Information Leaks via Safari's Intelligent Tracking Prevention

01/21/2020
by   Artur Janc, et al.
0

Intelligent Tracking Prevention (ITP) is a privacy mechanism implemented by Apple's Safari browser, released in October 2017. ITP aims to reduce the cross-site tracking of web users by limiting the capabilities of cookies and other website data. As part of a routine security review, the Information Security Engineering team at Google has identified multiple security and privacy issues in Safari's ITP design. These issues have a number of unexpected consequences, including the disclosure of the user's web browsing habits, allowing persistent cross-site tracking, and enabling cross-site information leaks (including cross-site search). This report is a modestly expanded version of our original vulnerability submission to Apple (WebKit bug #201319), providing additional context and edited for clarity. A number of the issues discussed here have been addressed in Safari 13.0.4 and iOS 13.3, released in December 2019.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/27/2021

Masked LARk: Masked Learning, Aggregation and Reporting worKflow

Today, many web advertising data flows involve passive cross-site tracki...
research
03/26/2018

Secure Web Access Control Algorithm

The paper presents a flexible and efficient method to secure the access ...
research
11/13/2021

Categorizing Service Worker Attacks and Mitigations

Service Workers (SWs) are a powerful feature at the core of Progressive ...
research
04/03/2020

A "Final" Security Bug

This article discusses a fixed critical security bug in Google Tink's Ed...
research
01/22/2021

My Mouse, My Rules: Privacy Issues of Behavioral User Profiling via Mouse Tracking

This paper aims to stir debate about a disconcerting privacy issue on we...
research
05/14/2020

DjangoChecker: Applying Extended Taint Tracking and Server Side Parsing for Detection of Context-Sensitive XSS Flaws

Cross-site scripting (XSS) flaws are a class of security flaws that perm...
research
09/14/2021

What's in Your Wallet? Privacy and Security Issues in Web 3.0

Much of the recent excitement around decentralized finance (DeFi) comes ...

Please sign up or login with your details

Forgot password? Click here to reset