论文标题

信息通过Safari的智能跟踪预防泄漏

Information Leaks via Safari's Intelligent Tracking Prevention

论文作者

Janc, Artur, Kotowicz, Krzysztof, Weichselbaum, Lukas, Clapis, Roberto

论文摘要

智能跟踪预防(ITP)是Apple的Safari浏览器实施的隐私机制,于2017年10月发布。ITP旨在通过限制Cookie和其他网站数据的功能来减少Web用户的跨站点跟踪。作为常规安全审查的一部分,Google的信息安全工程团队已确定了Safari ITP设计中的多个安全性和隐私问题。这些问题会带来许多意外的后果,包括披露用户的网络浏览习惯,允许持续的跨站点跟踪以及启用跨站点信息泄漏(包括跨站点搜索)。该报告是我们对Apple的原始漏洞提交的适度扩展版本(Webkit Bug#201319),提供了其他上下文,并为清晰度进行了编辑。此处讨论的许多问题已在2019年12月发布的Safari 13.0.4和iOS 13.3中解决。

Intelligent Tracking Prevention (ITP) is a privacy mechanism implemented by Apple's Safari browser, released in October 2017. ITP aims to reduce the cross-site tracking of web users by limiting the capabilities of cookies and other website data. As part of a routine security review, the Information Security Engineering team at Google has identified multiple security and privacy issues in Safari's ITP design. These issues have a number of unexpected consequences, including the disclosure of the user's web browsing habits, allowing persistent cross-site tracking, and enabling cross-site information leaks (including cross-site search). This report is a modestly expanded version of our original vulnerability submission to Apple (WebKit bug #201319), providing additional context and edited for clarity. A number of the issues discussed here have been addressed in Safari 13.0.4 and iOS 13.3, released in December 2019.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源