Happy New Year! Forget all that stuff about the Mayan Calendar. Be Cool!

Latest Reviews & Tutorials

  • How to make DuckDuckGo the default search engine in Chromium
  • How to customize Linux Mint 12 KDE
  • Linux Mint 12 KDE review
  • GhostBSD 2.5 review
  • How to install Takeoff Launcher on Fedora 16 KDE
  • Install Quick Access on Linux Mint 12 KDE or any KDE installation
  • How to install Linux Mint 12 KDE on a btrfs file system
  • Manual disk partitioning guide for Linux Mint 12 KDE
  • How to compile and install Takeoff Launcher on Linux Mint 12 KDE
  • 3 must-have extensions for Fedora 16 and other GNOME 3 installations
  • How to install Razor-qt on Linux Mint 12 KDE
  • How to enable desktop slideshow on Linux Mint 12 KDE
  • KahelOS 111111 review
  • How to install Cinnamon in Ubuntu 11.10
  • How to customize Cinnamon on Fedora 16 and Linux Mint 12
  • How to install Cinnamon on Fedora 16
  • What does Cinnamon bring to the desktop?
  • How to access Microsoft Windows files and folders from Linux
  • How to dual-boot Pear OS Panther 3 and Windows 7
  • How to dual-boot Chakra Linux Edn and Windows 7, part 1

All Your Browsing History Are Belong to Us


For several years, it has been a poorly kept secret that any Web site you went to could secretly search your browser’s history file to see what sites you had previously visited.  All the site owner had to do was ask.  And while browser history “sniffing” has been around for a long time, companies are finally starting to actively take advantage of it.  The time to act to prevent this clear threat to personal privacy is now.

The History of Browser History Sniffing

Browser history sniffing exploits the functionality of all Web browsers that displays hyperlinks of visited and non-visited sites in different colors.  That is, when you visit a Web site that contains links to a number of other urls, the links to sites you have not previously visited will be shown in blue, while the links to sites that you had previously visited will be shown in purple.  The links appear this way because the Web page is allowed to query to user’s browser history in order to know what color to render the links on the Web page.  Web sites can game this functionality by listing hundreds of Web addresses (often hidden to the user, who doesn’t see the links at all, blue or purple) to get answers from the user’s browser about what color to display the links.  In this way, Web sites can effectively play “go fish” with a user’s browser history file, asking if the visitor has visited www.facebook.com, or www.nytimes.com, or, perhaps more personally, www.viagra.com or www.gamblersanonymous.org.  If you’re curious to see how it works, the site www.whattheInternetknowsaboutyou.com provides several useful demonstrations.

The existence of this trick to query whether site visitors have visited a predetermined list of urls has been known for a long time.  It has been identified as “Bug 147777” in Mozilla’s development forum for nearly eight years.  And for years, researchers and privacy advocates have ask that the issue be addressed.  To date, nothing has been done, and unscrupulous Web site owners still maintain the capacity to determine whether site visitors have previously visited any other Web site.

Quite apart from the fact that Web sites don’t have the right to see where you’ve been on the Web, there are real dangers to unrestricted access to browser history files.  Identity thieves could find out what bank and credit card sites you use for better targeted phishing attacks. Furthermore, recent research suggests that sites could use data about visited urls to accurately determine the identity of site visitors.  One study released last month shows how a site could correlate browser history queries with publicly available information about group membership on popular social networking sites to reliably identify a large percentage of visitors to a particular Web site.  Thus, if you’re active on any number of popular social networking sites, any Web site you try to visit anonymously could very likely figure out who you are. Continue reading.

0saves
To have articles like this delivered automatically to your Feed Reader or Inbox, subscribe via RSS or email. For simple comments, use the commenting system, but for more involved assistance, please use the Question & Answer section.

Posts From The Same Category:




Questions & Answers Hola! Looking for an answer to a question but did not find it? Then surf on over to the Questions & Answers section. It's a brand new addition to our site, and we are waiting just to answer your question(s).

Leave a Reply

Trackbacks

Read previous post:
Scientist Invents a Digital Security Tool Good Enough for the CIA — And for You
Why I Am Against Software Patents
Who does that server really serve?
Close