Live data from Hacker News

Cname cloaking, a disguise of third-party trackers

medium.com

1–10 of 202 posts

Re: Cname cloaking, a disguise of third-party trackers

#5
post #2

So block content, as always? That's not possible for NextDNS, which I guess is their concern, but then DNS blocking was always going to be a very very blunt instrument.

>Security implications of CNAME Cloaking

>While this is considered bad practice for a website to set cookies as accessible to all subdomains (i.e., *.website.com), many do this.

>In that case, those cookies are automatically sent to the cloaked third-party tracker.

Re: Cname cloaking, a disguise of third-party trackers

#8
post #2

So block content, as always? That's not possible for NextDNS, which I guess is their concern, but then DNS blocking was always going to be a very very blunt instrument.

At home I'm using it in addition to ad blocking in the browser, for apps and other things that might slip through.

Currently it's just dnsmasq with a huge blacklist, and I guess it doesn't support checking the whole CNAME chain against that list, which would be really cool.

Re: Cname cloaking, a disguise of third-party trackers

#9
post #5
post #2

So block content, as always? That's not possible for NextDNS, which I guess is their concern, but then DNS blocking was always going to be a very very blunt instrument.

>Security implications of CNAME Cloaking >While this is considered bad practice for a website to set cookies as accessible to all subdomains (i.e., *.website.com), many do this. >In that case, those cookies are automatically sent to the cloaked third-party tracker.

So website.com decided to sellout and now the cookies you send to website.com that betrayed your trust are also sent to it's chosen third-party tracker?

That is a distinction without difference. The security implication is storing any data with website.com!

Post reply on HN