Retrieving your browsing history through a CAPTCHA (2022)
varun.ch
varun.ch
The first trick: the asteroids are actually (in)visible depending on whether you had visited a specific website, same as here. If you clicked on an asteroid that's because you could see it, and now you've revealed that you've visited that website before.
Second trick: these asteroids don't actually hit you - they pass close by (close enough that you want to shoot them) but they don't actually aim at you (to keep you playing as long as possible).
Sounds like they can't have them hurt you since the game doesn't know which asteroids are "real" until you've destroyed them.
https://lcamtuf.coredump.cx/whack/
See also "History theft with CSS Boolean algebra":
If you do this, beware this from the PoC when testing:
> Additionally, I included some fake squares to catch if visitors are trying to spoof their results.
set to false you mean, surely?
Sorry if this sounds kind of ignorant, but I do primarily backend stuff lol :)
Instead they have to have you the user do something to indicate which ones you can see and which ones you can't. That's why you HAVE to click on the squares. And if you click on white squares, it'll (wrongly) think you've visited sites you haven't. If you click on NONE of the squares, it'll think you haven't visited any of them, since it won't have any way to double check the info.
So that's why they can't "just render it outside the viewport." For sources, see the other comments by folks with good info.
It's cleverer than that. There are two positive controls (squares that are always black) and one negative control (always white). If you don't click both positive controls, or if you click the negative control, the page will tell you that you've failed the CAPTCHA.
their database was huge and it went from a funny gotcha to awkward really fast
JWZ uses the same trick, and redirects to an image of a hairy ball in an eggcup.
Unless they're also doing some CSS stuff I haven't read about.
Edit: clicked through a bit more. a red banner got added to their site using something like this.
No, that's what they used to do until HN got updated to put rel="noreferrer" on the links specifically to stop that.
> Unless they're also doing some CSS stuff I haven't read about.
That's exactly what they're doing now. They have white-on-white text at the top of every page that turns red (i.e., becomes visible) if you've ever visited the HN submit page.
No need to remove the feature completely, just not applying :visited on cross-domain links would fix privacy leak, while keeping most legit uses of :visited working fine.
edit: no I'm wrong, it's early here and I've not had coffee
Retrieving your browsing history through a CAPTCHA - https://news.ycombinator.com/item?id=30569396 - March 2022 (56 comments)
This sounds sensible. Color is perhaps the only thing that browsers should be able to control.
There's all kinds of things browsers do that no amount of coding will help me access because there's no public API for it. Why should this be any different?
Turns out that it does prevent leaking data in this case. No local data, no history, no boxes to click, no data leaked.
There are timing attacks that work automatically though. https://ndev.tk/visted/ works on Chrome.