Apple said this week it refused to implement 16 new web technologies (Web APIs) in Safari because they posed a threat to user privacy by opening new avenues for capturing users' fingerprints.

The technologies that Apple refused to include in Safari due to concerns about user fingerprints are the following:
- Web Bluetooth – Allows websites to connect to nearby Bluetooth LE devices.
- Web MIDI API – Allows websites to enumerate, manipulate, and access MIDI devices.
- Magnetometer API – Allows websites to access data about the local magnetic field around a user, as detected by the device's primary magnetometer sensor.
- Web NFC API – Allows websites to communicate with NFC tags via a device's NFC reader.
- Device Memory API – Allows websites to get an approximate amount of device memory in gigabytes.
- Network Information API – Provides information about the connection a device uses to communicate with the network and provides a means for notifying scripts if the connection type changes.
- Battery Status API – Allows websites to obtain information about the battery status of the hosting device.
- Web Bluetooth Scanning – Allows websites to scan for nearby Bluetooth LE devices.
- Ambient Light Sensor – Allows websites to obtain the current light level or brightness of the environment around the hosting device via the device's native sensors.
- HDCP Policy Check extension for EME – Allows websites to check for HDCP policies, used in media streaming/playback.
- Proximity Sensor – Allows websites to retrieve data about the distance between a device and an object, as measured by a proximity sensor.
- WebHID – Allows websites to retrieve information about locally connected Human Interface Device (HID) devices.
- Serial API – Allows websites to write and read data from serial interfaces, used by devices such as microcontrollers, 3D printers, and others.
- Web USB – Allows websites to communicate with devices via USB (Universal Serial Bus).
- Geolocation Sensor – A more modern version of the older geolocation API that allows websites to access geolocation data.
- User Idle Detection – Notifies the website when a user is idle.
Apple claims that the 16 Web APIs above will allow online advertisers and data analytics companies in Safari to create scripts that fingerprint users on their devices.
User fingerprints are small scripts that an advertiser loads and runs inside each user's browser. The scripts perform a set of standard operations, usually against a common Web API or web browser feature, and measure the response.
Since each user has a different browser and operating system configuration, the responses are unique per user device. Advertisers use this unique response (fingerprint), combined with other fingerprints and data points, to create unique identifiers for each user.
Over the past three years, fingerprinting has become the standard method of user tracking in the online technology and advertising market.
The move to user fingerprinting comes as browser makers have developed anti-tracking features that have limited the capabilities and reach of third-party (tracking) cookies.
Some browser manufacturers have also developed countermeasures to prevent fingerprinting operations through the most common methods – such as fonts, HTML5 canvases, and WebGL.
Additionally, new ones are constantly being created as browser manufacturers add new Web APIs to code .
For now, Apple has identified the above 16 Web APIs as some of the worst violations. However, Apple said that if any of these new technologies “reduce the use of fingerprints” it will reconsider adding them to Safari.
" WebKit 's first line of defense against fingerprinting is to not implement web features that enhance fingerprinting capabilities and do not provide a secure way to protect the user ," Apple said.
For Web APIs that have already been implemented in Safari years ago, Apple says it is working to limit their fingerprinting vector. So far, Apple has stated the following:
- Support for custom fonts has been removed. This means that only built-in fonts that are the same for all users on the same system continue to work.
- Minimal software update information has been removed from the user agent string. The string only changes with the marketing version of the platform and browser.
- The Do Not Track flag, which was ironically used as a fingerprint vector, was removed, adding uniqueness to users who had it enabled.
- Support for any macOS. Other desktop ports may vary.
- Require user permission for websites to access device orientation/motion APIs on mobile devices, because the nature of motion sensors may allow fingerprinting of the device.
- Avoid fingerprinting of connected cameras and microphones via the Web Real-Time Communication API (WebRTC).
