XHOUND: Quantifying the Fingerprintability of Browser Extensions
Oleksii Starov, Nick Nikiforakis
Abstract
In recent years, researchers have shown that unwanted web tracking is on the rise, as advertisers are trying to capitalize on users' online activity, using increasingly intrusive and sophisticated techniques. Among these, browser fingerprinting has received the most attention since it allows trackers to uniquely identify users despite the clearing of cookies and the use of a browser's private mode. In this paper, we investigate and quantify the fingerprintability of browser extensions, such as, AdBlock and Ghostery. We show that an extension's organic activity in a page's DOM can be used to infer its presence, and develop XHOUND, the first fully automated system for fingerprinting browser extensions. By applying XHOUND to the 10,000 most popular Google Chrome extensions, we find that a significant fraction of popular browser extensions are fingerprintable and could thus be used to supplement existing fingerprinting methods. Moreover, by surveying the installed extensions of 854 users, we discover that many users tend to install different sets of fingerprintable browser extensions and could thus be uniquely, or near-uniquely identifiable by extension-based fingerprinting. We use XHOUND's results to build a proof-of-concept extension-fingerprinting script and show that trackers can fingerprint tens of extensions in just a few seconds. Finally, we describe why the fingerprinting of extensions is more intrusive than the fingerprinting of other browser and system properties, and sketch two different approaches towards defending against extension-based fingerprinting. Our results highlight the danger of extension-based fingerprinting which, in conjunction with existing fingerprinting techniques, can greatly boost the accuracy of stateless, user identification. Moreover, our findings are likely to be applicable to mobile platforms where most browsers have poor or no support for plugins, yet popular browsers, such as, Firefox Mobile and Dolphin Browser for Android, and Chrome for iOS [32] , support extensions. To address the threat of extension-based fingerprinting, we first briefly discuss the difficulty of protecting against it, and then sketch two possible countermeasures, based on isolating DOM changes and constructively polluting the DOM namespace. II. BACKGROUND In this section, we first provide a brief comparison of browser extensions and browser plugins and then list the threat models that we will use throughout this paper.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4a375579-cb72-44ec-bcba-44e417462c00Cited by top-tier papers40
- Acquisitional Rule-based Engine for Discovering Internet-of-Thing DevicesXuan Feng, Qiang Li, Haining Wang, Limin SunUSENIX Security 2018 · 139 citations
- The Web's Sixth Sense: A Study of Scripts Accessing Smartphone SensorsAnupam Das, Gunes Acar, Nikita Borisov, Amogh PradeepCCS 2018 · 91 citations
- Oh, the Places You've Been! User Reactions to Longitudinal Transparency About Third-Party Web Tracking and InferencingBen Weinshel, Miranda Wei, Mainack Mondal, Euirim Choi et al.CCS 2019 · 73 citations
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 60 citations
- Fp-Scanner: The Privacy Implications of Browser Fingerprint InconsistenciesAntoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain RouvoyUSENIX Security 2018 · 52 citations
Builds on2
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
Related papers
- Fingerprinting in Style: Detecting Browser Extensions via Injected Style SheetsPierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos et al.USENIX Security 2021 · 49 citations
- Everyone is Different: Client-side Diversification for Defending Against Extension FingerprintingErik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis et al.USENIX Security 2019 · 43 citations
- Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and InteractionsShubham Agarwal, Aurore Fass, Ben StockCCS 2024 · 4 citations
- Carnus: Exploring the Privacy Threats of Browser Extension FingerprintingSoroush Karami, Panagiotis Ilia, Konstantinos Solomos, Jason PolakisNDSS 2020
- Double-Edged Shield: On the Fingerprintability of Customized Ad BlockersSaiid El Hajj Chehade, Ben Stock, Carmela TroncosoUSENIX Security 2025
