Picasso: Light-weight device class fingerprinting for web clients
Elie Bursztein, Artem Malyshev, Tadek Pietraszek, Kurt Thomas
Picasso: Light-weight device class fingerprinting for web clients - - PowerPoint PPT Presentation
Picasso: Light-weight device class fingerprinting for web clients Elie Bursztein , Artem Malyshev, Tadek Pietraszek, Kurt Thomas Title Interesting story here Subpoint g.co/research/protect Keeping online interactions meaningful
Elie Bursztein, Artem Malyshev, Tadek Pietraszek, Kurt Thomas
g.co/research/protect
Subpoint
g.co/research/protect
g.co/research/protect
Trust required Interaction Impact
Account recovery Bank transfer Content creation Content consumption Content like
g.co/research/protect
Trust
Human interaction
Phone call SMS Hard captcha No captcha Picasso
g.co/research/protect
Allow to enforce quotas and help anomaly detection
Enforce that attacker will expend 20ms of iOS time per request
g.co/research/protect
Any platform (Android, iOS) and any language (Javascript, SWIFT)
Safari on iPhone vs Safari on an emulator
Chrome OSX vs Safari OSX, Chrome Windows vs Chrome OSX
g.co/research/protect
Must run on off-the-shelf devices
Code to be shipped to clients and potentially executed offline
Can be downloaded/executed often even on low-end devices
g.co/research/protect
g.co/research/protect
g.co/research/protect
Challenge id
Graphical instruction Graphical instruction Graphical instruction Graphical instruction Graphic rendering
Image unique to device type
g.co/research/protect
g.co/research/protect
g.co/research/protect
g.co/research/protect
g.co/research/protect
Chrome vs Firefox Chrome vs Safari Firefox vs Safari
g.co/research/protect
Red imply pixels are differents
g.co/research/protect
Fraction of challenge response which are unique to a given device class
Number of distinct challenges response generated by a given class of device
g.co/research/protect
Stability
Picasso
g.co/research/protect
Uniqueness
Picasso
g.co/research/protect
g.co/research/protect
g.co/research/protect
g.co/research/protect
g.co/research/protect
g.co/research/protect
g.co/research/protect