USENIX Security2022Top-tier venue
Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting
Xu Lin, Panagiotis Ilia, Saumya Solanki, Jason Polakis
Abstract
As users navigate the web they face a multitude of threats; among them, attacks that result in account compromise can be particularly devastating. In a world fraught with data breaches and sophisticated phishing attacks, web services strive to fortify user accounts by adopting new mechanisms that identify and prevent suspicious login attempts. More recently, browser fingerprinting techniques have been incorporated into the authentication workflow of major services as part of their decision-making process for triggering additional security mechanisms (e.g., two-factor authentication).
In this paper we present the first comprehensive and in-depth exploration of the security implications of real-world systems relying on browser fingerprints for authentication. Guided by our investigation, we develop a tool for automatically constructing fingerprinting vectors that replicate the process of target websites, enabling the extraction of fingerprints from users' devices that exactly match those generated by target websites. Subsequently, we demonstrate how phishing attackers can replicate users' fingerprints on different devices to deceive the risk-based authentication systems of high-value web services (e.g., cryptocurrency trading) to completely bypass two-factor authentication. To gain a better understanding of whether attackers can carry out such attacks, we study the evolution of browser fingerprinting practices in phishing websites over time. While attackers do not generally collect all the necessary fingerprinting attributes, unfortunately that is not the case for attackers targeting certain financial institutions where we observe an increasing number of phishing sites capable of pulling off our attacks. To address the significant threat posed by our attack, we have disclosed our findings to the vulnerable vendors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1d480b9e-ac19-4879-a3d4-c7851d0e70f3Cited by top-tier papers16
- Mutual Wasserstein Discrepancy Minimization for Sequential RecommendationZiwei Fan, Zhiwei Liu, Hao Peng, Philip S. YuWWW 2023 · 24 citations
- The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting BehaviorAsuman Senol, Alisha Ukani, Dylan Cutler, Igor BilogrevicWWW 2024 · 14 citations
- Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral ModificationsKonstantinos Solomos, Panagiotis Ilia, Nick Nikiforakis, Jason PolakisCCS 2022 · 10 citations
- The First Early Evidence of the Use of Browser Fingerprinting for Online TrackingZengrui Liu, Jimmy Dani, Yinzhi Cao, Shujiang Wu et al.WWW 2025 · 7 citations
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 6 citations
Builds on18
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 199 citations
Related papers
- Large-Scale Measurement and Real-World Mitigation of Web Browser Fingerprinting in the WildTom Ritter, Fatih Kilic, Frederik Braun, Elisa Luo et al.CCS 2026
- Him of Many Faces: Characterizing Billion-scale Adversarial and Benign Browser Fingerprints on Commercial WebsitesShujiang Wu, Pengfei Sun, Yao Zhao, Yinzhi CaoNDSS 2023
- Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at ScaleMichele Campobasso, Luca AllodiCCS 2020 · 24 citations
- Rods with Laser Beams: Understanding Browser Fingerprinting on Phishing PagesIskander Sánchez-Rola, Leyla Bilge, Davide Balzarotti, Armin Buescher et al.USENIX Security 2023
- Beyond the Crawl: Unmasking Browser Fingerprinting in Real User InteractionsMeenatchi Sundaram Muthu Selva Annamalai, Emiliano De Cristofaro, Igor BilogrevicWWW 2025 · 4 citations
