{"id":"fdbb6379-4a64-4cd9-a09e-e297449e5318","arxiv_id":"1908.07965","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"Websites detected as using Canvas fingerprinting do not identify the technique in their privacy policies, making indirect tracking harder for users to block.","lead":"This paper examines whether websites that use Canvas fingerprinting, a technique that identifies devices by how they render images, disclose that practice in their privacy policies. It finds that none of the 28 sampled websites provide enough detail for a visitor to detect or block this indirect tracking method.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The 28-site sample rests on an unvalidated 2014 detector; without independent confirmation that each site actually Canvas-fingerprints, the policy non-disclosure claim is not fully anchored.","rationale":"The central claim is empirical: none of the 28 policies disclose Canvas fingerprinting specifically. Whether those 28 are genuinely Canvas fingerprinters is a precondition for the claim. The reader identifies the same vulnerability in the detector's completeness, and I agree, sharpening it with the false-positive issue. Because the paper argues by example (\"many sites\" for direct methods, \"none\" for indirect), the validity of the example set is critical. That said, the paper is explicitly a case study, it acknowledges the obfuscation limitation in Section 2.2, and the conclusion is hedged with \"often\" in the abstract. An unvalidated detector creates uncertainty, but no positive evidence suggests the 28-site finding is wrong. The proposed manual audit is cheap and would confirm the sample; until then, the verdict should not change. The policy-review subjectivity is a secondary concern but reinforces the value of an independent check. I therefore recommend UNCHANGED, with the suggestion that the authors publish the audit results as an appendix.","tokens_in":8485,"tokens_out":8177,"duration_ms":79559,"concrete_test":"Using an instrumented browser (e.g., OpenWPM with a Canvas-logging patch), load the main page of each of the 28 sites and record all canvas read operations (toDataURL, getImageData, etc.). Independently classify each site as \"fingerprinting\" if the site writes fixed text or graphics to a canvas and then reads the result back in a script that appears to send the data to a server. If any of the 28 sites fails this manual audit, re-run the privacy policy analysis on the validated subset; if the finding changes, the detector concern lands. Reporting the outcome of this audit would settle whether the sample is valid.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section 3.1 identifies Canvas fingerprinting sites using code from Acar et al. (2014), and Section 2.2 acknowledges that obfuscated fingerprinting techniques may evade detection. This admission exposes a load-bearing sub-assumption: the detector correctly and completely identifies the population of interest. The paper does not report a false-positive or false-negative rate on a 2019 corpus, nor does it manually verify any of the 49 detected sites. If the detector has false positives, some of the 28 policies describe sites that do not actually Canvas-fingerprint, making the \"no policy mentions Canvas\" result less probative. If it has false negatives, the sample may be biased toward sites using older, well-known scripts; such sites could plausibly have different privacy practices than sites using obfuscated methods. Because the paper extrapolates from these 28 policies to the broader statement that \"indirect fingerprinting methods are ... not identified with specificity in privacy policies,\" the sample selection is not merely a footnote limitation. Additionally, the policy categorization is based on manual review without a released codebook or inter-rater reliability, so the central classification is not independently auditable. Both issues are fixable but currently leave the empirical core of the paper more fragile than the strong wording of the conclusion suggests.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper presents a case study of whether privacy policies disclose indirect device fingerprinting, specifically Canvas fingerprinting. The authors used the Acar et al. (2014) detector on the Alexa Top 500 sites, identified 49 sites with Canvas fingerprinting, filtered to 28 English-language US-focused sites, and manually reviewed their privacy policies. They find that none of the 28 policies specifically mention Canvas fingerprinting, while many do disclose direct fingerprinting techniques. They conclude that indirect fingerprinting methods are often difficult to detect and are not identified with specificity in privacy policies, undermining users' ability to block them.","tokens_in":8685,"tokens_out":4739,"duration_ms":43043,"significance":"The paper addresses an important and understudied intersection of privacy law and technology. Its main contribution is a concrete, small-N empirical observation: on a sample of sites that appear to use Canvas fingerprinting, privacy policies provide insufficient technical granularity to allow technically savvy users to identify and block that technique. The use of a mixed legal-technical reviewing team is a strength, and the comparison between direct and indirect fingerprinting disclosures is instructive. If the finding holds, it has practical implications for FTC guidance and for privacy-enhancing tool design. However, the study is explicitly a case study, and its broader generalization should be read with caution; the conclusion is proportionally modest and the paper is transparent about its limitations.","major_comments":[{"comment":"The validity of the site selection