Collected research
Request and Conquer: Exposing Cross-Origin Resource Size
TLS conceals content but not message size. Design flaws in browser storage and quota mechanisms let a cross-origin page measure the exact byte size of any resource fetched with the victim's cookies within seconds, and a further technique does the same against Wi-Fi traffic. The size of a personalised page reveals private facts about the user; a safer storage design is proposed.
Record
- Researcher
- Tom Van Goethem, Mathy Vanhoef, Frank Piessens and Wouter Joosen
- Published by
- usenix.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Tom Van Goethem, Mathy Vanhoef, Frank Piessens and Wouter Joosen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .