Sniff browser history for improved user experience
niallkennedy.com
niallkennedy.com
There is no discussion of the privacy issues, which seems like a huge omission. I wouldn't use this on a website unless you like playing with fire.
Summary: To mitigate, either (a) tell your browser not to save any history, or (b) in Firefox, go to about:config and turn off layout.css.visited_links_enabled. (Chrome doesn't seem to have about:config ...)
This should probably be the default ...
Another workable approach are keeping a full history graph, and only showing visited links on the site where you originally clicked on them.
Or, the browser could highlight visited links in a way that can't be detected with JavaScript code.
This isn't hard to fix, so obviously we just haven't been complaining loud enough.
http://www.mikeonads.com/2008/07/13/using-your-browser-url-h...
Since changing browsers to prevent this will not happen tomorrow, this can be partially worked around both server and client-side.
Server-side: If you have any sensitive URIs you don't want leaked or brute-forced, add an extra parameter containing a random value. URIs you might want to protect are those with XSRF tokens or session IDs. URIs can be brute-forced locally on the victim at a speed of approximately 40,000 URIs per second.
Client-side: Use incognito mode for sensitive surfing. Plugins such as noscript can partially defend against this, however it's possible to do history detection using pure CSS which I believe will work even if you're using noscript. Update: Fixnum posted another client-side solution "in Firefox, go to about:config and turn off layout.css.visited_links_enabled"
History trick here (JS, no cookies, can poll user's web history): http://jeremiahgrossman.blogspot.com/2006/08/i-know-where-yo...
I'm pretty sure it's beeing used in loads of places by now - there's probably (/should be) a jQuery plugin for it, even.
I'm wondering why this is making it to HN now, 2 years later?
No, there shouldn't. Taking advantage of this design flaw is no better than trying to send a Javascript exploit to read my history file directly. I'm surprised that supposedly legitimate sites think using it is an acceptable practice, but I guess I shouldn't be.