Massive new study lifts the lid on top websites’ tracking secrets
nakedsecurity.sophos.com
nakedsecurity.sophos.com
Now, the one mechanism that was very effective was ETag tracking. When you request a picture or other asset from a website, the website can send you an etag id which is supposed to signify the picture's version. When the client revisits the page, the client sends back the etag to confirm the version cached is the same as the version on the server. The security leak is that the etag protocol allows arbitrary text to be set as an etag, so to set an etag cookie all you have to do is place a 1x1 pixel on each page with a random GUID, and when the user revisits the page the browser will resend the tracking etag in its request for the 1x1 tracking pixel. This works for browsers with cookies disabled, and will remain when cookies are cleared. The only way to clear it is to clear all browsing history entirely, including cached images.
I was shopping a while back for a new tent. Wondered if I should wait for a 20% off single item coupon event like they do a couple times a year. Googled "when is the next rei 20% coupon?". I got the expected results: probably around labor day.
Lo and behold, a couple days after this I received an email from REI with a 25% off single item offer code.
I don't know of I should be frightened or not, but I got a new tent!
I was working for a sex toy company in the UK and remember one of the developers running a mail shot process with a bug that accidentally resent the "abandoned baskets" email for all abandoned baskets for the last 4 years or so with a 20% off voucher. Busiest unexpected sales spike in the history of the company :)
Pretty awesome company tbh.
We watch how much time you spend on a page, if you mess with options, etc.
If you seem to have any interest in a product we want to unload, we send you a coupon.
We have literally hundreds of SKUs we do this for at any given time to clear warehouse space for newer stuff.
What I found curious however, is the fact that I have never ordered anything from REI on my phone, nor logged on to any REI website (no cart, no account). All REI purchases go through my wife's account for the dividend.
How does casual browsing connect with an email address, excepting the Google search?
Sometimes I wonder if the Web has already passed some basic level of sentience.
You guys will let me know when that happens, right?
E.g. a software-only... err... shim (or how should I call it?) for canvas and audio APIs, and only allow fast native one to a trusted whitelisted parties. And an uniform list of fonts and plugins, despite of what's actually installed.
Of course, I know about NoScript. It can't be mass-used as a "just install this and you're good" strategy, thus doesn't help much - the fingerprints would still remain quite unique. Yet, if something is less obtrusive - just slow at times (and then it asks "hey, this site does something fancy with canvas, maybe allow it to speed up at the cost of your privacy?") may work.
Out of date 2/5 stars
Language spoofing no longer works (assuming it ever worked). Chosen user-agent, etc is pretty out of date. Should choose the same ones as the Tor Browser Bundle or something
how accurate is this? is this extension still worth it?There are ones that'll keep working without Javascript or plugins, like anything coming across in HTTP headers (user-agent, accept, Etag) or on the lower layers (IP address, ciphersuites). Chromium maintains a good Wiki of tracking techniques and possible mitigations [1], Firefox also [2].
Predictably, ones in the lower layers are more difficult and/or impossible to mitigate from a browser; the ones relating to the precise use of HTTP can be mitigated at the cost of breaking automatic HTTP content-negotiation (including mimetypes and language), and caching/state-control semantics.
[1] http://www.chromium.org/Home/chromium-security/client-identi...
(I suppose it doesn't make sense to swap the above URL out at this point.)