USENIX Security2022Top-tier venue
Leaky Forms: A Study of Email and Password Exfiltration Before Form Submission
Asuman Senol, Gunes Acar, Mathias Humbert, Frederik J. Zuiderveen Borgesius
Abstract
Web users enter their email addresses into online forms for a variety of reasons, including signing in or signing up for a service or subscribing to a newsletter. While enabling such functionality, email addresses typed into forms can also be collected by third-party scripts even when users change their minds and leave the site without submitting the form. Email addresses-or identifiers derived from them-are known to be used by data brokers and advertisers for cross-site, crossplatform, and persistent identification of potentially unsuspecting individuals. In order to find out whether access to online forms is misused by online trackers, we present a measurement of email and password collection that occurs before the form submission on the top 100, 000 websites. We evaluate the effect of user location, browser configuration, and interaction with consent dialogs by comparing results across two vantage points (EU/US), two browser configurations (desktop/mobile), and three consent modes. Our crawler finds and fills email and password fields, monitors the network traffic for leaks, and intercepts script access to filled input fields. Our analyses show that users' email addresses are exfiltrated to tracking, marketing and analytics domains before form submission and without giving consent on 1, 844 websites in the EU crawl and 2, 950 websites in the US crawl. While the majority of email addresses are sent to known tracking domains, we further identify 41 tracker domains that are not listed by any of the popular blocklists. Furthermore, we find incidental password collection on 52 websites by third-party session replay scripts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c5d0362a-0ee6-4b35-9187-c308fd5c28f5Cited by top-tier papers18
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- SoK: State of the Krawlers - Evaluating the Effectiveness of Crawling Algorithms for Web Security MeasurementsAleksei Stafeev, Giancarlo PellegrinoUSENIX Security 2024 · 12 citations
- PURL: Safe and Effective Sanitization of Link DecorationShaoor Munir, Patrick Lee, Umar Iqbal, Sandra Deepthy Siby et al.USENIX Security 2024 · 9 citations
- Automating Website Registration for Studying GDPR ComplianceKarel Kubicek, Jakob Merane, Ahmed Bouhoula, David A. BasinWWW 2024 · 9 citations
- SINBAD: Saliency-informed detection of breakage caused by ad blockingSaiid El Hajj Chehade, Sandra Deepthy Siby, Carmela TroncosoS&P 2024 · 3 citations
Builds on10
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking EcosystemAbbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan et al.NDSS 2018 · 271 citations
Related papers
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 99 citations
- PIIxel Leaks: Passive Identification of Personally Identifiable Information Leakage through Meta PixelPaschalis Bekos, Panagiotis Papadopoulos, Nicolas Kourtellis, Michalis PolychronakisCCS 2025
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
- Characterizing Pixel Tracking through the Lens of Disposable Email ServicesHang Hu, Peng Peng, Gang WangS&P 2019 · 25 citations
- The Representativeness of Automated Web Crawls as a Surrogate for Human BrowsingDavid Zeber, Sarah Bird, Camila Oliveira, Walter Rudametkin et al.WWW 2020 · 37 citations
