Your Web Browser Verifies You

The Electronic Freedom Foundation web site http://panopticlick.eff.org has an interesting experiment underway. Of the 806,321 persons who had visited that site, no one had the same identifying characteristics as me. A web connection shares a great deal of information in case the destination site can produce a richer experience for the client. Unlike many communication approaches, capabilities aren’t negotiated; they’re reported.

Of 806,321, I am the only one with this particular set. In a way, this is like a fingerprint. The set lacks the permanence of a fingerprint (web browser characteristics change) and it is the fingerprint of the web browser on a machine. Multiple web browsers will give a machine multiple fingerprints. Multiple machines will give a person multiple fingerprints.

This can be just enough consistency to become a second factor (a “something you have”) in a two factor authentication process. Your userid / password combination maps to the device (web browser) that you usually use.

Four months later, using a different (although superficially similar) machine: 1,083,078 clients had visited, and no one matched my configuration. See Peter Eckersley’s “How Unique Is Your Web Browser?” [pdf].

See also: What’s My User Agent?

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.