Proceedings 2021 Network and Distributed System Security Symposium 2021
DOI: 10.14722/ndss.2021.24202
|View full text |Cite
|
Sign up to set email alerts
|

Tales of Favicons and Caches: Persistent Tracking in Modern Browsers

Abstract: Statement from the NDSS 2021 Program Committee: NDSS is devoted to ethical principles and encourages the research community to ensure its work protects the privacy, security, and safety of users and others involved. While the NDSS 2021 PC appreciated the technical contributions of this paper, it was the subject of a debate in our community regarding the responsible disclosure of vulnerabilities for the Firefox web browser. The PC examined and discussed the ethics concerns raised and the authors' response. Alth… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
10
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
5
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 15 publications
(11 citation statements)
references
References 34 publications
0
10
0
Order By: Relevance
“…Stateful-tracking also describes other ways websites can set and read identifiers, by using APIs and browser capabilities not intended for such purposes. Examples of such techniques include exploiting the browser HTTP cache, DNS cache or other ways of setting long term state (e.g., HSTS instructions [1], favicon caches [2], or, ironically, storage intended to prevent tracking [3]).…”
Section: Relationship To Other Tracking Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…Stateful-tracking also describes other ways websites can set and read identifiers, by using APIs and browser capabilities not intended for such purposes. Examples of such techniques include exploiting the browser HTTP cache, DNS cache or other ways of setting long term state (e.g., HSTS instructions [1], favicon caches [2], or, ironically, storage intended to prevent tracking [3]).…”
Section: Relationship To Other Tracking Methodsmentioning
confidence: 99%
“…Distinct from browser fingerprinting, researchers have also found other ways of misusing browser features to construct unique user identifiers. Solomos et al [2] transformed the browser's "favicon" cache into a persistent tracking mechanism, Janc et al [3] showed that Safari's "Intelligent Tracking Prevention" 26 features could be abused to re-identify users, and Syverson and Traudt [1] showed how the browsers "HTTP Strict-Transport-Security" system could be re-purposed to construct and assign unique identifiers.…”
Section: A Online Tracking Through Feature Misusementioning
confidence: 99%
“…These modes prevent websites from accessing cookies stored in non-private mode, and it erases browsing history, search history, and cookies upon exit. However, private browsing modes have historically not removed all forensic traces [27,28]. Prior work has also shown that many users are unaware of private browsing modes, and many of those who are aware do not understand the actual privacy protections offered by these modes [13].…”
Section: Related Workmentioning
confidence: 99%
“…Subtle errors can lead to tracking. For example, Solomos et al recently showed that malicious websites could bypass incognito mode on all major browsers using favicons [27]. ResidueFree avoids such tracking by eliminating all persistent data.…”
Section: Motivation: Case Studies Of Popular Application Residuesmentioning
confidence: 99%
See 1 more Smart Citation