Cookie Swap Party: Abusing First-Party Cookies for Web Tracking
Quan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros Kapravelos
摘要
As a step towards protecting user privacy, most web browsers perform some form of third-party HTTP cookie blocking or periodic deletion by default, while users typically have the option to select even stricter blocking policies. As a result, web trackers have shifted their efforts to work around these restrictions and retain or even improve the extent of their tracking capability. In this paper, we shed light into the increasingly used practice of relying on first-party cookies that are set by third-party JavaScript code to implement user tracking and other potentially unwanted capabilities. Although unlike third-party cookies, first-party cookies are not sent automatically by the browser to third-parties on HTTP requests, this tracking is possible because any included third-party code runs in the context of the parent page, and thus can fully set or read existing first-party cookies—which it can then leak to the same or other third parties. Previous works that survey user privacy on the web in relation to cookies, third-party or otherwise, have not fully explored this mechanism. To address this gap, we propose a dynamic data flow tracking system based on Chromium to track the leakage of first-party cookies to third parties, and used it to conduct a large-scale study of the Alexa top 10K websites. In total, we found that 97.72% of the websites have first-party cookies that are set by third-party JavaScript, and that on 57.66% of these websites there is at least one such cookie that contains a unique user identifier that is diffused to multiple third parties. Our results highlight the privacy-intrusive capabilities of first-party cookies, even when a privacy-savvy user has taken mitigative measures such as blocking third-party cookies, or employing popular crowd-sourced filter lists such as EasyList/EasyPrivacy and the Disconnect list.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Investigating Influencer VPN Ads on YouTubeOmer Akgul, Richard Roberts, Moses Namara, Dave Levin 等S&P 2022 · 被引用 27 次
- The Hitchhiker's Guide to Facebook Web Tracking with Invisible Pixels and Click IDsPaschalis Bekos, Panagiotis Papadopoulos, Evangelos P. Markatos, Nicolas KourtellisWWW 2023 · 被引用 24 次
- Targeted and Troublesome: Tracking and Advertising on Children's WebsitesZahra Moti, Asuman Senol, Hamid Bostani, Frederik J. Zuiderveen Borgesius 等S&P 2024 · 被引用 15 次
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis 等USENIX Security 2024 · 被引用 13 次
- The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern WebBehzad Ousat, Esteban Schafir, Duc C. Hoang, Mohammad Ali Tofighi 等WWW 2024 · 被引用 11 次
它引用的顶会 Paper5
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson 等NDSS 2017 · 被引用 183 次
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 被引用 88 次
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
- Journey to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and RelationshipsIskander Sánchez-Rola, Matteo Dell'Amico, Davide Balzarotti, Pierre-Antoine Vervier 等S&P 2022 · 被引用 35 次
相关 Paper
- CookieGraph: Understanding and Detecting First-Party Tracking CookiesShaoor Munir, Sandra Deepthy Siby, Umar Iqbal, Steven Englehardt 等CCS 2023 · 被引用 22 次
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 被引用 99 次
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 被引用 3 次
- PanoptiChrome: A Modern In-browser Taint Analysis FrameworkRahul Kanyal, Smruti R. SarangiWWW 2024 · 被引用 5 次
- Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful TrackingJordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos 等WWW 2022 · 被引用 15 次