rests on the Acar et al. (2014) detector, but the paper does not report any validation of that detector on a 2019 corpus, nor does it manually verify that the 28 sites actually engage in Canvas fingerprinting. Because the central finding is that policies of Canvas-fingerprinting sites do not mention the technique, false positives would weaken the link between the observed policy gap and the actual tracking practice. I recommend that the authors either manually confirm the presence of Canvas fingerprinting on the 28 sites or report the detector's expected error rates and discuss the sensitivity of the conclusion to those errors.","section":"Section 3.1"},{"comment":"The paper does not provide a codebook, complete quoted language for all categorized statements, or inter-rater reliability measures. The classification of policies into three categories and the determination that no policy specifically mentions Canvas fingerprinting rely on the authors' judgment. To make the analysis auditable, the authors should provide a supplementary table listing, for each of the 28 sites, the policy language that supports the coding, and ideally have a second pair of coders independently apply the same rules.","section":"Section 3.1, policy review"},{"comment":"The conclusion that 'indirect fingerprinting methods are often difficult to detect and are not identified with specificity in privacy policies' goes beyond the evidence presented. The study examines one indirect technique (Canvas fingerprinting) on 28 sites, all selected because they are detected as using that technique. The sample is not representatively drawn from all indirect fingerprinting implementations, and the word 'often' is not directly supported without a broader sampling frame. Please soften the conclusion to apply to the sampled sites or to Canvas fingerprinting specifically, and avoid implying a general statistical claim about all indirect fingerprinting methods.","section":"Abstract and Section 1"}],"minor_comments":[{"comment":"The claim that 'The most popular Firefox add-on for blocking Canvas fingerprinting has only about 46,000 average daily users as of August 2019' lacks a source; please provide a citation or link to the add-on statistics.","section":"Section 2.2"},{"comment":"The claim that 'Adblock Plus, a common ad-blocker, has 11 million average daily users on Firefox' also lacks a citation; please add a reference for this statistic.","section":"Section 2.2"},{"comment":"The GDPR discussion is framed as a conditional hypothesis ('If the GDPR requires attorneys to...'); consider labeling it explicitly as a hypothesis so that readers do not mistake it for a finding of the study.","section":"Section 3.3"},{"comment":"The text uses the phrase 'd´ etente' with an odd accent; please ensure the spelling is standardized to 'détente' throughout.","section":"Section 4.1"}],"recommendation":"minor_revision","confidential_remarks":"This is a sound but modest case study. The main empirical finding is clearly stated and the limitations are mostly acknowledged. The detector-validation concern is real but addressable with a short sensitivity discussion or manual verification of a subset. The paper fits the scope of cs.CY and would be a useful contribution after the requested revisions are made."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nRead the Milligan et al. case study. The short version: it's a careful little paper that actually does something new. It takes 28 sites that appear to Canvas-fingerprint, reads their privacy policies line by line, and shows that none of them name Canvas or any indirect method, while many name direct methods like cookies and beacons. That asymmetry is a real, concrete finding, and I don't think any of the prior detection papers made the disclosure comparison.\n\nThe paper earns credit for its framing. It's explicitly a case study, the sample is small, and the legal/technical author mix makes the manual review more credible than a single-discipline reading would be. The writing is clean, and the limitations are acknowledged in the body. The 'armistice' metaphor is a useful way to think about the direct-tracking ecosystem.\n\nSoft spots, in order of real weight. The 2014 Acar detector used on 2019 sites is the biggest one. They don't give false-positive or false-negative numbers for their corpus, and they don't manually confirm that all 49 detected sites actually Canvas-fingerprint. The stress-test note is right that false positives would blunt the 'none of the 28 policies mention Canvas' claim, because you'd be looking at policies of sites that maybe don't do it. That said, the authors do say 'It is possible we did not detect existing obfuscated fingerprinting techniques,' and they frame the study as a conservative detection exercise. So the weakness is real but the paper's conclusions are scoped tightly enough that it doesn't collapse.\n\nSecond: no released codebook and no inter-rater reliability numbers for the policy classification. Two people read each policy, but we only have their word that they categorized consistently. That's a minor-to-moderate transparency issue, fixable with an appendix.\n\nThird, minor: the leap from 'these 28 policies' to 'indirect fingerprinting methods are often ... not identified with specificity' in the abstract is a bit of extrapolation. The body stays closer to the data.\n\nBottom line: the central claim holds up for the sites examined, the study is honest about its limits, and the finding has real value for privacy-law and tracking-research audiences. It deserves a serious referee; I'd recommend asking for detector robustness checks and a released coding protocol, but accept the paper's empirical contribution either way. Yes, bring it to reading group; I'd cite it if writing about disclosure policy.