Cookies, Supercookies and Ubercookies: Stealing the Identity of Web Visitors
33bits.org
33bits.org
tptacek commented that it was a "batshit crazy idea," and that is exactly right. This article is an example of how to (really) abuse history stealing. As promised, a stronger variant I've been working on is coming soon.
Another way to look at it is, "Imagine how horrific the impact of this problem is going to become as researchers and criminals weaponize it. There is no way this browser behavior is going to survive. Therefore, it is a very bad idea for us to rely on it in any way."
It's also a nice clean example of how weaponization, exploit development, and full disclosure can move security forward. The worse this problem gets, the more likely it is that it will get fixed.
Wouldn't this break one of the fundamentally nice things about the web? Being able to refer to a page by a known fixed identity that can be bookmarked and passed around?
Wouldn't it be a far better solution to fix the history sniffing issue at the browser level, even if it means that css\javascript that relies on being able to read a:visited (or whatever else) no longer work?