Web Hack List

Collected research

Google User De-Anonymization

New Timing Attack Could De-Anonymize Google Users

Andrew Cantino's timing attack de-anonymises a chosen Google user: silently share a Google document with the target's address, then load it as an image and time the onerror callback. Loading averaged 891 ms when the document was accessible against 573 ms when it was not, revealing that account's presence with no cookie set.

Record

Document
New Timing Attack Could De-Anonymize Google Users
Researcher
Michael Mimoso
Published by
Threatpost | The first stop for security news
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michael Mimoso, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .