Reply to topic  [ 9 posts ] 
Private browsing modes in four biggest browsers often fail 
Author Message
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
Quote:
Features in the four major browsers designed to cloak users' browser history often don't work as billed, according to a research paper that warns that users may get a false sense of security when using the built-in privacy settings.

The private-browsing modes are supposed to allow users to visit a website without leaving any trace on their computers, and yet Internet Explorer, Firefox, Chrome, and Safari frequently leave tracks, according to the research, which is scheduled to be presented at next week's Usenix Security Symposium in Washington DC. The makers of those browsers — Microsoft, Mozilla, Google, and Apple respectively — often hail the offerings as a way to enhance privacy when using shared computers.

One failure that affects IE, Firefox, and Safari happens when users save SSL, or secure sockets layer, client certificates while browsing in private mode. The browsers store a record of those actions in a file that allows anyone who has physical access to know exactly what site the user was visiting at the time. Similarly, when IE and Safari encounter a self-signed certificate, it is stored in a certificate vault that is preserved even after the private session ends.

Similarly, Firefox users who make security certificate settings while in private mode will have a partial copy of their browsing history stored in a file called cert8.db, the researchers said.

“We discovered that all these browsers retain the generated key pair even after private browsing ends,” the researchers wrote. “Again, if the user visits a site that generates an SSL client key pair, the resulting keys will leak the site's identity to the local attacker.”

The study (PDF here) showed each browser failing in specific settings.

The privacy mode in Firefox, for instance, is undermined when a user sets site-specific preferences or uses a variety of Mozilla-sanctioned plug-ins. The open-source browser also stores websites visited that dole out custom protocol handlers based on the HTML5 standard.

For its part, IE's InPrivate mode can be undermined when websites make SMB queries, since the Microsoft browser shares large chunks of code with Windows Explorer.

The researchers also devised a way for webmasters to detect when someone visiting their sites is using the privacy mode. It involves placing an iframe with a unique web address and then “using JavaScript to check whether a link to that URL was displayed as purple (visited) or blue (unvisited).”

The researchers said that to the best of their knowledge they are the first to demonstrate a way to detect private browsing mode — but that may not really matter for much longer. The technique appears to use the decade-old browser history attack, which was recently fixed in Safari and will soon be fixed in Firefox. It's only a matter of time before Microsoft and Google follow suit.

Using the technique, they confirmed what we all suspected: the feature is mainly used when surfing to porn sites. Gift and news sites, not so much.


http://www.theregister.co.uk/2010/08/06 ... e_failure/

I always suspected something like that would be the case, private mode just seemed too easy :)

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Fri Aug 06, 2010 9:14 am
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
I think for most people the current level of protection is just fine. For example people trying to hide surprises from their partners rather than terrorist material from the police.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Fri Aug 06, 2010 9:31 am
Profile WWW
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
l3v1ck wrote:
I think for most people the current level of protection is just fine. For example people trying to hide surprises from their partners rather than terrorist material from the police.

And what surprises would those include? That you are about to run off with a Tranny called Roxanne whom you met on Chicks with dicks need love* website :shock: :D

* I do not know if such website exists I made it up before you start looking for a profile of me on there! :D

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Fri Aug 06, 2010 2:11 pm
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
I was thinking more along the lines of a surprise weekend away etc.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Sat Aug 07, 2010 7:17 am
Profile WWW
Spends far too much time on here

Joined: Thu Apr 23, 2009 6:12 pm
Posts: 2020
Location: Mute City
Reply with quote
l3v1ck wrote:
I was thinking more along the lines of a surprise weekend away etc.


i see your point, but its not like the average person would know how to access these files, or what they actually mean should they stumble upon them :wink:


Sat Aug 07, 2010 9:33 am
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
l3v1ck wrote:
I was thinking more along the lines of a surprise weekend away etc.

Why not use a second browser? Most people only think if IE or Firefox. So if you have Opera, Camino, Safari or Chrome they would never even realise that you have another search history to look through.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Sat Aug 07, 2010 12:07 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:36 pm
Posts: 5152
Location: /dev/tty0
Reply with quote
Amnesia10 wrote:
l3v1ck wrote:
I was thinking more along the lines of a surprise weekend away etc.

Why not use a second browser? Most people only think if IE or Firefox. So if you have Opera, Camino, Safari or Chrome they would never even realise that you have another search history to look through.


That means the person who is wanting to hide their browsing has to know about them browsers too...

I agree with l3v1ck, for most people, the current level of hiding is fine.


Sat Aug 07, 2010 12:37 pm
Profile WWW
Spends far too much time on here
User avatar

Joined: Thu Apr 23, 2009 11:36 pm
Posts: 3527
Location: Portsmouth
Reply with quote
Yeah, and to be honest - I doubt people actively look through their partner's web browsing history unless they suspect something.

But a lot of the modern browsers have auto-complete features for URLs which could really easily give the game away.

_________________
Image


Sat Aug 07, 2010 12:53 pm
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
forquare1 wrote:
Amnesia10 wrote:
l3v1ck wrote:
I was thinking more along the lines of a surprise weekend away etc.

Why not use a second browser? Most people only think if IE or Firefox. So if you have Opera, Camino, Safari or Chrome they would never even realise that you have another search history to look through.


That means the person who is wanting to hide their browsing has to know about them browsers too...

I agree with l3v1ck, for most people, the current level of hiding is fine.

I agree with you both. It is perfectly adequate for the vast majority of people. I have never used the feature as I do not need it.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Sat Aug 07, 2010 2:03 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 9 posts ] 

Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.