Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

isExtended is additional fingerprinting surface #120

Open
pes10k opened this issue Dec 2, 2022 · 0 comments
Open

isExtended is additional fingerprinting surface #120

pes10k opened this issue Dec 2, 2022 · 0 comments
Labels
privacy-needs-resolution Issue the Privacy Group has raised and looks for a response on.

Comments

@pes10k
Copy link

pes10k commented Dec 2, 2022

This issue is being filed as part of the requested PING privacy review #106

As noted in the spec, isExtended is additional fingerprinting surface that is not mitigated or prevented by the spec. This is particularly concerning since the screen APIs are already well know and exploited by fingeprinters, and so it seems very likely that this bit will be similarly used by fingerprinters.

One possibility is to removing the property all together and just having sites use the result of the permission guarded getScreenDetails. A website needing to use explicit multi-screen capabilities seems extremely rare as a % of websites, and I imagine that users could easily predict when these feautres are needed for benign functionality (either because of the kind of site, or because of the site using a "click to enable multi-montior support" button).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
privacy-needs-resolution Issue the Privacy Group has raised and looks for a response on.
Projects
None yet
Development

No branches or pull requests

1 participant