Cookie Swap Party: Abusing First-PartyCookies for Web Tracking

被引:10
|
作者
Chen, Quan [1 ]
Ilia, Panagiotis [2 ]
Polychronakis, Michalis [3 ]
Kapravelos, Alexandros [1 ]
机构
[1] North Carolina State Univ, Raleigh, NC 27695 USA
[2] Univ Illinois, Chicago, IL USA
[3] SUNY Stony Brook, Stony Brook, NY 11794 USA
基金
美国国家科学基金会;
关键词
D O I
10.1145/3442381.3449837
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As a step towards protecting user privacy, most web browsers perform some form of third-party HTTP cookie blocking or periodic deletion by default, while users typically have the option to select even stricter blocking policies. As a result, web trackers have shifted their efforts to work around these restrictions and retain or even improve the extent of their tracking capability. In this paper, we shed light into the increasingly used practice of relying on first-party cookies that are set by third-party JavaScript code to implement user tracking and other potentially unwanted capabilities. Although unlike third-party cookies, first-party cookies are not sent automatically by the browser to third-parties on HTTP requests, this tracking is possible because any included third-party code runs in the context of the parent page, and thus can fully set or read existing first-party cookies-which it can then leak to the same or other third parties. Previous works that survey user privacy on the web in relation to cookies, third-party or otherwise, have not fully explored this mechanism. To address this gap, we propose a dynamic data flow tracking system based on Chromium to track the leakage of first-party cookies to third parties, and used it to conduct a large-scale study of the Alexa top 10K websites. In total, we found that 97.72% of the websites have first-party cookies that are set by third-party JavaScript, and that on 57.66% of these websites there is at least one such cookie that contains a unique user identifier that is diffused to multiple third parties. Our results highlight the privacy-intrusive capabilities of first-party cookies, even when a privacy-savvy user has taken mitigative measures such as blocking third-party cookies, or employing popular crowd-sourced filter lists such as EasyList/EasyPrivacy and the Disconnect list.
引用
收藏
页码:2117 / 2129
页数:13
相关论文
共 21 条
  • [1] Evaluation of Third Party Tracking on the Web
    Hamed, Asma
    Kaffel-Ben Ayed, Hella
    Kaafar, Mohamed Ali
    Kharraz, Ahmed
    2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 471 - +
  • [2] The Evolution of Third-Party Web Tracking
    Wambach, Tim
    Braeunlich, Katharina
    INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP 2016), 2017, 691 : 130 - 147
  • [3] What a Tangled Web We Weave: Understanding the Interconnectedness of the Third Party Cookie Ecosystem
    Hu, Xuehui
    Sastry, Nishanth
    PROCEEDINGS OF THE 12TH ACM CONFERENCE ON WEB SCIENCE, WEBSCI 2020, 2020, : 76 - 85
  • [4] Third-Party Web Tracking: Policy and Technology
    Mayer, Jonathan R.
    Mitchell, John C.
    2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, : 413 - 427
  • [5] Third-party Tracking on the Web: A Swedish Perspective
    Purra, Joel
    Carlsson, Niklas
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 28 - 34
  • [6] Prevalence of Third-Party Tracking on Abortion Clinic Web Pages
    Friedman, Ari B.
    Bauer, Lujo
    Gonzales, Rachel
    McCoy, Matthew S.
    JAMA INTERNAL MEDICINE, 2022, 182 (11) : 1221 - 1222
  • [7] CookieGraph: Understanding and Detecting First-Party Tracking Cookies
    Munir, Shaoor
    Siby, Sandra
    Iqbal, Umar
    Englehardt, Steven
    Sha, Zubair
    Troncoso, Carmela
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3490 - 3504
  • [8] MindYourPrivacy: Design and Implementation of a Visualization System for Third-Party Web Tracking
    Takano, Yuuki
    Ohta, Satoshi
    Takahashi, Takeshi
    Ando, Ruo
    Inoue, Tomoya
    2014 TWELFTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2014, : 48 - 56
  • [9] Exploring the Impact of Third-Party Web Tracking on Healthcare Providers' Business Value
    Ivanov, Anton
    Sharman, Raj
    AMCIS 2016 PROCEEDINGS, 2016,
  • [10] Prevalence of Third-Party Tracking on COVID-19-Related Web Pages
    McCoy, Matthew S.
    Libert, Timothy
    Buckler, David
    Grande, David T.
    Friedman, Ari B.
    JAMA-JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 2020, 324 (14): : 1462 - 1464