February 10

Apple’s Tracking-Prevention Feature within Safari includes a Privacy Bug

Privacy

0  comments

Last month, engineers at Google published an extremely curious privacy bug in Apple’s Safari browser. Apple’s Intelligent Tracking Prevention, an attribute made to reduce user tracking, has vulnerabilities that themselves allow user tracking. Some details:

ITP detects and blocks tracking on the net. When you search for a few websites that eventually load exactly the same third-party resource, ITP detects the domain hosting the resource as a potential tracker and after that sanitizes web requests compared to that domain to limit tracking. Tracker domains are put into Safari’s internal, on-device ITP list. When future third-party requests are created to a domain on the ITP list, Safari will modify them to eliminate some information it believes may allow tracking an individual (such as for example cookies).

[…]

The details should come as a surprise to everyone since it works out that ITP could effectively be utilized for:

  • information leaks: detecting websites visited by an individual (web browsing history hijacking, stealing a summary of visited sites)
  • tracking the user with ITP, making the mechanism function such as a cookie
  • fingerprinting an individual: in ways like the HSTS fingerprint, but perhaps a little better

I am sure most of us agree that we’d not be expectant of a privacy feature designed to guard against tracking to effectively enable tracking, and in addition accidentally allowing any website on the market to steal its visitors’ web browsing history. But web architecture is complex, and the consequence is that is strictly the case.

Apple fixed this vulnerability in December, per month before Google published.

If there’s any lesson here, it’s that privacy is hard — and that privacy engineering is even harder. It isn’t that people shouldn’t try, but we have to recognize that you can fail.

About the author 

Agent 86

Maxwell Smart, agent 86, is CONTROL's top spy (except for Bannister) and, later, the Chief of CONTROL.

You may also like

On the Evolution of Ransomware

On the Evolution of Ransomware

Russia’s SolarWinds Attack

Russia’s SolarWinds Attack
{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}

Subscribe to our newsletter now!

Malcare WordPress Security