Case Study: Disclosure of Indirect Device Fingerprinting in Privacy Policies

被引:0
|
作者
Milligan, Julissa [1 ]
Scheffler, Sarah [1 ]
Sellars, Andrew [1 ]
Tiwari, Trishita [1 ]
Trachtenberg, Ari [1 ]
Varia, Mayank [1 ]
机构
[1] Boston Univ, Boston, MA 02215 USA
基金
美国国家科学基金会;
关键词
D O I
10.1007/978-3-030-55958-8_10
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recent developments in online tracking make it harder for individuals to detect and block trackers. This is especially true for device fingerprinting techniques that websites use to identify and track individual devices. Direct trackers - those that directly ask the device for identifying information - can often be blocked with browser configurations or other simple techniques. However, some sites have shifted to indirect tracking methods, which attempt to uniquely identify a device by asking the browser to perform a seemingly-unrelated task. One type of indirect tracking known as Canvas fingerprinting causes the browser to render a graphic recording rendering statistics as a unique identifier. Even experts find it challenging to discern some indirect fingerprinting methods. In this work, we aim to observe how indirect device fingerprinting methods are disclosed in privacy policies, and consider whether the disclosures are sufficient to enable website visitors to block the tracking methods. We compare these disclosures to the disclosure of direct fingerprinting methods on the same websites. Our case study analyzes one indirect fingerprinting technique, Canvas fingerprinting. We use an existing automated detector of this fingerprinting technique to conservatively detect its use on Alexa Top 500 websites that cater to United States consumers, and we examine the privacy policies of the resulting 28 websites. Disclosures of indirect fingerprinting vary in specificity. None described the specific methods with enough granularity to know the website used Canvas fingerprinting. Conversely, many sites did provide enough detail about usage of direct fingerprinting methods to allow a website visitor to reliably detect and block those techniques. We conclude that indirect fingerprinting methods are often technically difficult to detect, and are not identified with specificity in legal privacy notices. This makes indirect fingerprinting more difficult to block, and therefore risks disturbing the tentative armistice between individuals and websites currently in place for direct fingerprinting. This paper illustrates differences in fingerprinting approaches, and explains why technologists, technology lawyers, and policymakers need to appreciate the challenges of indirect fingerprinting.
引用
收藏
页码:175 / 186
页数:12
相关论文
共 50 条
  • [31] A case study of Eucalyptus globulus fingerprinting for breeding
    Maria Margarida Ribeiro
    Leopoldo Sanchez
    Carla Ribeiro
    Fátima Cunha
    José Araújo
    Nuno M. G. Borralho
    Cristina Marques
    Annals of Forest Science, 2011, 68 : 701 - 714
  • [32] An Online Method for Estimating the Wireless Device Count via Privacy-Preserving Wi-Fi Fingerprinting
    Torkamandi, Pegah
    Karkkainen, Ljubica
    Ott, Jorg
    PASSIVE AND ACTIVE MEASUREMENT, PAM 2021, 2021, 12671 : 406 - 423
  • [33] A case study of Eucalyptus globulus fingerprinting for breeding
    Ribeiro, Maria Margarida
    Sanchez, Leopoldo
    Ribeiro, Carla
    Cunha, Fatima
    Araujo, Jose
    Borralho, Nuno M. G.
    Marques, Cristina
    ANNALS OF FOREST SCIENCE, 2011, 68 (04) : 701 - 714
  • [34] Understanding privacy policies A study in empirical analysis of language usage
    Laemmel, Ralf
    Pek, Ekaterina
    EMPIRICAL SOFTWARE ENGINEERING, 2013, 18 (02) : 310 - 374
  • [35] Privacy Policies in Web Sites of Portuguese Municipalities: An Empirical Study
    Dias, Goncalo Paiva
    Gomes, Helder
    Zuquete, Andre
    ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, 2013, 206 : 87 - 96
  • [36] A Study of Online Privacy Policies of South African Retail Websites
    Maraba, Jean
    Da Veiga, Adele
    ADVANCED RESEARCH IN TECHNOLOGIES, INFORMATION, INNOVATION AND SUSTAINABILITY, PT 2, ARTIIS 2023, 2024, 1936 : 426 - 440
  • [37] CHALLENGES TO GENETIC PRIVACY The case of disclosure of genetic information to a patient's genetic relatives
    Bogdanoski, Tony
    ALTERNATIVE LAW JOURNAL, 2008, 33 (03) : 165 - 168
  • [38] Privacy Concern in Mobile Payment: A Diary Study on Users' Perception of Information Disclosure
    Zhang, Jiaxin
    Luximon, Yan
    HUMAN SYSTEMS ENGINEERING AND DESIGN II, 2020, 1026 : 1000 - 1006
  • [39] Ethics disclosure as strategy: a longitudinal case study
    Kumarasinghe, Sriyalatha
    Peiris, Indujeeva Keerthilal
    Everett, Andre M.
    MEDITARI ACCOUNTANCY RESEARCH, 2021, 29 (02) : 294 - 323
  • [40] Developing a culture of privacy - A case study
    Power, E. Michael
    IEEE SECURITY & PRIVACY, 2007, 5 (06) : 58 - 60