Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy Leakage
Soroush Karami, Panagiotis Ilia, Jason Polakis
摘要
Service workers are a powerful technology supported by all major modern browsers that can improve users' browsing experience by offering capabilities similar to those of native applications. While they are gaining significant traction in the developer community, they have not received much scrutiny from security researchers. In this paper, we explore the capabilities and inner workings of service workers and conduct the first comprehensive large-scale study of their API use in the wild. Subsequently, we show how attackers can exploit the strategic placement of service workers for history-sniffing in most major browsers, including Chrome and Firefox. We demonstrate two novel history-sniffing attacks that exploit the lack of appropriate isolation in these browsers, including a non-destructive cache-based version. Next, we present a series of use cases that illustrate how our techniques enable privacy-invasive attacks that can infer sensitive application-level information, such as a user's social graph. We have disclosed our techniques to all vulnerable vendors, prompting the Chromium team to explore a redesign of their site isolation mechanisms for defending against our attacks. We also propose a countermeasure that can be incorporated by websites to protect their users, and develop a tool that streamlines its deployment, thus facilitating adoption at a large scale. Overall, our work presents a cautionary tale on the severe risks of browsers deploying new features without an in-depth evaluation of their security and privacy implications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web BrowsersLukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor Noß 等CCS 2021 · 被引用 11 次
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 被引用 7 次
- CorbFuzz: Checking Browser Security Policies with FuzzingChaofan Shou, Ismet Burak Kadron, Qi Su, Tevfik BultanASE 2021 · 被引用 5 次
- WEBRR: A Forensic System for Replaying and Investigating Web-Based Attacks in The Modern WebJoey Allen, Zheng Yang, Feng Xiao, Matthew Landen 等USENIX Security 2024 · 被引用 2 次
- Rise of Inspectron: Automated Black-box Auditing of Cross-platform Electron AppsMir Masood Ali, Mohammad Ghasemisharif, Chris Kanich, Jason PolakisUSENIX Security 2024 · 被引用 2 次
它引用的顶会 Paper14
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 被引用 273 次
- Privacy Risks with Facebook's PII-Based Targeting: Auditing a Data Broker's Advertising InterfaceGiridhari Venkatadri, Athanasios Andreou, Yabing Liu, Alan Mislove 等S&P 2018 · 被引用 110 次
- The Web's Sixth Sense: A Study of Scripts Accessing Smartphone SensorsAnupam Das, Gunes Acar, Nikita Borisov, Amogh PradeepCCS 2018 · 被引用 91 次
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 被引用 75 次
- How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)SecurityBen Stock, Martin Johns, Marius Steffens, Michael BackesUSENIX Security 2017 · 被引用 67 次
相关 Paper
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 被引用 60 次
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 被引用 67 次
- Fill in the Blanks: Empirical Analysis of the Privacy Threats of Browser Form AutofillXu Lin, Panagiotis Ilia, Jason PolakisCCS 2020 · 被引用 24 次
- The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the WebJannis Rautenstrauch, Giancarlo Pellegrino, Ben StockS&P 2023
- Latex Gloves: Protecting Browser Extensions from Probing and Revelation AttacksAlexander Sjösten, Steven Van Acker, Pablo Picazo-Sanchez, Andrei SabelfeldNDSS 2019 · 被引用 36 次
