Exclusive: How the (synced) Cookie Monster breached my encrypted VPN session

Exclusive: How the (synced) Cookie Monster breached my encrypted VPN session
复制标题

独家:(同步的)Cookie Monster 如何破坏我的加密 VPN 会话

DOI:
--
复制
发表时间:
2018
期刊:
EuroSec@EuroSys
影响因子:
--
通讯作者:
E. Markatos
E. Markatos
中科院分区:
--
文献类型:
--
作者:
P. Papadopoulos;N. Kourtellis;E. Markatos

文献摘要

被引文献

相似文献

近年来,在斯诺登泄密事件之后,组织、政策制定者和个人在网络上发起了一场重大运动,以提高用户的隐私意识。因此,越来越多的出版商在其网站中支持 TLS,并且供应商提供隐私和匿名工具,例如安全 VPN 或 Tor 洋葱,以满足用户保护隐私的 Web 浏览的需求。但这些工具的零星使用足以提供隐私吗?在本文中,我们描述了针对通过安全 VPN 访问互联网的用户的两种隐私泄露威胁。这些违规行为是通过 Cookie 同步造成的,目前第三方广泛将其用于广告和跟踪目的。生成的隐私泄露可以被 ISP 等窥探实体用来重新识别网络中的用户并泄露他们的浏览历史记录,即使用户隐藏在 VPN 后面。通过调查排名前 12K 的 Alexa 网站,我们发现十分之一的网站将其用户暴露在这些隐私泄露的风险之中。
In recent years, and after the Snowden revelations, there has been a significant movement in the web from organizations, policymakers and individuals to enhance the privacy awareness among users. As a consequence, more and more publishers support TLS in their websites, and vendors provide privacy and anonymity tools, such as secure VPNs or Tor onions, to cover the need of users for privacy-preserving web browsing. But is the sporadic appliance of such tools enough to provide privacy? In this paper, we describe two privacy-breaching threats against users accessing the Internet over a secure VPN. The breaches are made possible through Cookie Synchronization, nowadays widely used by third parties for advertisement and tracking purposes. The generated privacy leaks can be used by a snooping entity such as an ISP, to re-identify a user in the web and reveal their browsing history even when users are hidden behind a VPN. By probing the top 12K Alexa sites, we find that 1 out of 13 websites expose their users to these privacy leaks.