Enhanced Performance and Privacy for TLS over TCP Fast Open

05/09/2019
by   Erik Sy, et al.
0

Small TCP flows make up the majority of web flows. For them, the TCP three-way handshake represents a significant delay overhead. The TCP Fast Open (TFO) protocol provides zero round-trip time (0-RTT) handshakes for subsequent TCP connections to the same host. In this paper, we present real-world privacy and performance limitations of TFO. We investigated its deployment on popular websites and browsers. We found that a client revisiting a web site for the first time fails to use an abbreviated TFO handshake about 40 to web server load-balancing. Our analysis further reveals significant privacy problems in the protocol design and implementation. Network-based attackers and online trackers can exploit these shortcomings to track the online activities of users. As a countermeasure, we introduce a novel protocol called TCP Fast Open Privacy (FOP). It overcomes the performance and privacy limitations of TLS over TFO by utilizing a custom TLS extension. TCP FOP prevents tracking by network attackers and impedes third-party tracking, while still allowing for 0-RTT handshakes as in TFO. As a proof-of-concept, we have implemented the proposed protocol. Our measurements indicate that TCP FOP outperforms TLS over TFO when websites are served from multiple IP addresses.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/13/2019

By the user, for the user: A user-centric approach to quantifying the privacy of websites

Third-party tracking is common on almost all commercially operated websi...
research
05/23/2019

Beyond Cookie Monster Amnesia: Real World Persistent Online Tracking

Browser fingerprinting is a relatively new method of uniquely identifyin...
research
08/13/2019

Enhanced Performance and Privacy via Resolver-Less DNS

The domain name resolution into IP addresses can significantly delay con...
research
09/01/2021

The Internet with Privacy Policies: Measuring The Web Upon Consent

To protect users' privacy, legislators have regulated the usage of track...
research
01/31/2021

Follow the Scent: Defeating IPv6 Prefix Rotation Privacy

IPv6's large address space provides ample freedom for assigning addresse...
research
01/07/2020

Is Cryptojacking Dead after Coinhive Shutdown?

Cryptojacking is the exploitation of victims' computer resources to mine...
research
10/27/2021

Masked LARk: Masked Learning, Aggregation and Reporting worKflow

Today, many web advertising data flows involve passive cross-site tracki...

Please sign up or login with your details

Forgot password? Click here to reset