View unanswered posts | View active topics
It is currently Thu Jun 19, 2025 5:36 am
|
Page 1 of 1
|
[ 9 posts ] |
|
Private browsing modes in four biggest browsers often fail
Author |
Message |
pcernie
Legend
Joined: Sun Apr 26, 2009 12:30 pm Posts: 45931 Location: Belfast
|

 |  |  |  | Quote: Features in the four major browsers designed to cloak users' browser history often don't work as billed, according to a research paper that warns that users may get a false sense of security when using the built-in privacy settings.
The private-browsing modes are supposed to allow users to visit a website without leaving any trace on their computers, and yet Internet Explorer, Firefox, Chrome, and Safari frequently leave tracks, according to the research, which is scheduled to be presented at next week's Usenix Security Symposium in Washington DC. The makers of those browsers — Microsoft, Mozilla, Google, and Apple respectively — often hail the offerings as a way to enhance privacy when using shared computers.
One failure that affects IE, Firefox, and Safari happens when users save SSL, or secure sockets layer, client certificates while browsing in private mode. The browsers store a record of those actions in a file that allows anyone who has physical access to know exactly what site the user was visiting at the time. Similarly, when IE and Safari encounter a self-signed certificate, it is stored in a certificate vault that is preserved even after the private session ends.
Similarly, Firefox users who make security certificate settings while in private mode will have a partial copy of their browsing history stored in a file called cert8.db, the researchers said.
“We discovered that all these browsers retain the generated key pair even after private browsing ends,” the researchers wrote. “Again, if the user visits a site that generates an SSL client key pair, the resulting keys will leak the site's identity to the local attacker.”
The study (PDF here) showed each browser failing in specific settings.
The privacy mode in Firefox, for instance, is undermined when a user sets site-specific preferences or uses a variety of Mozilla-sanctioned plug-ins. The open-source browser also stores websites visited that dole out custom protocol handlers based on the HTML5 standard.
For its part, IE's InPrivate mode can be undermined when websites make SMB queries, since the Microsoft browser shares large chunks of code with Windows Explorer.
The researchers also devised a way for webmasters to detect when someone visiting their sites is using the privacy mode. It involves placing an iframe with a unique web address and then “using JavaScript to check whether a link to that URL was displayed as purple (visited) or blue (unvisited).”
The researchers said that to the best of their knowledge they are the first to demonstrate a way to detect private browsing mode — but that may not really matter for much longer. The technique appears to use the decade-old browser history attack, which was recently fixed in Safari and will soon be fixed in Firefox. It's only a matter of time before Microsoft and Google follow suit.
Using the technique, they confirmed what we all suspected: the feature is mainly used when surfing to porn sites. Gift and news sites, not so much. |  |  |  |  |
http://www.theregister.co.uk/2010/08/06 ... e_failure/I always suspected something like that would be the case, private mode just seemed too easy 
_________________Plain English advice on everything money, purchase and service related:
http://www.moneysavingexpert.com/
|
Fri Aug 06, 2010 9:14 am |
|
 |
l3v1ck
What's a life?
Joined: Fri Apr 24, 2009 10:21 am Posts: 12700 Location: The Right Side of the Pennines (metaphorically & geographically)
|
I think for most people the current level of protection is just fine. For example people trying to hide surprises from their partners rather than terrorist material from the police.
|
Fri Aug 06, 2010 9:31 am |
|
 |
Amnesia10
Legend
Joined: Fri Apr 24, 2009 2:02 am Posts: 29240 Location: Guantanamo Bay (thanks bobbdobbs)
|
And what surprises would those include? That you are about to run off with a Tranny called Roxanne whom you met on Chicks with dicks need love* website  * I do not know if such website exists I made it up before you start looking for a profile of me on there! 
_________________Do concentrate, 007... "You are gifted. Mine is bordering on seven seconds." https://www.dropbox.com/referrals/NTg5MzczNTkhttp://astore.amazon.co.uk/wwwx404couk-21
|
Fri Aug 06, 2010 2:11 pm |
|
 |
l3v1ck
What's a life?
Joined: Fri Apr 24, 2009 10:21 am Posts: 12700 Location: The Right Side of the Pennines (metaphorically & geographically)
|
I was thinking more along the lines of a surprise weekend away etc.
|
Sat Aug 07, 2010 7:17 am |
|
 |
soddit112
Spends far too much time on here
Joined: Thu Apr 23, 2009 6:12 pm Posts: 2020 Location: Mute City
|
i see your point, but its not like the average person would know how to access these files, or what they actually mean should they stumble upon them 
|
Sat Aug 07, 2010 9:33 am |
|
 |
Amnesia10
Legend
Joined: Fri Apr 24, 2009 2:02 am Posts: 29240 Location: Guantanamo Bay (thanks bobbdobbs)
|
Why not use a second browser? Most people only think if IE or Firefox. So if you have Opera, Camino, Safari or Chrome they would never even realise that you have another search history to look through.
_________________Do concentrate, 007... "You are gifted. Mine is bordering on seven seconds." https://www.dropbox.com/referrals/NTg5MzczNTkhttp://astore.amazon.co.uk/wwwx404couk-21
|
Sat Aug 07, 2010 12:07 pm |
|
 |
forquare1
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 6:36 pm Posts: 5152 Location: /dev/tty0
|
That means the person who is wanting to hide their browsing has to know about them browsers too... I agree with l3v1ck, for most people, the current level of hiding is fine.
|
Sat Aug 07, 2010 12:37 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
Yeah, and to be honest - I doubt people actively look through their partner's web browsing history unless they suspect something.
But a lot of the modern browsers have auto-complete features for URLs which could really easily give the game away.
_________________
|
Sat Aug 07, 2010 12:53 pm |
|
 |
Amnesia10
Legend
Joined: Fri Apr 24, 2009 2:02 am Posts: 29240 Location: Guantanamo Bay (thanks bobbdobbs)
|
I agree with you both. It is perfectly adequate for the vast majority of people. I have never used the feature as I do not need it.
_________________Do concentrate, 007... "You are gifted. Mine is bordering on seven seconds." https://www.dropbox.com/referrals/NTg5MzczNTkhttp://astore.amazon.co.uk/wwwx404couk-21
|
Sat Aug 07, 2010 2:03 pm |
|
|
|
Page 1 of 1
|
[ 9 posts ] |
|
Who is online |
Users browsing this forum: No registered users and 8 guests |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum
|
|