SugarCoat: Programmatically Generating Privacy-Preserving, Web-Compatible Resource Replacements for Content Blocking
Michael Smith, Peter Snyder, Benjamin Livshits, Deian Stefan
Abstract
Content blocking systems today exempt thousands of privacy-harming scripts. They do this because blocking these scripts breaks the Web sites that rely on them. In this paper, we address this privacy/functionality trade-off with SugarCoat, a tool that allows filter list authors to automatically patch JavaScript scripts to restrict their access to sensitive data according to a custom privacy policy. We designed SugarCoat to generate resource replacements compatible with existing content blocking tools, including uBlock Origin and the Brave Browser, and evaluate our implementation by automatically replacing scripts exempted by the 6,000+ exception rules in the popular EasyList, EasyPrivacy, and uBlock Origin filter lists. Crawling a sample of pages from the Alexa 10k, we find that SugarCoat preserves the functionality of existing pages-our replacements result in Web-compatibility properties similar to exempting scripts-while providing privacy properties most similar to blocking those scripts. SugarCoat is intended for real-world practical deployment, to protect Web users from privacy harms current tools are unable to protect against. Our design choices emphasize compatibility with existing tools, policy flexibility, and extensibility. SugarCoat is open source and is being integrated into Brave's content blocking tools: an initial set of SugarCoat-generated resource replacements are already shipping to users in the Brave Browser.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext af1a842e-4708-4280-9b97-2826cfc9c196Cited by top-tier papers8
- ASTrack: Automatic Detection and Removal of Web Tracking Code with Minimal Functionality LossIsmael Castell-Uroz, Kensuke Fukuda, Pere Barlet-RosINFOCOM 2023 · 8 citations
- SINBAD: Saliency-informed detection of breakage caused by ad blockingSaiid El Hajj Chehade, Sandra Deepthy Siby, Carmela TroncosoS&P 2024 · 3 citations
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 3 citations
- Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript BundlesMir Masood Ali, Peter Snyder, Chris Kanich, Hamed HaddadiCCS 2024 · 2 citations
- Pool-Party: Exploiting Browser Resource Pools for Web TrackingPeter Snyder, Soroush Karami, Arthur Edelstein, Benjamin Livshits et al.USENIX Security 2023
Builds on6
- Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting BehaviorsUmar Iqbal, Steven Englehardt, Zubair ShafiqS&P 2021 · 143 citations
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits et al.S&P 2020 · 112 citations
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 75 citations
- Measuring and Disrupting Anti-Adblockers Using Differential Execution AnalysisShitong Zhu, Xunchao Hu, Zhiyun Qian, Zubair Shafiq et al.NDSS 2018 · 44 citations
- PERCIVAL: Making In-Browser Perceptual Ad Blocking Practical with Deep LearningZain ul Abi Din, Panagiotis Tigas, Samuel T. King, Benjamin LivshitsUSENIX ATC 2020 · 34 citations
Related papers
- Detecting Filter List Evasion with Event-Loop-Turn Granularity JavaScript SignaturesQuan Chen, Peter Snyder, Ben Livshits, Alexandros KapravelosS&P 2021 · 33 citations
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
- Beast in the Cage: A Fine-grained and Object-oriented Permission System to Confine JavaScript Operations on the WebRui ZhaoWWW 2025 · 2 citations
- Least Privilege Access for Persistent Storage Mechanisms in Web BrowsersGayatri Priyadarsini Kancherla, Dishank Goel, Abhishek BichhawatWWW 2025 · 2 citations
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
