3 ms·
This approach is rather interesting. But I'm wondering whether a similar attack could be made by placing links on a web page and using the CSS :visited selector
by SanPilot 11y ago
This approach is rather interesting.
But I'm wondering whether a similar attack could be made by placing links on a web page and using the CSS :visited selector to change the style of visited web pages. Couldn't you then check which links have that formatting and which don't via JS?
- mccr8 11y agoYou used to be able to do that, but it was fixed in 2010: https://blog.mozilla.org/security/2010/03/31/plugging-the-css-history-leak/ https://blog.mozilla.org/security/2010/03/31/plugging-the-cs...
- seanwilson 11y agoYes, this attack was demoed to work several years ago but has been patched as far as I know: https://developer.mozilla.org/en-US/docs/Web/CSS/Privacy_and_the_%3Avisited_selector https://developer.mozilla.org/en-US/docs/Web/CSS/Privacy_and... "The first change is that Gecko will lie to web applications under certain circumstances. In particular, getComputedStyle() and similar functions such as element.querySelector() always return values indicating that a user has never visited any of the links on a page."
- bzbarsky 11y agoThis used to be possible, but browsers put into place various mitigations: restricting which properties a :visited selector can affect, always computing both the visited and non-visited style to avoid timing attacks, etc. http://dbaron.org/mozilla/visited-privacy http://dbaron.org/mozilla/visited-privacy has a writeup describing the issues and the solutions that were adopted.