news.volyx.in

TeamViewer installs suspicious font only useful for web fingerprinting (ctrl.blog)

706 points by kevincox · 1514 days ago · 235 comments on HN

Article summary

TeamViewer, a remote desktop program, installs a unique font on Windows systems that can be used for web fingerprinting, allowing websites to detect if the software is installed. The font is not used by the TeamViewer software itself and is only bundled with the Windows version. This raises privacy concerns as it could be used to target TeamViewer customers with specific messaging. TeamViewer has announced that it will remove the font in a future release.

Main themes

  • font fingerprinting
  • privacy concerns
  • browser security
  • TeamViewer software
  • web tracking
  • user experience
  • fingerprinting vulnerabilities
  • local font access

What commenters say

  • The font's presence is a privacy concern as it can be used to fingerprint users and target them with specific messaging.
  • The font may be used for legitimate purposes, such as improving the user experience when connecting to a remote session.
  • Browsers should not load fonts installed in the operating system to prevent fingerprinting vulnerabilities.
  • The benefits of local fonts are negligible compared to the downsides, including fingerprinting and inconsistent rendering across platforms.
  • Some commenters believe that the font could be generated dynamically and uniquely for each installation, making it a more effective fingerprinting tool.
  • Others argue that the font's presence is not necessarily malicious and that its removal may not be necessary.
  • There are proposals to improve browser security and prevent fingerprinting, such as shipping with a set of standard fonts and requiring permission to access local fonts.
  • The ingenuity and resources devoted to tracking users are seen as a significant concern by some commenters.