Brave recently fortified user defenses against covert tracking mechanisms that function entirely without cookies. Starting with version 1.93, the browser actively obfuscates graphics card and driver specifications. Consequently, this obfuscation makes it exceedingly difficult for websites to differentiate individual computers.
The Mechanics of Graphics-Based Tracking
Exploiting WebGL and WebGPU
Websites frequently exploit WebGL and WebGPU application programming interfaces for this specific type of surveillance. Browsers typically require these interfaces to render complex, hardware-accelerated graphics. However, these identical interfaces also broadcast highly detailed device specifications. Therefore, a website can effortlessly discover the exact manufacturer and model of a graphics processing unit. Furthermore, it can retrieve precise driver details and a comprehensive list of supported graphical capabilities.
Creating a Persistent Digital Fingerprint
This granular information serves as excellent raw material for creating a unique browser fingerprint. The tracking system aggregates numerous device parameters into a singular, persistent identifier. Subsequently, this identifier allows entities to recognize a specific user across diverse websites. Thus, traditional cookies become entirely unnecessary under this sophisticated tracking scheme. Furthermore, graphics card characteristics prove exceptionally convenient for surveillance because a computer’s hardware configuration rarely changes.
Brave’s Countermeasures in Version 1.93
Analyzing the Surveillance Threat
Brave engineers meticulously analyzed how popular websites interact with WebGL and WebGPU APIs. They ultimately concluded that many sites harvested this data specifically to generate digital fingerprints. For instance, WebGL can inadvertently expose the precise nomenclature of a user’s graphics hardware. Additionally, the list of supported extensions varies wildly across different graphics cards and driver versions.
Implementing Universal Hardware Spoofing
In version 1.93, Brave began substituting the genuine manufacturer and graphics device names within WebGL with a universal value. Thanks to this clever scheme, different users’ browsers return identical information to probing websites. They no longer transmit accurate hardware traits. Furthermore, the browser now intentionally leaves the adapter data provided by WebGPU entirely blank. For an in-depth technical overview, users can review how Brave implements WebGL and WebGPU fingerprinting protections.
Randomizing Extension Lists
Brave also strategically alters the reported list of WebGL extensions. The browser injects randomized variations independently for every individual session and visited website. Consequently, this randomization makes it incredibly difficult for tracking services to transform supported features into a constant identifier. Meanwhile, developers strived to maintain normal graphical performance without outright blocking WebGL and WebGPU functionalities.
Deployment Details and Future Plans
Gradual Rollout and User Controls
This novel protection comes enabled by default within the desktop and Android versions of the Brave browser. However, developers are rolling out this feature gradually. Therefore, some users running version 1.93 might not receive these changes immediately. Previously, engineers rigorously tested this mechanism for several months within the Nightly and Beta preliminary builds.
Suppose this robust protection disrupts graphical rendering on a specific website. In that case, Brave can dynamically adjust its rules exclusively for that particular resource. Alternatively, a user can manually disable these graphical interface protections. They can also deactivate all digital fingerprinting defenses or completely disable the entire Shields system.
Upcoming Privacy Enhancements
Developers plan to further minimize the volume of information these graphical interfaces expose to external websites. Specifically, Brave intends to inject randomized alterations into the WebGPU capabilities list soon. Ultimately, their primary objective remains unchanged. They want to deprive tracking services of a stable hardware characteristic set without breaking websites that rely on hardware-accelerated graphics.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.