Collected research
An Empirical Study of Privacy-Violating Information Flows in JavaScript Web Applications
A rewriting-based JavaScript information-flow engine was built inside Chrome, injecting and propagating taints in rewritten source rather than in the runtime, then run over the Alexa top 50,000. It confirmed 46 sites sniffing browser history, cookies leaking to ad networks, and 7 popular sites covertly tracking clicks and mouse movement. Overhead was about 3x on script execution.
Record
- Researcher
- Dongseok Jang, Ranjit Jhala, Sorin Lerner and Hovav Shacham
- Published by
- cs.cornell.edu
- Format
- Whitepaper
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Dongseok Jang, Ranjit Jhala, Sorin Lerner and Hovav Shacham, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .