Live data from Hacker News

Information Leaks via Safari’s Intelligent Tracking Prevention

arxiv.org

31–37 of 37 posts

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#31
Last time Google researchers made similar discoveries, 2012, it was used to ... track users :-)

https://www.ghacks.net/2012/02/21/microsoft-google-is-also-b...

"We used known Safari functionality to provide features that signed-in Google users had enabled. It’s important to stress that these advertising cookies do not collect personal information."

and bypassing IE third party cookie protection: "impractical to comply with Microsoft’s request while providing modern web functionality." Google says complying with tracking protection is Impractical!

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#32
post #29
post #26

We've addressed the issues disclosed to us, and if you try any of the 5 POCs in the paper you will find they no longer work in the latest Safari. Details of the fixes here: https://webkit.org/blog/9661/preventing-tracking-prevention-... There may be room for more improvement here but be aware what the POCs illustrate is not an active vulnerability any more. In addition, we don't believe this channel was ever exploite…

If only we had the same level of transparency in native apps. At least in Chrome, Firefox, Safari - you have dedicated large groups of engineers thinking about privacy, security and stability. Compared to native iOS/android where you get isolated groups of developers able to exploit and track with little to no visibility from end users - let alone access to source code for review by third party software engineers lik…

> It’s madding that apple doesn't invest more in its browser and yet pretends to care so much about privacy - of the major three browsers - apple definitely _seems_ to underinvest when it comes to web technology...

Well, WebKit came from Apple’s work on KHTML. So Safari, Chrome, Edge ...

”KHTML and KJS were adopted by Apple in 2002 for use in the Safari web browser. Apple publishes the source code for their fork of the KHTML engine, called WebKit. In 2013, Google began development on a fork of WebKit, called Blink.”

https://en.wikipedia.org/wiki/KHTML

That’s not that long ago in browser families, and 2002 - 2013 is 11 years of investment in web tech that now everyone else built on. And they didn’t stop investing.

Some of those investments:

- It’s mostly been the least battery hungry modern browser (by a long shot) on the most wished for dev laptop, and in many cases, the highest performance.

- The bookmark and tab sync across devices is seamlessly slick. I regularly end up maxed on tabs (it’s in the 100s of tabs open at once) and can access any / all of them across all devices sharing iCloud account. Also appreciate that across all kinds of devices, you can save all open tabs to a folder of tabs, then close all tabs, and immediate get at those 300 tabs in the bookmarks from another machine. All those bookmarks are searchable too. None of this slows it down.

- Built in reader mode works beautifully. Reading List is there too.

- Saving a web page to file can save clean reader views into full length PDFs. They’re amazing!

- Interacts with keychain, essentially has LastPass “built in” if you let it store passwords on your keychain.

- While I miss UBlock Origin, ad blockers like 1BlockerX work great across iPad, iPhone, and MacOS. (See also AdGuard for Safari.)

- ITP performs better than one would expect for something you don’t think about at all, while not breaking most banks, which I appreciate.

- Safari never kills my iPad, iPhone, or Mac. Once in a blue moon a terrible site makes me ‘eject’ Safari from running apps on iOS. Launch it again, and all your tabs etc. are fine.

There’s a lot to like, except it’s not super tweakable, or basically “it’s not Chrome”. Even there, most devs or tech geeks who grump at Safari and reach for Chrome, have no idea of the lineage.

Doesn’t seem fair to call it under-invested in.

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#33
post #8
post #5

There is a fundamental difficulty when trying to implement privacy: A limit on the disclosure of information is itself a disclosure of information. A good privacy design needs to confront this issue directly. Sometimes there's nothing to be done. I think in some cases it's mathematically unsolvable (cf. Cynthia Dwork's paper on Differential Privacy). But an explicit consideration can at least surface some trade-offs.…

It makes me think of password requirements. Isn't it bad to earmark a password as requiring certain things rather than to let the possibilities be completely open?

