Researchers at University of California, San Diego have discovered that 485 of the 50,000 most popular Websites in the world are exploiting a flaw that lets them read your browser’s Web history. The offending sites include YouPorn.com, Gamesfreak.com, Newsmax.com, and TwinCities.com, according to the researchers.
“Many of these websites seem to try to obfuscate what they are doing,” UC San Diego researchers wrote in the paper, “An Empirical Study of Privacy-Violating Information Flows in JavaScript Web Applications.”
“We found that several popular sites – including an Alexa global top-100 site – make use of history sniffing to exfiltrate information about users’ browsing history, and, in some cases, do so in an obfuscated manner to avoid easy detection,” the report states. “While researchers have known about the possibility of such attacks, hitherto it was not known how prevalent they are in real, popular websites.”
Called history sniffing, the combination of JavaScript and Cascading Style Sheet (CSS) properties enables the sites to figure out where you’ve been on the Web. The researchers’ findings are published in a new study entitled “An Empirical Study of Privacy-Violating Information Flows in JavaScript Web Applications.”
The study also detected code on sites maintained by Microsoft, YouTube, Yahoo and About.com that perform what the scientists called “behavioral sniffing.” They employ JavaScript that covertly tracks mouse movements on a page to detect what a user does after visiting it.
Chrome and Safari, researchers said, are not vulnerable to history hijacking and that the most recent version of Firefox has closed loopholes. Internet Explorer users can turn on “private browsing” to stop the flaw from divulging histories.