Tracking Users across the Web via TLS Session Resumption

10/16/2018
by   Erik Sy, et al.
0

User tracking on the Internet can come in various forms, e.g., via cookies or by fingerprinting web browsers. A technique that got less attention so far is user tracking based on TLS and specifically based on the TLS session resumption mechanism. To the best of our knowledge, we are the first that investigate the applicability of TLS session resumption for user tracking. For that, we evaluated the configuration of 48 popular browsers and one million of the most popular websites. Moreover, we present a so-called prolongation attack, which allows extending the tracking period beyond the lifetime of the session resumption mechanism. To show that under the observed browser configurations tracking via TLS session resumptions is feasible, we also looked into DNS data to understand the longest consecutive tracking period for a user by a particular website. Our results indicate that with the standard setting of the session resumption lifetime in many current browsers, the average user can be tracked for up to eight days. With a session resumption lifetime of seven days, as recommended upper limit in the draft for TLS version 1.3, 65 in our dataset can be tracked permanently.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/15/2018

From Videos to URLs: A Multi-Browser Guide To Extract User's Behavior with Optical Character Recognition

Tracking users' activities on the World Wide Web (WWW) allows researcher...
research
12/12/2013

Managing NymBoxes for Identity and Tracking Protection

Despite the attempts of well-designed anonymous communication tools to p...
research
09/19/2020

On Multi-Session Website Fingerprinting over TLS Handshake

Analyzing users' Internet traffic data and activities has a certain impa...
research
07/04/2018

Teaching DevOps in Corporate Environments: An experience report

This paper describes our experience of training a team of developers of ...
research
04/03/2023

Quantifying Carbon Emissions due to Online Third-Party Tracking

In the past decade, global warming made several headlines and turned the...
research
08/04/2023

Who Is Alyx? A new Behavioral Biometric Dataset for User Identification in XR

This article presents a new dataset containing motion and physiological ...
research
05/15/2018

The remote_build Tool

This is an introduction to the remote_build tool for transparent remote ...

Please sign up or login with your details

Forgot password? Click here to reset