Consider two websites: website A and website B. Website A places no limitations on passwords except that they all have to be from the base64 character set, and be 1-30 characters in length (inclusive). Website B says all passwords must be at least 8-30 characters long and contain one number and one special character.

Technically, there are 1556820866911379157697368408533647424628560378091278400 possibilities for a given password from the first site, and only 1553740989173808677121103544993503115087947728215015424 for the second site. That's only 0.2% fewer total passwords. However, consider that the typical user's password is probably 6-8 characters and contains only lowercase letters; that means that most users from the first website have only 217167790528 possibilities, while users from the second website--even assuming they only go the bare minimum of 6 lowercase characters + one special character + one number--have 345985669120 password possibilities, which is about 60% more. And that's with the artificial base64 limitation; if you open it up to the full complement of 30 special characters it's significantly more.

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#34
post #29

Earlier quoted context omitted.

If only we had the same level of transparency in native apps. At least in Chrome, Firefox, Safari - you have dedicated large groups of engineers thinking about privacy, security and stability. Compared to native iOS/android where you get isolated groups of developers able to exploit and track with little to no visibility from end users - let alone access to source code for review by third party software engineers lik…

> It’s madding that apple doesn't invest more in its browser and yet pretends to care so much about privacy - of the major three browsers - apple definitely _seems_ to underinvest when it comes to web technology... Well, WebKit came from Apple’s work on KHTML. So Safari, Chrome, Edge ... ”KHTML and KJS were adopted by Apple in 2002 for use in the Safari web browser. Apple publishes the source code for their fork of t…

Hey hey, "Google Chrome" (+ MS Edge) is not everyone else. Firefox exists and is based on Gecko, which is based on Netscape, they've had a separate and unbroken lineage for 23 years now.

Apple's OSS work tends feel well-made (I use CUPS on Devuan, they own that), but they are not and will never be "The One True Web Tech Makers".

Still, they're the biggest ones on the market as of today, if you count their offspring, Blink.

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#35
post #25

Earlier quoted context omitted.

Chrome is restricting fingerprinting, but they still ship google analytics in the browser itself so it's harder to block. They'll only really block fingerprinting in their browser when they have no use for it.

I do not see connections on my network to google when I open and browse to 3rd party sites. Can you show me that's true? If it is, that's fairly interesting.

Look in the inspector of a page using GA, and you’ll see it’s served from within the browser, rather than as a download from the network.

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#36
post #12

Earlier quoted context omitted.

Based on that, won't the presence of facebook on the ITP list mean either you go to Facebook, or that you've been to multiple sites that have checked if you go to Facebook? ie, won't these techniques soon end up with all false positives?

If you make random domains that only your site references, and they're on someone's list, then you know it's your site

You don't need this to determine that someone goes to your site—they're there. This is for tracking people as they go to other sites, and for determining what other sites the people on your site have gone to.

Re: Information Leaks via Safari’s Intelligent Tracking Prevention

#37
post #18
post #3

Reposting from the other [1] thread: Basically Safari keeps track of which domains are being requested in a 3rd party context (i.e. I load example.com in my browser and the page loads the facebook sdk - Safari increments a counter for facebook by 1). Once a given domain reaches 3 hits, Safari will strip cookies and some other data in 3rd party requests to that domain. The problem is that advertisers can use this to f…

Please don't copy/paste comments on HN. It lowers the signal/noise ratio and makes for pain when we go to merge duplicate threads. If you want to refer to something you posted elsewhere, please use a link. Better still, when you see a split discussion, email hn@ycombinator.com so we can merge them. We'll make sure your comment ends up in the winning thread. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que…

This policy is odd.

The link could die, the text at the link could change, or the comment at the link could be deleted. Not to mention a comment section full of links is ugly and unreadable.

StackOverflow has the exact opposite approach because they don’t want their site riddled with dead links.

How many people will care enough to send an email to have a comment merger? That really isn’t a solution to whatever “problem” this is.

Post reply on HN