iTnews
  • Home
  • News
  • Technology
  • Security

Browser history hack compromises user privacy

By Tom Sanders
Oct 9 2006 10:03AM
Follow google news

Proof-of-concept code demonstrates search history 'theft'.

Browser history hack compromises user privacy
Security researchers at Spi Dynamics have demonstrated a technique that exposes the search queries and web pages that a user has visited. 

Websites could use the technique to check whether a user has researched its products through search engines.

An insurance provider, for instance, could verify whether a client applying for life insurance has ordered cigarettes online. It could also allow an online retailer to check whether users have been shopping with competing stores.

"You can basically determine how loyal a customer I am and offer me a price break," Billy Hoffman, a lead security researcher with Spi Dynamics, told vnunet.com. 

Hoffman likened the technique to the publication by AOL of 20 million search queries from 650,000 of its users last August. 

The 439MB of data was released as part of a research project and AOL was soon forced to delete the information following privacy concerns.

Although the data could not directly be linked to individual users, The New York Times was able to trace one set of search queries to 62 year-old Thelma Arnold from Lilburn, Georgia. 

"The release of the AOL data a few months ago showed that you can learn so much about a person from their search engine queries. Imagine that scary lack of privacy, but for everybody on the Internet," said Hoffman.

The URL for each online search query is formed in a standard way that discloses the keywords that a user has entered.

Web browsers store these URLs in a history file which, for example, allows the colour for a previously visited link to look different from a fresh one.

Spi Dynamic's technique checks a series of predefined URLs against the URLs in a user's search history through a JavaScript application that is embedded on a webpage.

The code is executed on the user's system without any noticeable performance interruption.

Most browsers are set to save the history for several days. Firefox is configured to save the history for nine days, while Internet Explorer holds onto the URLs for 20 days.

Hoffman said that he is not aware of anyone using the technique to track online user behaviour. But he added that if marketers had learnt of the technique, they probably would not disclose their use of it.

The company is not certain about the legality of the technique. Although it has obvious privacy implications, the technology is no different from the ways that websites today check for a system's screen resolution and installed plug-ins.

A proof-of-concept application is available on the Spi Dynamics website which allows users to verify Google, Yahoo and Icerocket searches.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
browsercompromiseshackhistoryprivacysecurityuser

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.