API de status da bateria empregada por motivos de rastreamento on-line


O rastreamento é um dos graves problemas de privacidade que os usuários enfrentam diariamente. Se uma parte quiser obter suas informações pessoais, pode ser bastante criativo nas formas de obtê-lo. One of the most recent methods of non-standard data collection is through the so-called Battery Status API, an HTML5 standard for browsers.

What Is a Battery Status API?

The Battery Status API, more often referred to as the Battery API, provides information about the system’s battery charge level and lets you be notified by events that are sent when the battery level or charging status change. This can be used to adjust your app’s resource usage to reduce battery drain when the battery is low, or to save changes before the battery runs out in order to prevent data loss. (através da

Researchers from Princeton University have now proved that the Battery API also allows a site owner to ask for the specific device’s current battery level or charging status. This potential privacy risk which was brought to light last year is now becoming a real concern.

relacionado: Tor Browser Users Fingerprinting Is Possible

A little-known feature of the HTML5 specification means that websites can find out how much battery power a visitor has left on their laptop or smartphone – and now, security researchers have warned that that information can be used to track browsers online, the Guardian wrote back then.

Curiosamente, the authors of the standard didn’t think it would start a fingerprinting issue. Contudo, it later turned out that the highly-detailed readings can actually administer a pseudo-unique identifier for every device.

Two Scripts Exploit the Battery Status API to Fingerprint Users

Steven Englehardt and Arvind Narayanan, Princeton researchers, discovered two scripts that employ the Battery API to fingerprint users online.

Their discoveries are part of a large-scale, ongoing investigation that is entirely focused on tracking. Researchers use a special privacy tool called OpenWPM (running on Firefox) which identifies tracking techniques across the Internet.

relacionado: Stop Targeted Ads from Following you

One of the scripts mentioned above retrieves the current charge level of the device and adds it to other fingerprint details and the user’s local IP address. The other script retrieves the current charging status, the charge level, and the amount of remaining time to recharge.

One of the original researchers that first stumbled upon this problem, Lukasz Olejnik, says that those readings could be exploited for other means as well:

Além disso, some companies may be analyzing the possibility of monetizing the access to battery levels. When battery is running low, people might be prone to someotherwise differentdecisions. In such circumstances, users will agree to pay more for a service.

To face this privacy issue, some browser vendors are considering the option to restrict or completely remove access to battery readout mechanisms.

Milena Dimitrova

Milena Dimitrova

Um escritor inspirado e gerenciador de conteúdo que foi com SensorsTechForum desde o início. Focada na privacidade do usuário e desenvolvimento de malware, ela acredita fortemente em um mundo onde a segurança cibernética desempenha um papel central. Se o senso comum não faz sentido, ela vai estar lá para tomar notas. Essas notas podem mais tarde se transformar em artigos! Siga Milena @Milenyim

mais Posts

Me siga:

Deixe um comentário

seu endereço de e-mail não será publicado. Campos obrigatórios são marcados *

limite de tempo está esgotado. Recarregue CAPTCHA.

Compartilhar no Facebook Compartilhar
Compartilhar no Twitter chilrear
Compartilhar no Google Plus Compartilhar
Partilhar no Linkedin Compartilhar
Compartilhar no Digg Compartilhar
Compartilhar no Reddit Compartilhar
Partilhar no StumbleUpon Compartilhar