


Implementing 'fingerprint identification' technology based on HTML Canvas_html/css_WEB-ITnose
作者:zhanhailiang 日期:2015-01-31
Description
The so-called fingerprint identification refers to identifying a unique identifier (hereinafter referred to as UUID) for each device. Apps such as mobile native apps can obtain the corresponding UUID by calling the relevant device API. However, the WebAPP in the browser cannot directly access the device API due to the operating environment. In this case, other methods need to be used to set the UUID.
Generate UUID based on persistent cookies
Principle
When a user visits a website, the website can plant a cookie containing UUID in the user's current browser cookie, and Through this information, all user behaviors (which pages were browsed? What keywords were searched? What are you interested in? Which buttons were clicked? What functions were used? What products were viewed? What were put into the shopping cart, etc.) stand up.
Implementation
function rand(len) { var hex = "0123456789abcdef", str = "", index = 0; for (len = len || 32; len > index; index++) { str += hex.charAt(Math.ceil(1e8 * Math.random()) % hex.length); } return str;}var uuid = (new Date).getTime() + "_" + rand();// 写持久化cookie,两年后过期// setcookie('uuid', uuid, 732 * 24 * 60 * 60);
Disadvantages
UUID can then be used to implement user tracking technology to facilitate subsequent data analysis.
However, as the Internet attaches more importance to personal privacy, Cookies are becoming less and less popular. Many security tools and even browsers have begun to allow or guide users to turn off cookie functions. For example, many mainstream browsers have a "privacy mode" function. In this way, it is difficult for websites to track user behavior through cookies. But there are still some ways for websites to track the behavior of each visitor. For example, flash cookies can also be used to achieve unique identification and tracking purposes.
Implementing "fingerprint recognition" technology based on HTML Canvas
Principle
Draw a picture with specific content based on Canvas, and use the canvas.toDataURL() method to return the base64 encoding of the picture content String. For the PNG file format, it is divided into chunks. The last chunk is a 32-bit CRC check code. Extracting this CRC check code can be used to uniquely identify the user.
The test results show that the CRC check code generated by the same browser when accessing this domain always remains unchanged. It can be simply understood as the same HTML Canvas element drawing operation. On different operating systems and different browsers, the image content generated is actually not exactly the same. There may be several reasons for this situation:
- In terms of image formats, different web browsers use different graphics processing engines, different image export options, different default compression levels, etc.
- At the pixel level, operating systems each use different settings and algorithms for anti-aliasing and sub-pixel rendering operations.
- Even if it is the same drawing operation, the final image data generated is still different at the hash level.
Implementation
function bin2hex(s) { // discuss at: http://phpjs.org/functions/bin2hex/ // original by: Kevin van Zonneveld (http://kevin.vanzonneveld.net) // bugfixed by: Onno Marsman // bugfixed by: Linuxworld // improved by: ntoniazzi (http://phpjs.org/functions/bin2hex:361#comment_177616) // example 1: bin2hex('Kev'); // returns 1: '4b6576' // example 2: bin2hex(String.fromCharCode(0x00)); // returns 2: '00' var i, l, o = '', n; s += ''; for (i = 0, l = s.length; i < l; i++) { n = s.charCodeAt(i) .toString(16); o += n.length < 2 ? '0' + n : n; } return o;}function getUUID(domain) { var canvas = document.createElement('canvas'); var ctx = canvas.getContext("2d"); var txt = domain; ctx.textBaseline = "top"; ctx.font = "14px 'Arial'"; ctx.textBaseline = "tencent"; ctx.fillStyle = "#f60"; ctx.fillRect(125,1,62,20); ctx.fillStyle = "#069"; ctx.fillText(txt, 2, 15); ctx.fillStyle = "rgba(102, 204, 0, 0.7)"; ctx.fillText(txt, 4, 17); var b64 = canvas.toDataURL().replace("data:image/png;base64,",""); var bin = atob(b64); var crc = bin2hex(bin.slice(-16,-12)); return crc;}console.log(getUUID("http://m.vip.com/"));
Advantages
UUID generated based on HTML Canvas can be effectively used for user tracking technology, which is currently not available Effective countermeasures.
More reading
- Client-Side: HTML5 Canvas Fingerprinting
- Website tracking technology that replaces cookies: A preliminary study on "canvas fingerprinting"
- JavaScript bin2hex function
- Comparison of existing IOS device unique identifier solutions
- Is there a unique Android device ID?

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

The official account web page update cache, this thing is simple and simple, and it is complicated enough to drink a pot of it. You worked hard to update the official account article, but the user still opened the old version. Who can bear the taste? In this article, let’s take a look at the twists and turns behind this and how to solve this problem gracefully. After reading it, you can easily deal with various caching problems, allowing your users to always experience the freshest content. Let’s talk about the basics first. To put it bluntly, in order to improve access speed, the browser or server stores some static resources (such as pictures, CSS, JS) or page content. Next time you access it, you can directly retrieve it from the cache without having to download it again, and it is naturally fast. But this thing is also a double-edged sword. The new version is online,

The article discusses using HTML5 form validation attributes like required, pattern, min, max, and length limits to validate user input directly in the browser.

This article demonstrates efficient PNG border addition to webpages using CSS. It argues that CSS offers superior performance compared to JavaScript or libraries, detailing how to adjust border width, style, and color for subtle or prominent effect

Article discusses best practices for ensuring HTML5 cross-browser compatibility, focusing on feature detection, progressive enhancement, and testing methods.

The article discusses the HTML <datalist> element, which enhances forms by providing autocomplete suggestions, improving user experience and reducing errors.Character count: 159

The article discusses the HTML <progress> element, its purpose, styling, and differences from the <meter> element. The main focus is on using <progress> for task completion and <meter> for stati

This article explains the HTML5 <time> element for semantic date/time representation. It emphasizes the importance of the datetime attribute for machine readability (ISO 8601 format) alongside human-readable text, boosting accessibilit

The article discusses the HTML <meter> element, used for displaying scalar or fractional values within a range, and its common applications in web development. It differentiates <meter> from <progress> and ex
