The Web Never Forgets: Persistent Tracking Mechanisms in the Wild

被引:185
作者
Acar, Gunes [1 ,2 ]
Eubank, Christian [3 ]
Englehardt, Steven [3 ]
Juarez, Marc [1 ,2 ]
Narayanan, Arvind [3 ]
Diaz, Claudia [1 ,2 ]
机构
[1] Katholieke Univ Leuven, ESAT COSIC, Leuven, Belgium
[2] iMinds, Leuven, Belgium
[3] Princeton Univ, Princeton, NJ 08544 USA
来源
CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2014年
关键词
Web security; privacy; tracking; canvas fingerprinting; browser fingerprinting; cookie syncing; evercookie; !text type='Java']Java[!/text]-Script; Flash;
D O I
10.1145/2660267.2660347
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present the first large-scale studies of three advanced web tracking mechanisms - canvas fingerprinting, evercookies and use of "cookie syncing" in conjunction with evercookies. Canvas fingerprinting, a recently developed form of browser fingerprinting, has not previously been reported in the wild; our results show that over 5% of the top 100,000 websites employ it. We then present the first automated study of evercookies and respawning and the discovery of a new evercookie vector, IndexedDB. Turning to cookie syncing, we present novel techniques for detection and analysing ID flows and we quantify the amplification of privacy-intrusive tracking practices due to cookie syncing. Our evaluation of the defensive techniques used by privacy-aware users finds that there exist subtle pitfalls - such as failing to clear state on multiple browsers at once - in which a single lapse in judgement can shatter privacy defenses. This suggests that even sophisticated users face great difficulties in evading tracking techniques.
引用
收藏
页码:674 / 689
页数:16
相关论文
共 44 条
  • [1] [Anonymous], 2013, P 2013 ACM SIGSAC C, DOI DOI 10.1145/2508859.2516674
  • [2] [Anonymous], 2011, USENIX C NETWORKED S
  • [3] [Anonymous], 2010, AAAI SPRING S INT IN
  • [4] AYENSON M. D., 2011, WORLD WIDE WEB INTER
  • [5] ObliviAd: Provably Secure and Practical Online Behavioral Advertising
    Backes, Michael
    Kate, Aniket
    Maffei, Matteo
    Pecina, Kim
    [J]. 2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, : 257 - 271
  • [6] Balebako R, 2012, WEB 2 0 WORKSH SEC P, V2012
  • [7] Besson Frederic., 2014, ENFORCING BROWSER AN
  • [8] Bilenko Mikhail., 2011, PRIVACY ENHANCING TE
  • [9] Black P. E, 2004, RATCLIFF OBERSHELP P
  • [10] Davis W., 2013, KISSMETRICS FINALIZE