WordPress "Attempted to extract html5 canvass image data" security warning
-
Seems there is a strange issue when viewing ANY of my WordPress sites with Tor Browser, that worries me somewhat. WP sites always return the following error:-
“The website (whatever.com) attempted to extract HTML5 canvass image data, which may be used to uniquely identify your computer.
Should Tor Browser allow this site to extract HTML5 canvass image data?”
All my sites are running WordPress 4.4.2. To replicate issue, simply install fresh copy of WP, no plugins, then view it with latest Tor Browser (5.5.2). Alternatively open any modern WordPress site you like on the latest Tor Browser, e.g. https://www.softaculous.com/demos/WordPress
I should add that my Joomla sites do not exhibit this behaviour. In fact, the only other sites I can find that regularly do this are running nasties such as AddThis. I also understand that canvass fingerprinting is becoming an increasing concern amongst security researchers. So my questions:-
What “HTML5 canvass image data” is WordPress trying to extract?
Why does it need to do so when other CMS’s don’t?
What WordPress code is causing it to happen?
And how do I prevent it from doing so in the future?Tor Browser is becoming increasingly popular. Even if these messages are caused by relatively harmless behaviour, it is still rather embarrassing for WP-based sites to be throwing scary messages of this sort.
All help gratefully appreciated. Many thanks in advance.
- The topic ‘WordPress "Attempted to extract html5 canvass image data" security warning’ is closed to new replies.