New techniques expose your browsing history to attackers

Discussion in 'privacy problems' started by Minimalist, Nov 2, 2018.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  2. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    Huh?
    Seriously, that class of attacks is ancient!

    I mean, I'm just a punter, and I recall playing with that years ago.
     
  3. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  4. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    They gonna see my porn fetish stuff :isay:

    Personally, I browse with JS disabled by default, and only enable it on sites where JS is absolutely needed to load the content. Same goes for cookies. I only keep cookies on sites which I need to be logged in, or sites which won't load without enabling cookies, in which case I use "clear on exit" option for the cookies

    A temporary bandaid for this is to simply browse non-trusted sites in incognito mode, so no history will be seen. Ctrl + Shift + N is a quick shortcut for that. Then again, I highly doubt these techniques are used much in the wild, and if they are, I imagine the scripts will be blocked soon enough by various filters, just like those coin miners and other bad scripts
     
  5. Lyx

    Lyx Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    149
    The principle of this attack is indeed old. I think what's new is the rate at which sniffing is performed (the linked page talks about 6000 sites/s).
     
  6. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Changed the setting:

    "layout.css.visited_links_enabled"

    to "false" in New Moon; Basilisk, Firefox 52 ESR.

    This setting is also recommended on line 0805 of Ghacks User.js v.52:

    https://github.com/ghacksuserjs/ghacks-user.js/releases

    Comment by Moonchild:



    https://forum.palemoon.org/viewtopic.php?f=4&p=155514&sid=8420b82f982074de2a1f4bea60703011#p155514
     
  7. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    I think that the Tor Browser compared favourably in that research can be attributed to its Cross-Origin Identifier Unlinkability. This is what is called First-Party Isolation in Firefox. Hence, enabling FPI in Firefox shoulld mitigate this threat.
     
  8. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    The researchers write that the remedy mentioned:

    "layout.css.visited_links_enabled" set to "false"

    that should solve the problem in reality does not solve it.

    It's a bug.
     
  9. __Nikopol

    __Nikopol Registered Member

    Joined:
    Aug 13, 2008
    Posts:
    630
    Location:
    Germany
    Please elaborate why. (proof)
    EDIT: I mean, you are saying you know more than the researchers who just ended their research. Do you understand?
     
  10. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  11. __Nikopol

    __Nikopol Registered Member

    Joined:
    Aug 13, 2008
    Posts:
    630
    Location:
    Germany
    Oh, so they said it themselves. You could have written that :)
    I need to read the paper..
     
  12. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    thanks for the paper so deleting history + specialized tools do nothing to prevent this? it should work right? even the classical ctrl+shift+delete for chrome is sufficient?
    the only thing is that google would still keep track of your history forever and ever, but they are building an AI so let them have it

    I always thought the tracking of history is extremely useful for spear fishing or fishing emails with malicious links techniques
     
    Last edited: Jun 14, 2019
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes it works. Whatever deletes your history will help here.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.