TY - GEN
T1 - Extended tracking powers
T2 - 26th International World Wide Web Conference, WWW 2017
AU - Starov, Oleksii
AU - Nikiforakis, Nick
N1 - Publisher Copyright: © 2017 International World Wide Web Conference Committee (IW3C2).
PY - 2017
Y1 - 2017
N2 - Users have come to rely on browser extensions to realize features that are not implemented by browser vendors. Extensions oer users the ability to, among others, block ads, de-clutter websites, enrich pages with third-party content, and take screenshots. At the same time, because of their privileged position inside a user’s browser, extensions have access to content and functionality that is not available to webpages, such as, the ability to conduct and read cross-origin requests, as well as get access to a browser’s history and cookie jar. In this paper, we report on the first large-scale study of privacy leakage enabled by extensions. By using dynamic analysis and simulated user interactions, we investigate the leaking happening by the 10,000 most popular browser extensions of Google Chrome and find that a non-negligible fraction leaks sensitive information about the user’s browsing habits, such as, their browsing history and search-engine queries. We identify common ways that extensions use to obfuscate this leakage and discover that, while some leakage happens on purpose, a large fraction of it is accidental because of the way that extensions attempt to introduce third-party content to a page’s DOM. To counter the inference of a user’s interests and private information enabled by this leakage, we design, implement, and evaluate BrowsingFog, a browser extension that automatically browses the web in a way that conceals a user’s true interests, from a vantage point of history-stealing, third-party trackers.
AB - Users have come to rely on browser extensions to realize features that are not implemented by browser vendors. Extensions oer users the ability to, among others, block ads, de-clutter websites, enrich pages with third-party content, and take screenshots. At the same time, because of their privileged position inside a user’s browser, extensions have access to content and functionality that is not available to webpages, such as, the ability to conduct and read cross-origin requests, as well as get access to a browser’s history and cookie jar. In this paper, we report on the first large-scale study of privacy leakage enabled by extensions. By using dynamic analysis and simulated user interactions, we investigate the leaking happening by the 10,000 most popular browser extensions of Google Chrome and find that a non-negligible fraction leaks sensitive information about the user’s browsing habits, such as, their browsing history and search-engine queries. We identify common ways that extensions use to obfuscate this leakage and discover that, while some leakage happens on purpose, a large fraction of it is accidental because of the way that extensions attempt to introduce third-party content to a page’s DOM. To counter the inference of a user’s interests and private information enabled by this leakage, we design, implement, and evaluate BrowsingFog, a browser extension that automatically browses the web in a way that conceals a user’s true interests, from a vantage point of history-stealing, third-party trackers.
KW - Browser extensions
KW - Privacy diusion
KW - Web tracking
UR - https://www.scopus.com/pages/publications/85048171091
U2 - 10.1145/3038912.3052596
DO - 10.1145/3038912.3052596
M3 - Conference contribution
SN - 9781450349130
T3 - 26th International World Wide Web Conference, WWW 2017
SP - 1481
EP - 1490
BT - 26th International World Wide Web Conference, WWW 2017
PB - International World Wide Web Conferences Steering Committee
Y2 - 3 April 2017 through 7 April 2017
ER -