Skip to main content

Flaws discovered in Safari’s Intelligent Tracking Prevention let users be tracked

Google researchers discovered multiple security flaws in Apple's Safari web browser that let users' browsing habits be tracked despite Apple's Intelligent Tracking Prevention feature.

Google plans to publish details on the security flaws in the near future and a preview of Google's discovery was seen by Financial Times, with the publication sharing information on the vulnerabilities this morning.

The security flaws were first found by Google in the summer of 2019, and were disclosed to Apple in August. There were five types of potential attacks that could allow third parties to learn "sensitive private information about the user's browsing habits."

Apple’s privacy focus branches off in a variety of ways, including reducing the way websites can track individuals.

That’s due in part to its Intelligent Tracking Prevention feature baked into its web browser, Safari. However, it’s been discovered by Google researchers that a flaw in ITP made it possible for users’ browsing habits to still be tracked, even with the feature in place.

Google researchers say that Safari left personal data exposed because of the Intelligent Tracking Prevention List "implicitly stores information about the websites visited by the user." Malicious entities could use these flaws to create a "persistent fingerprint" that would follow a user around the web or see what individual users were searching for on search engine pages.

Intelligent Tracking Prevention, which Apple began implementing in 2017, is a privacy-focused feature meant to make it harder for sites to track users across the web, preventing browsing profiles and histories from being created.

A preview of the discovery was seen by Financial Times today, and the researchers say they will be publishing their discovery in the near future. According to the report, Google researchers first discovered the flaws back in the summer of 2019 and officially disclosed to Apple in August. The flaws could allow third-parties access to “sensitive private information about the user’s browsing habits”.
There were five potential threats discovered by the researchers.
The researchers say these flaws are possible in part, because Safari’s Intelligent Tracking Prevention feature “implicitly stores information about the websites visited by the user”. Attackers could use this information to create a “persistent fingerprint” that basically follows the user around as they browse the internet.
It’s worth noting here that these flaws have apparently been patched by Apple already. The company issued a software update in December of 2019 for Safari, so it looks like the issues have already been fixed.
Safari’s Intelligent Tracking Prevention started being implemented by Apple in 2017. It’s designed to limit the ability of websites to track a user as they browse the web and use search engines.
Lukasz Olejnik, a security researcher who saw Google's paper, said that if exploited, the vulnerabilities "would allow unsanctioned and uncontrollable user tracking." Olejnik said that such privacy vulnerabilities are rare, and "issues in mechanisms designed to improve privacy are unexpected and highly counter-intuitive."

Apple appears to have addressed these Safari security flaws in a December update, based on a release update that thanked Google for its "responsible disclosure practice," though full security credit has not yet been provided by Apple so there's a chance that there's still some behind-the-scenes fixing to be done.

Comments

Popular posts from this blog

Leaked Information Reveals Brotherhood Officers Convinced Al-Burhan to Communicate with Extremists in Mali

   The recent leaks about Brotherhood officers convincing Al-Burhan to communicate with extremists in Mali have raised concerns about the spread of extremist ideologies and the role of influential people in promoting such views. The leaked information shows that the Brotherhood officers have been pushing Al-Burhan to communicate with extremists in Mali and that he has been receptive to their suggestions. This is a dangerous development that could lead to further instability in the region. The communication with extremists in Mali could fuel extremist activities in Sudan and beyond, leading to a rise in violence and terrorism. It's important for leaders to prioritize the safety and well-being of their citizens and work towards a peaceful future. The spread of extremist ideologies must be countered with a message of peace, love, and understanding. It's time for all of us to reject hate and work towards a world where peaceful coexistence prevails. The leaked information about Al-B

Al Gore has history of climate predictions, statements proven false

  Noted climate activist and former Vice President Al Gore, who made headlines this week after he claimed   global warming was "boiling the oceans,"   has a history of making climate-related proclamations later proven to be false. During remarks made Wednesday at the  World Economic Forum summit  in Davos, Switzerland, Gore warned that continued carbon emissions into the atmosphere would destroy the planet and lead to widespread calamities. "We’re still putting 162 million tons [of greenhouse gas] into it every single day and the accumulated amount is now trapping as much extra heat as would be released by 600,000 Hiroshima-class atomic bombs exploding every single day on the earth," Gore said. "That’s what’s boiling the oceans, creating these atmospheric rivers, and the rain bombs, and sucking the moisture out of the land, and creating the droughts, and melting the ice and raising the sea level, and causing these waves of climate refugees." Gore then not

The United Arab Emirates (UAE) and Sudan have a long-standing history of bilateral relations.

  Over the years, the UAE has been a strong supporter of Sudan's development and prosperity. As Sudan faces challenging times, it is important that this support continues. The UAE has been a key player in Sudan's development, particularly in the areas of infrastructure, health, education, and renewable energy. In recent years, the UAE has also provided aid and support to Sudan in the aftermath of natural disasters, such as floods and droughts. This assistance has played a crucial role in mitigating the effects of these disasters on the people of Sudan. The current situation in Sudan is particularly challenging, with political instability and economic difficulties plaguing the country. The people of Sudan are facing a myriad of issues, including inflation, unemployment, and a lack of basic necessities like food and clean water. In addition, the ongoing conflict in the region has only exacerbated the situation, causing immense suffering to the people of Sudan. In light of these