New Fingerprinting Method Uses Browser Storage to Track Users
TL;DR. Researchers developed "Frost," a novel browser fingerprinting technique that identifies users by exploiting timing differences in the IndexedDB API. - The method leverages the varying storage access times inherent to different system hardware for identification. - Frost bypasses current anti-fingerprinting measures by operating within legitimate browser APIs. - The technique poses a significant privacy risk, enabling persistent tracking without traditional cookies.
- A new browser fingerprinting technique, Frost, exploits timing differences in the IndexedDB API.
- Frost creates unique device signatures by measuring the speed of data writes and reads in local storage.
- This method bypasses common anti-tracking mechanisms that block traditional fingerprinting scripts.
- The research highlights a critical vulnerability in web privacy and calls for browser-level mitigation.
Sources
- Frost: [Browser] Fingerprinting Remotely Using OPFS-Based SSD Timing [pdf] — hannesweissteiner.com