Pool-Party: Exploiting Browser Resource Pools as Side-Channels for Web Tracking

12/12/2021
by   Peter Snyder, et al.
0

We identify a new class of side-channels in browsers that are not mitigated by current defenses. This class of side-channels, which we call "pool-party" attacks, allow sites to create covert channels by manipulating limited-but-unpartitioned resource pools in browsers. We identify pool-party attacks in all popular browsers, and show they are practical cross-site tracking techniques. In this paper we make the following contributions: first, we describe pool-party side-channel attacks that exploit limits in application-layer resource pools in browsers. Second, we demonstrate that pool-party attacks are practical, and can be used to track users in all popular browsers; we also share open source implementations of the attack and evaluate them through a representative web crawl. Third, we show that in Gecko based-browsers (including the Tor Browser Bundle) pool-party attacks can also be used for cross-profile tracking (e.g., linking user behavior across normal and private browsing sessions). Last, we discuss possible mitigations and defenses.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/06/2019

Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks

In a Cross-Origin State Inference (COSI) attack, an attacker convinces a...
research
02/03/2022

Towards Understanding First-Party Cookie Tracking in the Field

Third-party web tracking is a common, and broadly used technique on the ...
research
08/25/2022

COOKIEGRAPH: Measuring and Countering First-Party Tracking Cookies

Recent privacy protections by browser vendors aim to limit the abuse of ...
research
05/13/2021

Hedging Against Sore Loser Attacks in Cross-Chain Transactions

A *sore loser attack* in cross-blockchain commerce rises when one party ...
research
04/13/2023

Majority is not Needed: A Counterstrategy to Selfish Mining

In the last few years several papers investigated selfish mine attacks, ...
research
08/11/2022

Towards Automated Key-Point Detection in Images with Partial Pool View

Sports analytics has been an up-and-coming field of research among profe...
research
02/07/2018

Measuring third party tracker power across web and mobile

Third-party networks collect vast amounts of data about users via web si...

Please sign up or login with your details

Forgot password? Click here to reset