Quantifying User Password Exposure to Third-Party CDNs

01/09/2023
by   Rui Xin, et al.
0

Web services commonly employ Content Distribution Networks (CDNs) for performance and security. As web traffic is becoming 100 websites allow CDNs to terminate their HTTPS connections. This practice may expose a website's user sensitive information such as a user's login password to a third-party CDN. In this paper, we measure and quantify the extent of user password exposure to third-party CDNs. We find that among Alexa top 50K websites, at least 12,451 of them use CDNs and contain user login entrances. Among those websites, 33 popular CDN may observe passwords from more than 40 result suggests that if a CDN infrastructure has a vulnerability or an insider attack, many users' accounts will be at risk. If we assume the attacker is a passive eavesdropper, a website can avoid this vulnerability by encrypting users' passwords in HTTPS connections. Our measurement shows that less than 17 of the websites adopt this countermeasure.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/02/2018

Include Me Out: In-Browser Detection of Malicious Third-Party Content Inclusions

Modern websites include various types of third-party content such as Jav...
research
03/06/2018

Pathways to Fragmentation:User Flows and Web Distribution Infrastructures

This study analyzes how web audiences flow across online digital feature...
research
02/10/2023

Exploring the Cookieverse: A Multi-Perspective Analysis of Web Cookies

Web cookies have been the subject of many research studies over the last...
research
02/02/2023

A Transcontinental Analysis of Account Remediation Protocols of Popular Websites

Websites are used regularly in our day-today lives, yet research has sho...
research
04/26/2019

Characterizing web pornography consumption from passive measurements

Web pornography represents a large fraction of the Internet traffic, wit...
research
03/16/2019

Pythia: a Framework for the Automated Analysis of Web Hosting Environments

A common approach when setting up a website is to utilize third party We...
research
08/19/2020

Automatic Generation of Chatbots for Conversational Web Browsing

In this paper, we describe the foundations for generating a chatbot out ...

Please sign up or login with your details

Forgot password? Click here to reset