Breaking News

LIAN LI Launches Multi-Directional Vertical GPU Mounting Bracket with PCIe 5.0 Riser Cable Samsung announces Galaxy Tab S10 Lite Nikon releases the NIKKOR Z 24-70mm f/2.8 S II CORSAIR ONE a600 Brings Improved Cooling and Adaptive Performance in a Compact Design Speedlink setting the tone in the gaming zone

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Browsers' Password Managers Are Used by Advertisers' Scripts For Tracking Sites

Browsers' Password Managers Are Used by Advertisers' Scripts For Tracking Sites

Enterprise & IT Dec 31,2017 0

Web browsers' built-in password managers is abused by third-party scripts for tracking on more than a thousand sites, according to researchers.

Nearly every web browser now comes with built-in login managers (also called password managers). According to a new research from Princeton's Center for Information Technology Policy, third-party scripts exploit thsese password managers to retrieve and exfiltrate user identifiers without user awareness.

The underlying vulnerability of login managers to credential theft has been known for years.

The researchers haven't found password theft on the 50,000 sites that they analyzed, but they found tracking scripts embedded by the first party abusing the same technique to extract emails addresses for building tracking identifiers.

Here is how it works: First, a user fills out a login form on the page and asks the browser to save the login. The tracking script is not present on the login page. Then, the user visits another page on the same website which includes the third-party tracking script. The tracking script inserts an invisible login form, which is automatically filled in by the browser's login manager. The third-party script retrieves the user's email address by reading the populated form and sends the email hashes to third-party servers.

The researchers examined two different scripts - AdThink and OnAudience - both of are designed to get identifiable information out of browser-based password managers. The scripts work by injecting invisible login forms in the background of the webpage and scooping up whatever the browsers autofill into the available slots. That information can then be used as a persistent ID to track users from page to page, a potentially valuable tool in targeting advertising.

According to the researchers, there's no technical measure to stop scripts from collecting passwords. The only fix would be to change how password managers work, requiring more explicit approval before submitting information.

Tags:
Previous Post
Qualcomm Had the Highest Smartphone SoC Market Share in Q3 2017
Next Post
Mobile Devices Use More GPUs Than All Other Platforms Combined

Related Posts

Latest News

LIAN LI Launches Multi-Directional Vertical GPU Mounting Bracket with PCIe 5.0 Riser Cable
Enterprise & IT

LIAN LI Launches Multi-Directional Vertical GPU Mounting Bracket with PCIe 5.0 Riser Cable

Samsung announces Galaxy Tab S10 Lite
Consumer Electronics

Samsung announces Galaxy Tab S10 Lite

Nikon releases the NIKKOR Z 24-70mm f/2.8 S II
Cameras

Nikon releases the NIKKOR Z 24-70mm f/2.8 S II

CORSAIR ONE a600 Brings Improved Cooling and Adaptive Performance in a Compact Design
Cooling Systems

CORSAIR ONE a600 Brings Improved Cooling and Adaptive Performance in a Compact Design

Speedlink setting the tone in the gaming zone
PC components

Speedlink setting the tone in the gaming zone

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Terramaster F8-SSD

Terramaster F8-SSD

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Pure Base 501

be quiet! Pure Base 501

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed