Every story tagged Fingerprinting, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
Since Chrome 148, a critical fingerprinting vulnerability has emerged where the Math.tanh() function returns slightly different bit-level results across operating systems (Linux, macOS, Windows) due to reliance on platform-specific math libraries, enabling threat actors and anti-bot systems to reliably identify users' underlying OS despite spoofed User-Agents. This represents a significant privacy and security risk for organizations managing browser-based access controls, as attackers can now defeat device verification mechanisms that rely on consistency checks between reported and actual OS signatures. IT leaders must assess the exposure of their web applications and authentication systems to this fingerprinting vector and coordinate with security teams to implement detection mechanisms while monitoring for exploitation by malicious actors.
Cloudflare Turnstile's bot verification now requires WebGL fingerprinting for device identification, effectively blocking privacy-focused browsers like WebKit-GTK and potentially future Firefox users with enhanced privacy protections enabled. This creates a strategic tension between security (bot prevention) and privacy, forcing IT organizations to choose between implementing Cloudflare protection or maintaining user privacy standards, while also exposing a broader industry trend toward invasive tracking justified by security measures. Organizations must evaluate whether this fingerprinting requirement aligns with their privacy commitments and consider the business impact of potentially excluding users with privacy tools or alternative browsers.