Case Study: Disclosure of Indirect Device Fingerprinting in Privacy Policies
Julissa Milligan, Sarah Scheffler, Andrew Sellars, Trishita Tiwari,, Ari Trachtenberg, Mayank Varia

TL;DR
This study examines how indirect device fingerprinting, specifically Canvas fingerprinting, is disclosed in privacy policies and finds that such disclosures are often insufficient, making detection and blocking difficult for users.
Contribution
It provides a detailed analysis of privacy policy disclosures of indirect fingerprinting, highlighting their inadequacy compared to direct fingerprinting disclosures.
Findings
Disclosures of indirect fingerprinting are often vague and insufficient.
Many websites clearly disclose direct fingerprinting methods, aiding detection.
Indirect fingerprinting remains difficult to detect and block due to poor disclosures.
Abstract
Recent developments in online tracking make it harder for individuals to detect and block trackers. Some sites have deployed indirect tracking methods, which attempt to uniquely identify a device by asking the browser to perform a seemingly-unrelated task. One type of indirect tracking, Canvas fingerprinting, causes the browser to render a graphic recording rendering statistics as a unique identifier. In this work, we observe how indirect device fingerprinting methods are disclosed in privacy policies, and consider whether the disclosures are sufficient to enable website visitors to block the tracking methods. We compare these disclosures to the disclosure of direct fingerprinting methods on the same websites. Our case study analyzes one indirect fingerprinting technique, Canvas fingerprinting. We use an existing automated detector of this fingerprinting technique to conservatively…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
