USENIX Security2022Top-tier venue
Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention
Soroush Karami, Faezeh Kalantari, Mehrnoosh Zaeifi, Xavier J. Maso, Erik Trickel, Panagiotis Ilia, Yan Shoshitaishvili, Adam Doupé, Jason Polakis
Abstract
Online tracking has garnered significant attention due to the privacy risk it poses to users. Among the various approaches, techniques that identify which extensions are installed in a browser can be used for fingerprinting browsers and tracking users, but also for inferring personal and sensitive user data. While preventing certain fingerprinting techniques is relatively simple, mitigating behavior-based extension-fingerprinting poses a significant challenge as it relies on hiding actions that stem from an extension's functionality. To that end, we introduce the concept of DOM Reality Shifting, whereby we split the reality users experience while browsing from the reality that webpages can observe. To demonstrate our approach we develop Simulacrum, a prototype extension that implements our defense through a targeted instrumentation of core Web API interfaces. Despite being conceptually straightforward, our implementation highlights the technical challenges posed by the complex and often idiosyncratic nature and behavior of web applications, modern browsers, and the JavaScript language. We experimentally evaluate our system against a state-of-theart DOM-based extension fingerprinting system and find that Simulacrum readily protects 95.37% of susceptible extensions. We then identify trivial modifications to extensions that enable our defense for the majority of the remaining extensions. To facilitate additional research and protect users from privacy-invasive behaviors we will open-source our system.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3ccb1503-53c0-41ea-8c6e-b158735f15a3Cited by top-tier papers9
- Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral ModificationsKonstantinos Solomos, Panagiotis Ilia, Nick Nikiforakis, Jason PolakisCCS 2022 · 10 citations
- Fledging Will Continue Until Privacy Improves: Empirical Analysis of Google's Privacy-Preserving Targeted AdvertisingGiuseppe Calderonio, Mir Masood Ali, Jason PolakisUSENIX Security 2024 · 8 citations
- Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and InteractionsShubham Agarwal, Aurore Fass, Ben StockCCS 2024 · 4 citations
- Read Between the Lines: Detecting Tracking JavaScript with Bytecode ClassificationMohammad Ghasemisharif, Jason PolakisCCS 2023 · 3 citations
- Only Pay for What You Leak: Leveraging Sandboxes for a Minimally Invasive Browser Fingerprinting DefenseRyan Torok, Amit LevyS&P 2023
Builds on19
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 199 citations
- FP-STALKER: Tracking Browser Fingerprint EvolutionsAntoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain RouvoyS&P 2018 · 117 citations
- XHOUND: Quantifying the Fingerprintability of Browser ExtensionsOleksii Starov, Nick NikiforakisS&P 2017 · 104 citations
Related papers
- The Dangers of Human Touch: Fingerprinting Browser Extensions through User ActionsKonstantinos Solomos, Panagiotis Ilia, Soroush Karami, Nick Nikiforakis et al.USENIX Security 2022
- Breaking the Shield: Analyzing and Attacking Canvas Fingerprinting Defenses in the WildHoang Dai Nguyen, Phani VadrevuWWW 2025 · 2 citations
- Carnus: Exploring the Privacy Threats of Browser Extension FingerprintingSoroush Karami, Panagiotis Ilia, Konstantinos Solomos, Jason PolakisNDSS 2020
- Arcanum: Detecting and Evaluating the Privacy Risks of Browser Extensions on Web Pages and Web ContentQinge Xie, Manoj Vignesh Kasi Murali, Paul Pearce, Frank LiUSENIX Security 2024 · 16 citations
- Fingerprinting in Style: Detecting Browser Extensions via Injected Style SheetsPierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos et al.USENIX Security 2021 · 49 citations
