USENIX Security2019Top-tier venue
Leaky Images: Targeted Privacy Attacks in the Web
Cristian-Alexandru Staicu, Michael Pradel
Abstract
Sharing files with specific users is a popular service provided by various widely used websites, e.g., Facebook, Twitter, Google, and Dropbox. A common way to ensure that a shared file can only be accessed by a specific user is to authenticate the user upon a request for the file. This paper shows a novel way of abusing shared image files for targeted privacy attacks. In our attack, called leaky images, an image shared with a particular user reveals whether the user is visiting a specific website. The basic idea is simple yet effective: an attacker-controlled website requests a privately shared image, which will succeed only for the targeted user whose browser is logged into the website through which the image was shared. In addition to targeted privacy attacks aimed at single users, we discuss variants of the attack that allow an attacker to track a group of users and to link user identities across different sites. Leaky images require neither JavaScript nor CSS, exposing even privacy-aware users, who disable scripts in their browser, to the leak. Studying the most popular websites shows that the privacy leak affects at least eight of the 30 most popular websites that allow sharing of images between users, including the three most popular of all sites. We disclosed the problem to the affected sites, and most of them have been fixing the privacy leak in reaction to our reports. In particular, the two most popular affected sites, Facebook and Twitter, have already fixed the leaky images problem. To avoid leaky images, we discuss potential mitigation techniques that address the problem at the level of the browser and of the image sharing website. no 4 youtube.com no 5 instagram.com no 6 linkedin.com no 8 pinterest.com no 9 wikipedia.org no 10 wordpress.com yes no no no 15 tumblr.com no 18 vimeo.com no 19 flickr.com no 25 vk.com no 26 reddit.com no 33 blogger.com no 35 github.com yes no no no 39 myspace.com no 54 stumbleupon.com no 65 dropbox.com yes yes planned yes 71 msn.com no 72 slideshare.net no 91 typepad.com no 126 live.com yes yes planned no 152 spotify.com no 160 goodreads.com no 161 scribd.com no 163 imgur.com no 166 photobucket.com no 170 deviantart.com no 217 skype.com yes yes planned no
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5da1afc2-24c6-4107-935d-6865b035493dCited by top-tier papers9
- The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite CookiesSoheil Khodayari, Giancarlo PellegrinoS&P 2022 · 28 citations
- XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web BrowsersLukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor Noß et al.CCS 2021 · 11 citations
- Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-LeaksAvinash Sudhodanan, Soheil Khodayari, Juan CaballeroNDSS 2020
- Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress MarketplacesRanjita Pai Kasturi, Jonathan Fuller, Yiting Sun, Omar Chabklo et al.USENIX Security 2022
- Shadowed Realities: An Investigation of UI Attacks in WebXRChandrika Mukherjee, Reham Mohamed, Arjun Arunasalam, Habiba Farrukh et al.USENIX Security 2025
Builds on13
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 199 citations
Related papers
- Targeted Deanonymization via the Cache Side Channel: Attacks and DefensesMojtaba Zaheri, Yossi Oren, Reza CurtmolaUSENIX Security 2022
- PIIxel Leaks: Passive Identification of Personally Identifiable Information Leakage through Meta PixelPaschalis Bekos, Panagiotis Papadopoulos, Nicolas Kourtellis, Michalis PolychronakisCCS 2025
- Exploiting the Shared Storage APIAlexandra Nisenoff, Deian Stefan, Nicolas ChristinCCS 2025
- Towards Face Encryption by Generating Adversarial Identity MasksXiao Yang, Yinpeng Dong, Tianyu Pang, Hang Su et al.ICCV 2021 · 109 citations
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
