mirror of
https://github.com/imputnet/helium.git
synced 2026-08-20 00:57:32 +02:00
26252d38c2
Chromium's canvas noising was mostly removed in 3 parts, which landed in 144: 1. https://crrev.com/1537919 2. https://crrev.com/1538396 3. https://crrev.com/1538814 Prior to 144, Helium relied on Chromium's implementation of Canvas noising for fingerprinting protection, as it was the best option at the time. Now that it's no longer available, we had to either revert the removal, or come up with our own implementation. Helium Noise is something in-between: it builds on top of Chromium's implementation, but removes extras and extends it further. Key highlights of this implementation: - Completely independent, doesn't rely on any remaining bits of Chromium's deprecated implementation. - Noise isn't locked to just Canvas, it's built with extensibility in mind, so we can implement fingerprint deception for more browser APIs in the future. - Noise generates unique BrowserContext tokens per feature (kCanvas, kAudio, etc) to prevent (highly unlikely) correlation. Aka the way it should be implemented. - Canvas is noised only during readback, just like in Chromium's implementation. - Canvas noising works without hardware acceleration unlike Chromium's implementation. I've also updated AudioContext fingerprint deception to use Helium Noise, just like Canvas. This should fix #249, because AudioContext fingerprint is now consistent within an origin and BrowserContext. More testing is needed, as I'm unable to replicate the original issue on previous builds.