The Web Never Forgets: Persistent Tracking Mechanisms in the Wild

被引:185
作者
Acar, Gunes [1 ,2 ]
Eubank, Christian [3 ]
Englehardt, Steven [3 ]
Juarez, Marc [1 ,2 ]
Narayanan, Arvind [3 ]
Diaz, Claudia [1 ,2 ]
机构
[1] Katholieke Univ Leuven, ESAT COSIC, Leuven, Belgium
[2] iMinds, Leuven, Belgium
[3] Princeton Univ, Princeton, NJ 08544 USA
来源
CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2014年
关键词
Web security; privacy; tracking; canvas fingerprinting; browser fingerprinting; cookie syncing; evercookie; !text type='Java']Java[!/text]-Script; Flash;
D O I
10.1145/2660267.2660347
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We present the first large-scale studies of three advanced web tracking mechanisms - canvas fingerprinting, evercookies and use of "cookie syncing" in conjunction with evercookies. Canvas fingerprinting, a recently developed form of browser fingerprinting, has not previously been reported in the wild; our results show that over 5% of the top 100,000 websites employ it. We then present the first automated study of evercookies and respawning and the discovery of a new evercookie vector, IndexedDB. Turning to cookie syncing, we present novel techniques for detection and analysing ID flows and we quantify the amplification of privacy-intrusive tracking practices due to cookie syncing. Our evaluation of the defensive techniques used by privacy-aware users finds that there exist subtle pitfalls - such as failing to clear state on multiple browsers at once - in which a single lapse in judgement can shatter privacy defenses. This suggests that even sophisticated users face great difficulties in evading tracking techniques.
引用
收藏
页码:674 / 689
页数:16
相关论文
共 44 条
  • [41] Tran M.-D., 2014, ARXIV14044533
  • [42] Unger Thomas, 2013, 2013 International Conference on Availability, Reliability and Security (ARES), P255, DOI 10.1109/ARES.2013.33
  • [43] Vasilyev V., 2012, VALVE FINGERPRINTJS
  • [44] [No title captured]