Solved

Info that can be obtained to "finger print" users to keep them unique?

Posted on 2013-06-03
8
184 Views
Last Modified: 2014-05-31
I come to you today with a unqiue issue.

We have a web application that people access, they need to go to our website first to download the application.

We want to do specific promotions however we do not want people abusing it by using the same computer for example to sign up multiple times.

I know that alot of info can only be obtained with active x and java and user prompts.

What data can be obtained with out needing admin local rights to pull user data?

Harddrive serial number?
CPU ID's ?

I know that OS and screen res and such can be had, but this can be changed, looking for things a little more unique to the users system.

Any help is appreciated
0
Comment
Question by:Mathiau
8 Comments
 
LVL 7

Accepted Solution

by:
msifox earned 167 total points
ID: 39216849
You cannot really prevent it reliably.
That said, flash cookies are more difficult to get rid of than http cookies, so that's often used. And/or you could enforce people providing correct email addresses. Some people may have two or three, but most cannot quickly come up with many more, and it's time consuming to generate really lots of them.
Also your application could hide info in registry, %CommonProgramFiles% and other places.
0
 
LVL 2

Author Comment

by:Mathiau
ID: 39216887
Ya, that is what i had assumed, we plan to use both types of cookies where possible, the people who use are app, there are some who will get creative, so i wanted to see how much more info we could get that is basically "open" with out prompting the user to allow something to run.

Once our application is installed we do gather other info to create a uniqueID, but we wanted to see if we could implement a system prior to them even downloading our software to get as many points to create a score / ID for a user and if they pass of fail.
0
 
LVL 53

Assisted Solution

by:COBOLdinosaur
COBOLdinosaur earned 333 total points
ID: 39216953
The flash cookies are actually not difficult to get rid of all it takes is the FF addon BetterPrivacy which has a rating of 5 stars out of 5 and I would not be without it.

In the end you will not prevent abuse, you might reduce it, but that just gives a bigger advantage to the cheaters, and if you are offering real value yu just create a market for those willing to sell or give away easy workarounds.

Cd&
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 
LVL 2

Author Comment

by:Mathiau
ID: 39231812
So i assume short of cookies there really is nothing else that can be obtained with out user prompts like hardware ID's, mac address or anything?
0
 
LVL 53

Assisted Solution

by:COBOLdinosaur
COBOLdinosaur earned 333 total points
ID: 39231827
In general the mac address can only be obtained in a localized environment like a lan.  Across the internet it is not going to happen.

Cd&
0
 
LVL 2

Author Comment

by:Mathiau
ID: 39231897
I was reading about that, as the mac never goes past the router, learn something new everyday!
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 40103189
I've requested that this question be closed as follows:

Accepted answer: 168 points for msifox's comment #a39216849
Assisted answer: 166 points for COBOLdinosaur's comment #a39231827
Assisted answer: 166 points for COBOLdinosaur's comment #a39216953

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Since upgrading to Office 2013 or higher installing the Smart Indenter addin will fail. This article will explain how to install it so it will work regardless of the Office version installed.
Whether you’re a college noob or a soon-to-be pro, these tips are sure to help you in your journey to becoming a programming ninja and stand out from the crowd.
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…
In this fourth video of the Xpdf series, we discuss and demonstrate the PDFinfo utility, which retrieves the contents of a PDF's Info Dictionary, as well as some other information, including the page count. We show how to isolate the page count in a…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now