Skip to main content

Flaws discovered in Safari’s Intelligent Tracking Prevention let users be tracked

Google researchers discovered multiple security flaws in Apple's Safari web browser that let users' browsing habits be tracked despite Apple's Intelligent Tracking Prevention feature.

Google plans to publish details on the security flaws in the near future and a preview of Google's discovery was seen by Financial Times, with the publication sharing information on the vulnerabilities this morning.

The security flaws were first found by Google in the summer of 2019, and were disclosed to Apple in August. There were five types of potential attacks that could allow third parties to learn "sensitive private information about the user's browsing habits."

Apple’s privacy focus branches off in a variety of ways, including reducing the way websites can track individuals.

That’s due in part to its Intelligent Tracking Prevention feature baked into its web browser, Safari. However, it’s been discovered by Google researchers that a flaw in ITP made it possible for users’ browsing habits to still be tracked, even with the feature in place.

Google researchers say that Safari left personal data exposed because of the Intelligent Tracking Prevention List "implicitly stores information about the websites visited by the user." Malicious entities could use these flaws to create a "persistent fingerprint" that would follow a user around the web or see what individual users were searching for on search engine pages.

Intelligent Tracking Prevention, which Apple began implementing in 2017, is a privacy-focused feature meant to make it harder for sites to track users across the web, preventing browsing profiles and histories from being created.

A preview of the discovery was seen by Financial Times today, and the researchers say they will be publishing their discovery in the near future. According to the report, Google researchers first discovered the flaws back in the summer of 2019 and officially disclosed to Apple in August. The flaws could allow third-parties access to “sensitive private information about the user’s browsing habits”.
There were five potential threats discovered by the researchers.
The researchers say these flaws are possible in part, because Safari’s Intelligent Tracking Prevention feature “implicitly stores information about the websites visited by the user”. Attackers could use this information to create a “persistent fingerprint” that basically follows the user around as they browse the internet.
It’s worth noting here that these flaws have apparently been patched by Apple already. The company issued a software update in December of 2019 for Safari, so it looks like the issues have already been fixed.
Safari’s Intelligent Tracking Prevention started being implemented by Apple in 2017. It’s designed to limit the ability of websites to track a user as they browse the web and use search engines.
Lukasz Olejnik, a security researcher who saw Google's paper, said that if exploited, the vulnerabilities "would allow unsanctioned and uncontrollable user tracking." Olejnik said that such privacy vulnerabilities are rare, and "issues in mechanisms designed to improve privacy are unexpected and highly counter-intuitive."

Apple appears to have addressed these Safari security flaws in a December update, based on a release update that thanked Google for its "responsible disclosure practice," though full security credit has not yet been provided by Apple so there's a chance that there's still some behind-the-scenes fixing to be done.

Comments

Popular posts from this blog

“Stepping Forward for the Betterment of the Country”

  Here’s something I want to share today. It’s about how there are chances of it turning into another sort of geo-monetary worry for states who dread that their vital financial influence will be subverted. Additionally, Suez Canal can be utilized by non-state entertainers as a monetary instrument to accomplish vital destinations. Notwithstanding their expressed places of keeping the channel open to worldwide exchange, significant forces have regularly played with making elective courses, though with restricted achievement. Notwithstanding, seen from the carefully adjusted international and geo-monetary stances in the Middle East, the Suez Canal could be an indicator for the district's financial fortunes.   Moreverc to guarantee they procure profits, all partners should keep on putting resources into the Suez Canal's security and life span to support financial advancement. In the most dire outcome imaginable, however, the waterway could in a real sense cripple worldwide excha...

Jenna Ortega talks about Wednesday Season 2

  Jenna Ortega, a successful American actress who rose to fame with the Wednesday series, has opened up about season 2 of Wednesday. Jenna Ortega, the show's leading lady, extensively spoke about Wednesday season 2. She talked about major updates on the genre of Season 2. She confirmed that season 2 contains horror elements. In an interview with Variety, the Wednesday actress stated, “We have decided that we want to lean into the horror aspect of the show a little bit more. Because it is so light-hearted, and a show like this with vampires and werewolves and superpowers, you don’t want to take yourself too seriously.” She said that season 2 ditched the idea of a love interest. In March this year, she confirmed the second season of Wednesday. She said that the series would focus more on horror and less on romance. In a Saturday Night Live episode, she said that the character of Wednesday Addams would be an individual going forward in the second season of the series. The ac...

“Iraq is Utilizing What They Have Right Now”

Here’s something good that I want to share with what I read today. It’s about  how Iraq utilizes a decentralized arrangement of administration, the Gulf countries and their organizations can investigate such financial possibilities with different individual Iraqi governorates, directed by the national government. This can likewise make a sound rivalry among Iraqi governorates to offer better costs and more good arrangements with Gulf organizations, as the two sides advantage. For me, Iraq needs huge monetary and monetary support. Monetary guide bundles can just reduce some tension on the present moment. Aside from Iran, there is insignificant territorial interest in Iraq's private area. Tehran's interest in Iraq has not given remarkable monetary advantages, for the most part because of authorizations. Inlet countries ought to investigate Iraq as a feasible competitor for their business ventures, and they can even use Jordan as a middle person to shape a solid financial ternio...