The CNAME of the Game: Large-scale Analysis of DNS-based Tracking Evasion

02/18/2021
by   Yana Dimova, et al.
0

Online tracking is a whack-a-mole game between trackers who build and monetize behavioral user profiles through intrusive data collection, and anti-tracking mechanisms, deployed as a browser extension, built-in to the browser, or as a DNS resolver. As a response to pervasive and opaque online tracking, more and more users adopt anti-tracking tools to preserve their privacy. Consequently, as the information that trackers can gather on users is being curbed, some trackers are looking for ways to evade these tracking countermeasures. In this paper we report on a large-scale longitudinal evaluation of an anti-tracking evasion scheme that leverages CNAME records to include tracker resources in a same-site context, effectively bypassing anti-tracking measures that use fixed hostname-based block lists. Using historical HTTP Archive data we find that this tracking scheme is rapidly gaining traction, especially among high-traffic websites. Furthermore, we report on several privacy and security issues inherent to the technical setup of CNAME-based tracking that we detected through a combination of automated and manual analyses. We find that some trackers are using the technique against the Safari browser, which is known to include strict anti-tracking configurations. Our findings show that websites using CNAME trackers must take extra precautions to avoid leaking sensitive information to third parties.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/30/2019

Clash of the Trackers: Measuring the Evolution of the Online Tracking Ecosystem

Websites are constantly adapting the methods used, and intensity with wh...
research
11/13/2019

By the user, for the user: A user-centric approach to quantifying the privacy of websites

Third-party tracking is common on almost all commercially operated websi...
research
02/03/2022

Towards Understanding First-Party Cookie Tracking in the Field

Third-party web tracking is a common, and broadly used technique on the ...
research
03/18/2022

Trackers Bounce Back: Measuring Evasion of Partitioned Storage in the Wild

This work presents a systematic study of navigational tracking, the late...
research
08/07/2023

PURL: Safe and Effective Sanitization of Link Decoration

While privacy-focused browsers have taken steps to block third-party coo...
research
04/24/2018

WhoTracks.Me: Monitoring the online tracking landscape at scale

We present the largest and longest measurement of online tracking to dat...
research
02/14/2019

Spy the little Spies - Security and Privacy issues of Smart GPS trackers

Tracking expensive goods and/or targeted individuals with high-tech devi...

Please sign up or login with your details

Forgot password? Click here to reset