Plugging the CSS History Leak
blog.mozilla.com
blog.mozilla.com
A far better solution, IMHO, is to simply track both the origin page and destination page of clicked links, and only apply a:visited styles to links when the origin page is one that has been previously been used to visited the destination page. This is the solution employed by the SafeHistory plugin. (http://www.safehistory.com/)
Now I go to HN to see what's new and I see a link to the same article. Will my browser make it look like I haven't visited it because I haven't visited it through HN?
That would not please me as a user.
So I asked myself: When do I use the visited link colors for? And I think the answer is: only when I press the browser's Back button. I want to see where I left off clicking. If I have to click an extra link and say "Whoops, already saw that", then oh well. As long as I know where to start reading when I return.
The place I use it most is for Google search results, particularly when I refine my search and I want to know what are the links I visited in my previous search so I can click only on the new ones.
It's always a trade-off. I think this is a fairly reasonable one.
Do people really have layouts that rely on visited links changing size or shape? What Javascript uses visited link styling to do something useful?
I'd love to see an example, because I can't think of any myself.
If you changed the font at all for a visited link, it will display differently across Mozilla browsers versus Chrome ones. Having not read about this, I'd never be able to figure out what was preventing the style from "taking" in normal development.
Edit: Nevermind, I forgot that the URL destination can be changed. I guess the browser could force style changes to the links if href is changed, but that might be too complicated. It just seems like there should be a more elegant way to fix the problem than restricting what styles can be set for visited links.
I would love to see them make this optional and turn it off by default. It's a paranoia thing that people have lived with forever, and the most concerned people could turn on this mode if they ever need to do so.
The most valuable thing Mozilla just did was to send a signal to the market that history sniffing is going to be unreliable, and that ad networks shouldn't invest time and money into exploiting it. The scariest thing about history sniffing was the idea that some large company would adopt it and create pressure to keep the vulnerability there forever, as part of how the Internet works.
I know I have the minority opinion on this, so I have to speak up or that opinion will go unheard. I prefer to avoid breaking backwards compatibility for presentation as much as possible. I'd much rather some approach be tried/found that isn't quite so inelegant as this one.
The checkmarked visited links thing seems completely wrong to me, to take that example. Something like a checkmark next to a link feels like part of site UI rather than the browser's, and a site's UI shouldn't have access to what I've done on other sites! If they want to keep track of what links I click on the site and maintain checkmarks in their UI accordingly, they can still do that, of course.
Note that I take the word "paranoia" from Mozilla's own blog discussing the topic. I do feel that it is a real privacy issue, but it isn't new and I'd much prefer something like what SafeHistory does than this presentation level hack they're planning.
Firefox already allow you to disable all visited
styling (immediately stops this attack) by setting the
layout.css.visited_links_enabled option in about:config
to false.
I would rather they stop here. Don't break things for everybody for something that most people consider to be a non-problem.[1] Maybe. Or not. I doubt either of us has evidence one way or the other.
<a href="some-visited-url">
<span class="test"></span>
</a>
Does the CSS for span.test change if the link is visited or not?Also, this will be very awkward when the style you see with your eyes is not the style that is given to JavaScript.
a:visited .test { /* sneaky style */ }
a .test {
color: red;
}
a:visited .test {
color: green;
}
Then I could for example using jQuery do: $('a .test').each(function() {
if ( $(this).css('color') == 'green' ) {
console.log( $(this).parent().attr('href') );
}
});
Is that incorrect?a:visited + .sneakydiv { /* ... */ }
My question: is it really worth worrying about?
What's the threat scenario where this leaks appreciable amounts of my privacy ? Note: I'm NOT arguing "my privacy is worthless".
Here's a simple case: What if your employer was very stuck-up and controlling and the CEO is a crazy {insert religion or lack of here}. They make you log in from home to check your email on their website. Now what if their website sniffed your computer to check if you'd been looking at {insert other religious belief here} and forwarded that information on.
In this case your expectation of privacy does not match the actual privacy case. Most people wouldn't think that looking at a hard-core christian website from home might get them looked at funny by their atheist bosses. This is a case of technology not behaving properly, which is a bug.
You can think of all sorts of cases where there might be negative consequences for you if everyone could view your at-home browsing history.
Are any of these 'broken' besides not being quite as pretty? Is any content or feature invisible, unreadable, or unavailable?