Case Study: Disclosure of Indirect Device Fingerprinting in Privacy Policies

被引:0
|
作者
Milligan, Julissa [1 ]
Scheffler, Sarah [1 ]
Sellars, Andrew [1 ]
Tiwari, Trishita [1 ]
Trachtenberg, Ari [1 ]
Varia, Mayank [1 ]
机构
[1] Boston Univ, Boston, MA 02215 USA
基金
美国国家科学基金会;
关键词
D O I
10.1007/978-3-030-55958-8_10
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recent developments in online tracking make it harder for individuals to detect and block trackers. This is especially true for device fingerprinting techniques that websites use to identify and track individual devices. Direct trackers - those that directly ask the device for identifying information - can often be blocked with browser configurations or other simple techniques. However, some sites have shifted to indirect tracking methods, which attempt to uniquely identify a device by asking the browser to perform a seemingly-unrelated task. One type of indirect tracking known as Canvas fingerprinting causes the browser to render a graphic recording rendering statistics as a unique identifier. Even experts find it challenging to discern some indirect fingerprinting methods. In this work, we aim to observe how indirect device fingerprinting methods are disclosed in privacy policies, and consider whether the disclosures are sufficient to enable website visitors to block the tracking methods. We compare these disclosures to the disclosure of direct fingerprinting methods on the same websites. Our case study analyzes one indirect fingerprinting technique, Canvas fingerprinting. We use an existing automated detector of this fingerprinting technique to conservatively detect its use on Alexa Top 500 websites that cater to United States consumers, and we examine the privacy policies of the resulting 28 websites. Disclosures of indirect fingerprinting vary in specificity. None described the specific methods with enough granularity to know the website used Canvas fingerprinting. Conversely, many sites did provide enough detail about usage of direct fingerprinting methods to allow a website visitor to reliably detect and block those techniques. We conclude that indirect fingerprinting methods are often technically difficult to detect, and are not identified with specificity in legal privacy notices. This makes indirect fingerprinting more difficult to block, and therefore risks disturbing the tentative armistice between individuals and websites currently in place for direct fingerprinting. This paper illustrates differences in fingerprinting approaches, and explains why technologists, technology lawyers, and policymakers need to appreciate the challenges of indirect fingerprinting.
引用
收藏
页码:175 / 186
页数:12
相关论文
共 50 条
  • [21] A systematic mapping study on automated analysis of privacy policies
    Del Alamo, Jose M.
    Guaman, Danny S.
    Garcia, Boni
    Diez, Ana
    COMPUTING, 2022, 104 (09) : 2053 - 2076
  • [22] A systematic mapping study on automated analysis of privacy policies
    Jose M. Del Alamo
    Danny S. Guaman
    Boni García
    Ana Diez
    Computing, 2022, 104 : 2053 - 2076
  • [23] Analyzing Privacy Policies based on a Privacy-Aware Profile: the Facebook and LinkedIn case studies
    Caramujo, Joao
    da Silva, Alberto Rodrigues
    2015 IEEE 17TH CONFERENCE ON BUSINESS INFORMATICS, VOL 1, 2015, : 77 - 84
  • [24] Communication Privacy Management and Self-Disclosure on Social Media - A Case of Facebook
    Chennamaneni, Anitha
    Taneja, Aakash
    AMCIS 2015 PROCEEDINGS, 2015,
  • [25] Do privacy concerns determine online information disclosure? The case of internet addiction
    Thompson, Nik
    Ahmad, Atif
    Maynard, Scan
    INFORMATION AND COMPUTER SECURITY, 2021, 29 (03) : 558 - 569
  • [26] Saving Life and Keeping Privacy: A Study on Mobile Apps for Suicide Prevention and Privacy Policies
    Reen, Jaisheen
    Friday, Aniefiok
    Orji, Rita
    PERSUASIVE TECHNOLOGY (PERSUASIVE 2022), 2022, 13213 : 190 - 207
  • [27] A PROSPECTIVE-STUDY OF DONOR INSEMINATION RECIPIENTS - SECRECY, PRIVACY, AND DISCLOSURE
    KLOCK, SC
    JACOB, MC
    MAIER, D
    FERTILITY AND STERILITY, 1994, 62 (03) : 477 - 484
  • [28] ONLINE DISCLOSURE AND PRIVACY CONCERNS: A STUDY OF MOROCCAN AND AMERICAN FACEBOOK USERS
    Veltri, Natasha
    Krasnova, Hanna
    El Garah, Wafa
    AMCIS 2011 PROCEEDINGS, 2011,
  • [29] A Case Study of Community Privacy
    Codio, Sherley
    Kafura, Dennis
    Perez-Quinones, Manuel
    Gracanin, Denis
    Kavanaugh, Andrea
    PROCEEDINGS OF THE 2012 ASE INTERNATIONAL CONFERENCE ON SOCIAL INFORMATICS (SOCIALINFORMATICS 2012), 2012, : 265 - 274
  • [30] Information Disclosure, Medical Device Regulation, and Device Safety: The Case of Cook Celect IVC Filters
    Kadakia, Kushal T.
    Bikdeli, Behnood
    Gupta, Aakriti
    Dhruva, Sanket S.
    Ross, Joseph S.
    Krumholz, Harlan M.
    ANNALS OF INTERNAL MEDICINE, 2024,