\n\nRegards.","headline":"A modest, honest case study that shows a real gap in privacy-policy disclosure of Canvas fingerprinting; the main soft spot is the unvalidated 2014 detector, but the paper's careful scoping keeps the central claim intact.","tokens_in":9219,"tokens_out":3468,"would_cite":true,"duration_ms":31765,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"None of the 28 privacy policies in this case study discloses Canvas fingerprinting specifically enough for a visitor to detect and block it, although many of the same policies describe direct tracking methods in actionable detail.","keywords":["Canvas fingerprinting","indirect device fingerprinting","privacy policies","online tracking","direct fingerprinting","consumer disclosure","web measurement","FTC privacy"],"falsifier":"Run an independent crawl of the same Alexa Top 500 with a detector that also catches obfuscated or modified Canvas scripts, read the privacy policies of every confirmed site, and check whether any policy names Canvas or describes image rendering well enough to identify the technique. A single such policy would undercut the paper's strongest claim that none of the detected sites discloses indirect fingerprinting at that granularity.","tokens_in":8295,"feed_emoji":"🕵️","tokens_out":5229,"duration_ms":48641,"temperature":0.7,"pith_summary":"This paper asks whether privacy policies tell consumers enough about indirect device fingerprinting, a newer tracking approach that is harder to detect than direct methods. It focuses on Canvas fingerprinting, in which a website makes the browser render an image and reads back pixel-level differences that uniquely identify the device. Using an existing automated detector on Alexa Top 500 US-facing sites, the authors identified 28 sites that appear to use Canvas fingerprinting and then read every policy. None of the 28 policies named Canvas or described the technique specifically enough for a visitor to know it was in use, while many policies did give actionable detail about direct methods such as cookies, headers, and web beacons. If correct, the finding means the disclosure system that supports today's uneasy truce over direct tracking does not extend to indirect tracking, leaving users without the information needed to block it.","feed_headline":"No reviewed privacy policy discloses Canvas fingerprinting","feed_subtitle":"A review of 28 tracking sites finds policies detail cookies but stay silent on the indirect method users cannot block.","key_machinery":"The load-bearing mechanism is the direct-versus-indirect distinction, instantiated by Canvas fingerprinting. Canvas fingerprinting works by instructing the browser to draw a graphic through the HTML5 Canvas API and then reading back the rendered pixel data; subtle differences across hardware, fonts, and graphics libraries make the output a stable and highly distinguishing device identifier. Because the same API call can also be used for legitimate rendering, the technique is dual-use, so observing the call does not by itself reveal tracking. The paper's method comparison shows that privacy policies do not resolve this ambiguity, and the categories the authors develop for reading the policies are what allow them to compare disclosure specificity across sites.","core_discovery":"The central discovery is a mismatch between how privacy policies treat direct and indirect fingerprinting. On the paper's own terms, the same websites that disclose direct fingerprinting techniques in ways a technically savvy reader can act on are silent at the method level about Canvas fingerprinting. All 28 policies in the sample put readers on notice that the site collects device-identifying information, but none identifies the indirect technique by name or description. The paper groups the policies into three categories: broad technology-agnostic language, specific disclosure of direct techniques only, and one policy that names 'device or browser fingerprints' without naming Canvas. The consequence the authors draw is that a privacy-aware visitor cannot turn the policy into a technical block or reset, because she cannot learn which indirect method is in use.","pith_inferences":["An implication the authors leave implicit is that the disclosure gap could be narrowed without making policies longer: a single human-readable line naming the indirect technique, such as 'Canvas fingerprinting,' would give users the one missing fact needed to seek a targeted block.","The same asymmetry likely applies to the other inference-based methods the paper lists, such as font enumeration, GPU measurement, and sensor access, because they share the dual-use property that makes Canvas disclosures opaque; testing those techniques would show whether the finding generalizes.","A testable extension would be to give technically savvy users the list of detected Canvas sites and ask them to identify the practice from the privacy policies alone; the paper's claim predicts near-zero success.","Because the detector is conservative and the authors acknowledge it may miss obfuscated scripts, the 28 reviewed policies may be a best-case sample, meaning the true disclosure gap could be wider than measured."],"forward_implications":["Consumers who rely on ad blockers or cookie controls can no longer assume they have prevented tracking on sites that use indirect fingerprinting.","A technically sophisticated visitor cannot currently use a privacy policy to decide whether to block Canvas fingerprinting, because no policy in the sample provides the needed specificity.","The de facto armistice over direct tracking, in which sites