Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
CNAME-based tracking increasingly used to bypass browsers’ anti-tracking defenses
#1
In 2019, Firefox was equipped with [color=var(--theme-link_a)]Enhanced Tracking Protection by default, blocking known trackers, third-party tracking cookies and cryptomining scripts. Social media trackers and tracking content in private Windows [color=var(--theme-link_a)]were added[/color] to that list a few months later. In August 2020, Firefox received a new protection feature to [color=var(--theme-link_a)]hamper redirect tracking[/color]. Last month, Firefox [color=var(--theme-link_a)]received protection[/color] against cache-based tracking “supercookies”.[/color]
 
On Tuesday, Mozilla [color=var(--theme-link_a)]released Firefox 86, and with it yet another new anti-tracking feature build into the browser’s Enhanced Tracking Protection (ETP): Total Cookie Protection.[/color]
“Total Cookie Protection confines cookies to the site where they were created, which prevents tracking companies from using these cookies to track your browsing from site to site,” Mozillans Tim Huang, Johann Hofmann and Arthur Edelstein [color=var(--theme-link_a)]explained.[/color]
 
There are exceptions to that rule, though: cross-site cookies needed for non-tracking purposes (e.g., for single sign-on purposes). “Only when Total Cookie Protection detects that you intend to use a provider, will it give that provider permission to use a cross-site cookie specifically for the site you’re currently visiting,” they noted.
 
Since its inception, the Chromium-based Brave browser introduced privacy/anti-tracking features such as a system for [color=var(--theme-link_a)]hiding privacy-harming page elements and third-party tracking ads, [color=var(--theme-link_a)]browser fingerprint randomization[/color], default removal of common tracking parameters from URLs, protection against query parameter tracking, [color=var(--theme-link_a)]temporary removal of Google’s Reporting API[/color][color=var(--theme-link_a)]CNAME-based adblocking[/color], etc.[/color]
 
Safari has its Intelligent Tracking Prevention feature that employs anti-fingerprinting protection (it presents a simplified version of the user’s system configuration to websites) and now effectively [color=var(--theme-link_a)]blocks all third-party cookies by default.[/color]
 
In early 2020, Google [color=var(--theme-link_a)]laid out a roadmap for making third party cookies obsolete by 2022, and works on creating alternative technologies/standards that will permit ad personalization without affecting user privacy.[/color]
CNAME cloaking dangers
[color=var(--theme-link_a)]According to researchers Yana Dimova, Gunes Acar, Lukasz Olejnik, Wouter Joosen, and Tom Van Goethem, CNAME cloaking is a tracking evasion scheme that is not new but is rapidly gaining in popularity.[/color]
 
The scheme takes advantage of a CNAME record on a subdomain.
“The tracker is injected in the first-party context, the context of the visited website. A website example.com is embedding the content of the form xxx.example.com. But in reality, this subdomain xxx.example.com is an alias for the tracker domain, the yyy.tracker.com, a separate domain hosted at a third-party server,” Lukasz Olejnik [color=var(--theme-link_a)]explained.[/color]
“This scheme works thanks to a DNS delegation. Most often it is a DNS CNAME record. The tracker technically is hosted in a subdomain of the visited website.”
 
And because most anti-tracking works on the principle of filter lists, the CNAME cloaking scheme effectively renders most browsers’ anti-tracking defenses ineffective, he notes.
“As of today, from the major web browser vendors only Firefox offers defenses. Since uBlock version 1.25 under Firefox, the extension dynamically resolves hosts and sanitizes such requests if a match is found. Such a measure does not work under Chrome because this web browser does not offer a way for extensions to dynamically resolve hostnames.”
 
What’s more, CNAME cloaking leads to session fixation and persistent cross-site scripting vulnerabilities, potentially opening users and publishers to attack, as well as massive cookie leaks.
“In 95% of cases of websites using this technique, we found cookies leaking to external tracker servers in an unsanctioned manner, invisible to the user. In some cases, we confirm that the leaked cookies contain private/sensitive data. All these likely trigger the violation of data protection regimes such as the GDPR, or maybe even the CCPA,” Olejnik concluded.


Source
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  DuckDuckGo removes carve-out for Microsoft tracking scripts after securing policy cha vietnamrum 0 598 12-23-2022 , 01:30 AM
Last Post: vietnamrum
  Low-Detection Phishing Kits Increasingly Bypass MFA Mohammad.Poorya 0 910 02-04-2022 , 05:29 PM
Last Post: Mohammad.Poorya
  Google sued by DC and three states for ‘deceptive’ Android location tracking mrtrout 0 785 01-24-2022 , 11:34 PM
Last Post: mrtrout
  Google: We're Tracking 270 State-Sponsored Hacker Groups From Over 50 Countries mrtrout 0 553 10-14-2021 , 10:21 PM
Last Post: mrtrout
  Over 60 million wearable, fitness tracking records exposed via unsecured database mrtrout 0 582 09-15-2021 , 03:24 AM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)