the website is reloaded, the web server can reconstruct the identification number with the network requests sent by the client for the missing favicons and thus identify the browser.

Supercookie Header

conventional cookies

supercookie

Identification accuracy - 100%
Incognito / Private mode detection
Persistent after flushed website cache and cookies
Identify multiple windows
Working with Anti-Tracking SW

🎯 Target

It looks like all top browsers ( Chrome, Firefox, Safari, Edge) are vulnerable to this attack scenario.
Mobile browsers are also affected.

Current versions

Browser

Windows

MacOS

Linux

iOS

Android

Info
Chrome (v 87.0) -
Safari (v 14.0) - - - -
Edge (v 87.0) -
Firefox (v 86.0) Fingerprint different in incognito mode
Brave (v 1.19.92) -

Previous versions

Browser

Windows

MacOS

Linux

iOS

Android

Info
Brave (v 1.14.0) -
Firefox (< v 84.0) -

Scalability & Performance

By varying the number of bits that corresponds to the number of redirects to subpaths, this attack can be scaled almost arbitrarily. It can distinguish 2^N unique users, where N is the number of redirects on the client side. The time taken for the read and write operation increases as the number of distinguishable clients does.
In order to keep the number of redirects as minimal as possible, N can have a dynamic length. More about this here.

📌How to defend against?

The most straightforward solution is to disable the favicon cache completely. As long as the browser vendors do not provide a feature against this vulnerability it's probably the best way to clear the F-cache.

  • ChromeMacOS

    • Delete ~/Library/Application Support/Google/Chrome/Default/Favicons
    • Delete ~/Library/Application Support/Google/Chrome/Default/Favicons-journal
  • ChromeWindows

    • Delete C:\Users\username\AppData\Local\Google\Chrome\User Data\Default
  • SafariMacOS

    • Delete content of ~/Library/Safari/Favicon Cache
  • EdgeMacOS

    • Delete ~/Library/Application Support/Microsoft Edge/Default/Favicon
    • Delete ~/Library/Application Support/Microsoft Edge/Default/Favicons-journal

Other

🙎‍♂️ About me

I am a twenty year old student from 🇩🇪 Germany. I like to work in software design and development and have an interest in the IT security domain.

This repository, including the setup of a demonstration portal, was created within two days as part of a private research project on the topic of "Tracking on the Web".

💖 Support the project

ko-fi

Spread the world!

Liked the project? Just give it a star and spread the world!

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].