disclose, privacy-aware users block, and sites tolerate the blockers, does not hold for indirect methods and may be disturbed as those methods spread.","Regulators and the lawyers who draft privacy policies may need to treat indirect fingerprinting as a distinct disclosure category rather than covering it with broad 'unique identifiers' language.","The sample shows no sign yet that GDPR-style pressure for greater technical detail has made indirect fingerprinting more transparent in these policies."],"supporting_citations":[{"why":"Supplies the automated detector and heuristics used in the paper's two web crawls to identify sites that use Canvas fingerprinting.","marker":"[1]"},{"why":"Provides the earlier 1-million-site measurement of Canvas fingerprinting prevalence and its third-party structure, justifying the paper's focus on Canvas as a detectable indirect method.","marker":"[8]"},{"why":"Establishes Canvas fingerprinting as a technique, defining the pixel-readback mechanism that the paper's direct-versus-indirect comparison relies on.","marker":"[14]"},{"why":"Supplies the Tor Browser team's characterization of Canvas fingerprinting as a leading fingerprinting threat, motivating the paper's concern about consumer self-defense.","marker":"[20]"},{"why":"Example of a policy the paper classifies as broad and technology-agnostic, showing disclosure that covers fingerprints without naming the technique.","marker":"[4]"},{"why":"Example of a policy that names device or browser fingerprints but not Canvas, supporting the finding of partial disclosure without method-level specificity.","marker":"[21]"},{"why":"Example of a policy that lists direct-tracking data fields such as browser type and IP address without naming Canvas, supporting the direct-versus-indirect comparison.","marker":"[22]"},{"why":"Used to argue that even tools meant to block fingerprinting can be detected by websites and turned into a fingerprint, supporting the difficulty of self-defense against indirect methods.","marker":"[17]"}],"fun_headline_variants":["Privacy policies hide Canvas fingerprinting","Canvas fingerprinting invisible in policies","Policies silent on Canvas tracking","Direct tracking disclosed, Canvas not","Study: 28 policies skip Canvas details"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The paper's results rest on the assumption that the automated detector from Acar et al. correctly and completely identifies sites that use Canvas fingerprinting; if sites obfuscate or vary their scripts, those sites fall out of the 28-policy sample and the measured disclosure gap could look different.","fun_headline_variants_meta":{"raw":{"variants":["Privacy policies hide Canvas fingerprinting","Canvas fingerprinting invisible in policies","Policies silent on Canvas tracking","Direct tracking disclosed, Canvas not","Study: 28 policies skip Canvas details"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00045,"raw_usage":{"total_tokens":2286,"prompt_tokens":981,"completion_tokens":1305,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":597,"completion_tokens_details":{"reasoning_tokens":1247}},"tokens_in":597,"tokens_out":1305,"duration_ms":8769,"temperature":1.0,"reasoning_tokens":1247,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T11:51:55.158612+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run an independent crawl of the same Alexa Top 500 with a detector that also catches obfuscated or modified Canvas scripts, read the privacy policies of every confirmed site, and check whether any policy names Canvas or describes image rendering well enough to identify the technique. A single such policy would undercut the paper's strongest claim that none of the detected sites discloses indirect fingerprinting at that granularity.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the automated detector and heuristics used in the paper's two web crawls to identify sites that use Canvas fingerprinting."},{"cited_title":"Englehardt and A","cited_arxiv_id":null,"evidence_quote":"Provides the earlier 1-million-site measurement of Canvas fingerprinting prevalence and its third-party structure, justifying the paper's focus on Canvas as a detectable indirect method."},{"cited_title":"Mowery and H","cited_arxiv_id":null,"evidence_quote":"Establishes Canvas fingerprinting as a technique, defining the pixel-readback mechanism that the paper's direct-versus-indirect comparison relies on."},{"cited_title":"Perry, E","cited_arxiv_id":null,"evidence_quote":"Supplies the Tor Browser team's characterization of Canvas fingerprinting as a leading fingerprinting threat, motivating the paper's concern about consumer self-defense."},{"cited_title":"CBS Privacy Policy Highlights , 2019","cited_arxiv_id":null,"evidence_quote":"Example of a policy the paper classifies as broad and technology-agnostic, showing disclosure that covers fingerprints without naming the technique."},{"cited_title":"Privacy Policy , 2019","cited_arxiv_id":null,"evidence_quote":"Example of a policy that names device or browser fingerprints but not Canvas, supporting the finding of partial disclosure without method-level specificity."},{"cited_title":"Yelp Privacy Policy, 2018","cited_arxiv_id":null,"evidence_quote":"Example of a policy that lists direct-tracking data fields such as browser type and IP address without naming Canvas, supporting the direct-versus-indirect comparison."},{"cited_title":"How canvas ﬁngerprint blockers make you easily trackable,","cited_arxiv_id":null,"evidence_quote":"Used to argue that even tools meant to block fingerprinting can be detected by websites and turned into a fingerprint, supporting the difficulty of self-defense against indirect methods."}],"review_version":1}