The Web Never Forgets: Persistent Tracking Mechanisms in the Wild

被引:203
作者
Acar, Gunes [1 ,2 ]
Eubank, Christian [3 ]
Englehardt, Steven [3 ]
Juarez, Marc [1 ,2 ]
Narayanan, Arvind [3 ]
Diaz, Claudia [1 ,2 ]
机构
[1] Katholieke Univ Leuven, ESAT COSIC, Leuven, Belgium
[2] iMinds, Leuven, Belgium
[3] Princeton Univ, Princeton, NJ 08544 USA
来源
CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2014年
关键词
Web security; privacy; tracking; canvas fingerprinting; browser fingerprinting; cookie syncing; evercookie; !text type='Java']Java[!/text]-Script; Flash;
D O I
10.1145/2660267.2660347
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present the first large-scale studies of three advanced web tracking mechanisms - canvas fingerprinting, evercookies and use of "cookie syncing" in conjunction with evercookies. Canvas fingerprinting, a recently developed form of browser fingerprinting, has not previously been reported in the wild; our results show that over 5% of the top 100,000 websites employ it. We then present the first automated study of evercookies and respawning and the discovery of a new evercookie vector, IndexedDB. Turning to cookie syncing, we present novel techniques for detection and analysing ID flows and we quantify the amplification of privacy-intrusive tracking practices due to cookie syncing. Our evaluation of the defensive techniques used by privacy-aware users finds that there exist subtle pitfalls - such as failing to clear state on multiple browsers at once - in which a single lapse in judgement can shatter privacy defenses. This suggests that even sophisticated users face great difficulties in evading tracking techniques.
引用
收藏
页码:674 / 689
页数:16
相关论文
共 44 条
[1]  
[Anonymous], 2013, P 2013 ACM SIGSAC C, DOI DOI 10.1145/2508859.2516674
[2]  
[Anonymous], 2011, USENIX C NETWORKED S
[3]  
[Anonymous], 2010, AAAI SPRING S INT IN
[4]  
AYENSON M. D., 2011, WORLD WIDE WEB INTER
[5]   ObliviAd: Provably Secure and Practical Online Behavioral Advertising [J].
Backes, Michael ;
Kate, Aniket ;
Maffei, Matteo ;
Pecina, Kim .
2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, :257-271
[6]  
Balebako R, 2012, WEB 2 0 WORKSH SEC P, V2012
[7]  
Besson Frederic., 2014, ENFORCING BROWSER AN
[8]  
Bilenko Mikhail., 2011, PRIVACY ENHANCING TE
[9]  
Black P. E, 2004, RATCLIFF OBERSHELP P
[10]  
Davis W., 2013, KISSMETRICS FINALIZE