De-anonymizing website visitors via FB timing attacks
1–5 of 5 posts
Re: De-anonymizing website visitors via FB timing attacks
#2Re: De-anonymizing website visitors via FB timing attacks
#3Site is in German. Google Translate has given me an idea as to the content of article but I'm still a little confused about how the timing attack works. Is someone able to explain this better please?
Re: De-anonymizing website visitors via FB timing attacks
#4Site is in German. Google Translate has given me an idea as to the content of article but I'm still a little confused about how the timing attack works. Is someone able to explain this better please?
Re: De-anonymizing website visitors via FB timing attacks
#5Site is in German. Google Translate has given me an idea as to the content of article but I'm still a little confused about how the timing attack works. Is someone able to explain this better please?
The author created a number of "Promoted Posts" on Facebook, for different age groups and relations. Then they send a series of requests to FB on behalf of the visitor. FB rejects them, but because they amount of time they take varies depending on whether they would see the promoted post or not, the site owner can use the time that FB takes to determine if their visitor would have seen the promoted post—and thus, whe…