USENIX Security2018Top-tier venue
Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie Policies
Gertjan Franken, Tom van Goethem, Wouter Joosen
Abstract
Nowadays, cookies are the most prominent mechanism to identify and authenticate users on the Internet. Although protected by the Same Origin Policy, popular browsers include cookies in all requests, even when these are cross-site. Unfortunately, these third-party cookies enable both cross-site attacks and third-party tracking. As a response to these nefarious consequences, various countermeasures have been developed in the form of browser extensions or even protection mechanisms that are built directly into the browser. In this paper, we evaluate the effectiveness of these defense mechanisms by leveraging a framework that automatically evaluates the enforcement of the policies imposed to third-party requests. By applying our framework, which generates a comprehensive set of test cases covering various web mechanisms, we identify several flaws in the policy implementations of the 7 browsers and 46 browser extensions that were evaluated. We find that even built-in protection mechanisms can be circumvented by multiple novel techniques we discover. Based on these results, we argue that our proposed framework is a much-needed tool to detect bypasses and evaluate solutions to the exposed leaks. Finally, we analyze the origin of the identified bypass techniques, and find that these are due to a variety of implementation, configuration and design flaws.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c34903fc-38a2-4b08-8e9e-c5fdf233c287Cited by top-tier papers20
- Beyond the Front Page: Measuring Third Party Dynamics in the FieldTobias Urban, Martin Degeling, Thorsten Holz, Norbert PohlmannWWW 2020 · 77 citations
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
- Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile BrowsersMeng Luo, Pierre Laperdrix, Nima Honarmand, Nick NikiforakisNDSS 2019 · 35 citations
- Journey to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and RelationshipsIskander Sánchez-Rola, Matteo Dell'Amico, Davide Balzarotti, Pierre-Antoine Vervier et al.S&P 2022 · 35 citations
- The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite CookiesSoheil Khodayari, Giancarlo PellegrinoS&P 2022 · 28 citations
Builds on2
Related papers
- Web Platform Threats: Automated Detection of Web Security Issues With WPTPedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara et al.USENIX Security 2024 · 6 citations
- Breaking the Shield: Analyzing and Attacking Canvas Fingerprinting Defenses in the WildHoang Dai Nguyen, Phani VadrevuWWW 2025 · 2 citations
- Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking VectorsMir Masood Ali, Binoy Chitale, Mohammad Ghasemisharif, Chris Kanich et al.NDSS 2023
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 67 citations
- Cookie Crumbles: Breaking and Fixing Web Session IntegrityMarco Squarcina, Pedro Adão, Lorenzo Veronese, Matteo MaffeiUSENIX Security 2023
