Fill in the Blanks: Empirical Analysis of the Privacy Threats of Browser Form Autofill
Xu Lin, Panagiotis Ilia, Jason Polakis
摘要
Providing functionality that streamlines the more tedious aspects of website interaction is of paramount importance to browsers as it can significantly improve the overall user experience. Browsers' autofill functionality exemplifies this goal, as it alleviates the burden of repetitively typing the same information across websites. At the same time, however, it also presents a significant privacy risk due to the inherent disparity between the browser's interpretation of a given web page and what users can visually perceive. In this paper we present the first, to our knowledge, comprehensive exploration of the privacy threats of autofill functionality. We first develop a series of new techniques for concealing the presence of form elements that allow us to obtain sensitive user information while bypassing existing browser defenses. Alarmingly, our largescale study in the Alexa top 100K reveals the widespread use of such deceptive techniques for stealthily obtaining user-identifying information, as they are present in at least 5.8% of the forms that are autofilled by Chrome. Subsequently, our in-depth investigation of browsers' autofill functionality reveals a series of flaws and idiosyncrasies, which we exploit through a series of novel attack vectors that target specific aspects of browsers' behavior. By chaining these together we are able to demonstrate a novel invasive side-channel attack that exploits browser's autofill preview functionality for inferring sensitive information even when users choose to not utilize autofill. This attack affects all major Chromium-based browsers and allows attackers to probe users' autofill profiles for over a hundred thousand candidate values (e.g., credit card and phone numbers). Overall, while the preview mode is intended as a protective measure for enabling more informed decisions, ultimately it creates a new avenue of exposure that circumvents a user's choice to not divulge their information. In light of our findings, we have disclosed our techniques to the affected vendors, and have also created a Chrome extension that can prevent our attacks and mitigate this threat until our countermeasures are incorporated into browsers. CCS CONCEPTS • Security and privacy → Browser security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Sequential Recommendation via Stochastic Self-AttentionZiwei Fan, Zhiwei Liu, Yu Wang, Alice Wang 等WWW 2022 · 被引用 203 次
- Mutual Wasserstein Discrepancy Minimization for Sequential RecommendationZiwei Fan, Zhiwei Liu, Hao Peng, Philip S. YuWWW 2023 · 被引用 24 次
- The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting BehaviorAsuman Senol, Alisha Ukani, Dylan Cutler, Igor BilogrevicWWW 2024 · 被引用 14 次
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 被引用 1 次
- Understanding Data Collection, Brokerage, and Spam in the Lead Marketing EcosystemYash Vekaria, Nurullah Demir, Konrad Kollnig, Zubair ShafiqS&P 2026 · 被引用 1 次
它引用的顶会 Paper11
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub 等CCS 2019 · 被引用 429 次
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 被引用 279 次
- UI Dark Patterns and Where to Find Them: A Study on Mobile Applications and User PerceptionLinda Di Geronimo, Larissa Braz, Enrico Fregnan, Fabio Palomba 等CHI 2020 · 被引用 262 次
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 被引用 199 次
相关 Paper
- The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the WebJannis Rautenstrauch, Giancarlo Pellegrino, Ben StockS&P 2023
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 被引用 67 次
- Checking Passwords on Leaky Computers: A Side Channel Analysis of Chrome's Password Leak Detect ProtocolAndrew Kwong, Walter Wang, Jason Kim, Jonathan Berger 等USENIX Security 2023
- Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web ApplicationsJiyeon Lee, Hayeon Kim, Junghwan Park, Insik Shin 等CCS 2018 · 被引用 40 次
