Article 5ECXA New browser-tracking hack works even when you flush caches or go incognito

New browser-tracking hack works even when you flush caches or go incognito

by
Dan Goodin
from Ars Technica - All content on (#5ECXA)
browser-tracking-800x534.jpg

Enlarge (credit: Getty Images)

The prospect of Web users being tracked by the sites they visit has prompted several countermeasures over the years, including using Privacy Badger or an alternate anti-tracking extension, enabling private or incognito browsing sessions, or clearing cookies. Now, websites have a new way to defeat all three.

The technique leverages the use of favicons, the tiny icons that websites display in users' browser tabs and bookmark lists. Researchers from the University of Illinois, Chicago said in a new paper that most browsers cache the images in a location that's separate from the ones used to store site data, browsing history, and cookies. Websites can abuse this arrangement by loading a series of favicons on visitors' browsers that uniquely identify them over an extended period of time.

Powerful tracking vector

Overall, while favicons have long been considered a simple decorative resource supported by browsers to facilitate websites' branding, our research demonstrates that they introduce a powerful tracking vector that poses a significant privacy threat to users," the researchers wrote. They continued:

Read 10 remaining paragraphs | Comments

index?i=w-U1f69sNCU:Nwr8Tp-d378:V_sGLiPB index?i=w-U1f69sNCU:Nwr8Tp-d378:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments