Web Hack List

Later archive addition

Browser history re:visited

Four new history sniffing attacks, two on visited links and two on caches, abuse modern browser features such as the CSS Paint API and the JavaScript bytecode cache, which handle cross-origin URL data without accounting for privacy. They let a page learn which sites a visitor has been to, one of them at roughly 3,000 URLs per second, against every browser tested but Tor Browser.

Record

Researcher
Michael Smith, Craig Disselkoen, Shravan Narayan, Fraser Brown and Deian Stefan

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Michael Smith, Craig Disselkoen, Shravan Narayan, Fraser Brown and Deian Stefan, first published at the original source. Preserved copies are kept so the citation survives its host.