Breaking News

Canon launches versatile EOS R6 Mark III and innovative RF 45mm F1.2 STM lens uHoo Launches Caeli – The Smart Air Quality Monitor DJI Introduces Osmo Mobile 8 with Intelligent Subject Tracking Samsung Launches New P9 Express microSD Express Cards Cloud Streaming officially arrives on PlayStation Portal

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Browsers' Password Managers Are Used by Advertisers' Scripts For Tracking Sites

Browsers' Password Managers Are Used by Advertisers' Scripts For Tracking Sites

Enterprise & IT Dec 31,2017 0

Web browsers' built-in password managers is abused by third-party scripts for tracking on more than a thousand sites, according to researchers.

Nearly every web browser now comes with built-in login managers (also called password managers). According to a new research from Princeton's Center for Information Technology Policy, third-party scripts exploit thsese password managers to retrieve and exfiltrate user identifiers without user awareness.

The underlying vulnerability of login managers to credential theft has been known for years.

The researchers haven't found password theft on the 50,000 sites that they analyzed, but they found tracking scripts embedded by the first party abusing the same technique to extract emails addresses for building tracking identifiers.

Here is how it works: First, a user fills out a login form on the page and asks the browser to save the login. The tracking script is not present on the login page. Then, the user visits another page on the same website which includes the third-party tracking script. The tracking script inserts an invisible login form, which is automatically filled in by the browser's login manager. The third-party script retrieves the user's email address by reading the populated form and sends the email hashes to third-party servers.

The researchers examined two different scripts - AdThink and OnAudience - both of are designed to get identifiable information out of browser-based password managers. The scripts work by injecting invisible login forms in the background of the webpage and scooping up whatever the browsers autofill into the available slots. That information can then be used as a persistent ID to track users from page to page, a potentially valuable tool in targeting advertising.

According to the researchers, there's no technical measure to stop scripts from collecting passwords. The only fix would be to change how password managers work, requiring more explicit approval before submitting information.

Tags:
Previous Post
Qualcomm Had the Highest Smartphone SoC Market Share in Q3 2017
Next Post
Mobile Devices Use More GPUs Than All Other Platforms Combined

Related Posts

Latest News

Canon launches versatile EOS R6 Mark III and innovative RF 45mm F1.2 STM lens
Cameras

Canon launches versatile EOS R6 Mark III and innovative RF 45mm F1.2 STM lens

uHoo Launches Caeli – The Smart Air Quality Monitor
Consumer Electronics

uHoo Launches Caeli – The Smart Air Quality Monitor

DJI Introduces Osmo Mobile 8 with Intelligent Subject Tracking
Drones

DJI Introduces Osmo Mobile 8 with Intelligent Subject Tracking

Samsung Launches New P9 Express microSD Express Cards
Cameras

Samsung Launches New P9 Express microSD Express Cards

Cloud Streaming officially arrives on PlayStation Portal
Gaming

Cloud Streaming officially arrives on PlayStation Portal

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed