Efficient history-stealing attack to identify website-visitors
33bits.org
33bits.org
It should be illegal. It's an invasion of privacy. Don't do it. Don't even learn that it is possible.
You're correct, It is an invasion of privacy. It is awful. But, I think it's better that this information be openly discussed by the tech community rather than hiding our heads in the sand.
At this point, I think the best that can be done is to make people aware of the practice. No browser should leak history by default. It's a huge security vulnerability, and should be regarded as such. Start putting pressure on Mozilla, Google, MS et al to fix it.
I guess really you just gotta delete your history all the time. Or make history links only work for the domain. If you see a link in a page that is not on the domain where the page originates, then make it the same color as the unvisited links.
In Chrome (dev only, currently, and weird / lacking the ability to manage them after install), use a "// @run-at document-start" line in your script: http://dev.chromium.org/developers/design-documents/user-scr...
In Opera, it looks like it always runs them first: http://www.opera.com/browser/tutorials/userjs/
And the important piece, something which can block this kind of probe, Caja: http://code.google.com/p/google-caja/
Obviously other possibilities exist, and this will likely need tweaking, but it's a solid start. If nothing else, it reads as a fairly simple how-to to make your own leaner version if you just want to target this.
Rather simple proposal for a fix: don't allow JS to read the :visited pseudo-class. I've yet to see anything use it cleverly anyway (though I fully admit this does not mean it cannot be used cleverly).
Personally, I'd just disable it by default / have a setting somewhere to always return "false" to that query, and I'd like a prompt to enable it for scripts as desired (sha-1 the js on a site, and remember permitted ones. Auto-breaks when changed). Ideally, it'd be nice to allow / block based on current-domain too. Prompts are a bad idea for most people, though.
Anyone know if doing this would be possible on browsers right now? I don't know what the APIs allow.