Web Hack List

Collected research

Browser history re:visited

Four new history sniffing attacks, two on visited links and two on caches, abuse modern browser features such as the CSS Paint API and the JavaScript bytecode cache, which handle cross-origin URL data without accounting for privacy. They let a page learn which sites a visitor has been to, one of them at roughly 3,000 URLs per second, against every browser tested but Tor Browser.

Record

Researcher
Michael Smith, Craig Disselkoen, Shravan Narayan, Fraser Brown and Deian Stefan
Published by
usenix.org
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Michael Smith, Craig Disselkoen, Shravan Narayan, Fraser Brown and Deian Stefan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .