27 ms·
Css-only-chat: A truly monstrous async web chat using no JS on the front end
- LeoPanthera 7y agoThe most interesting part of this at least for me is what inspired it: A way to track cursor location without using javascript, that even works in Tor Browser: https://twitter.com/davywtf/status/1124130932573839360 https://twitter.com/davywtf/status/1124130932573839360 tl;dr css hover selectors that change the background image don't actually cause the browser to GET the specified background image until you hover over it, thus creating a way to send data from a web page with no javascript.
- amelius 7y agoThe fix is to make the Tor browser preload all images. Unfortunately, as always, using Tor will make things slower.
- quickthrower2 7y agoOr no network communication unless during initial page load. (I assume you'd have JS disabled anyway if you want this level of privacy)
- ehsankia 7y agoIf you're disabling JS, you should probably be able to disable onhover too.
- mcv 7y agoPreloading images so they're ready to show when needed, does not sound like unreasonable behaviour, especially on a connection with high bandwidth but low latency. It will make this kind of example really slow, but if the intention is to break this kind of spying, then that's okay.
- dredmorbius 7y agoIndeed. Demoed in the Tor browser as a mouse tracker.
- WalterGR 7y agoHow does the Tor browser not route all http(s) traffic through Tor?
- arendtio 7y agoThis is pure evil. Maybe we should just go back to manually typing into SSL connections...
- justinmchase 7y agoAt least back to Gopher.
- ddalex 7y agoGopher had the right idea. Menus only. What executable code?
- ars 7y agoI've done this exact same thing to track when people printed vouchers we offered. Have a background image only on the print css.
- wybiral 7y agoYeah, I'm playing around with the idea of using the background image trick to profile the integrity hash speed of the visiting browser. That little background image feature in CSS has given up quite a bit of data in similar situations (people used to use it to check browsing history of :visited links before browser started blocking that).
- Domenic_S 7y agoYou're profiling the what now?
- wybiral 7y ago<link> tags to include CSS and JavaScript on a page can have an integrity property, which is a SHA hash of the resource they link to. It's intended to ensure that a CDN doesn't change the content they're serving to your users. But it turns out you can approximate the speed a visiting browser computes those hashes to fingerprint browsers just by including some CSS on a page.
- lucb1e 7y agoBut that hash is a regular, fast hash that takes like 1µs to compute right? Doesn't that get lost in network jitter? Wouldn't averaging the time it takes to run for(i=0;i<Math.pow(2,18);i++); over 10 runs be much more accurate? Or is this meant to spite the 0.01% of visitors that really try not to be tracked and have turned off javascript?
- wybiral 7y ago> But that hash is a regular, fast hash that takes like 1µs to compute right? They use SHA512 which is fast, but noticeable for large enough files. > Or is this meant to spite the 0.01% of visitors that really try not to be tracked and have turned off javascript? Yes, the point is that it works with blockers.
- Raphmedia 7y agoWe used to do that to track emails. Gmail's fix was to cache the emails' images on their own server, so it's only hit once. They also don't listen to selector:hover{} so you can't have hover effects.
- JoshTriplett 7y ago> Gmail's fix was to cache the emails' images on their own server, so it's only hit once. That doesn't solve the problem; email trackers could just use a unique URL per email.
- justinmchase 7y agoAnd they do that exactly. The fix is to disable images by default but every user has to manually do this.
- nerdponx 7y agoOr use an email client that disables images by default.
- dexterdog 7y agoI thought images were off by default
- Moru 7y agoNot in the Web client I'm afraid
- afiori 7y agoBut it does not matter, if google download all the images when for all your emails then showing them to you is just a fetch from their own servers. Similarly to the ad-blocking extension that clicked all ads on the page (in isolation) so that tracking would be useless.
- grifball 7y ago
- altfredd 7y ago> tl;dr css hover selectors that change the background image don't actually cause the browser to GET the specified background image until you hover over it This specific page uses :active, not :hover, so it is really no different from a web form, that performs web request each time you press a submit button. It just does not reload a page.
- rasz 7y agoSounds like privacy oriented browsers need a patch :hover Selector to always prefetch background-image
- nerdponx 7y agoOr disable image loading by default like in email clients.
- oftenwrong 7y agoThis is just a different spin on the (now fixed in most browsers?) trick of using ':visited' with a background image to uncover which sites the user has visited. It's things like this that drove me to start browsing the web with CSS disabled by default. It's yet another vector for tracking.
- pmoriarty 7y agoThis makes me wonder: is CSS turing complete? Are browsers that allow CSS as vulnerable to being exploited as those that allow Javascript?
- chx 7y agohttps://stackoverflow.com/q/2497146/308851 https://stackoverflow.com/q/2497146/308851
- _bxg1 7y agoI believe I saw something that said CSS is Turing Complete* * Only with user interaction to step things along, similar to powerpoint: https://www.youtube.com/watch?v=uNjxe8ShM-8 https://www.youtube.com/watch?v=uNjxe8ShM-8
- CriticalCathed 7y agoIf hovering counts as user interaction...
- _bxg1 7y agoIt does; it triggers an event just like clicking (or in the case of CSS, a state change).
- edjroot 7y agoThere was a discussion about this on the front page of HN literally a few hours ago: https://news.ycombinator.com/item?id=19847939 https://news.ycombinator.com/item?id=19847939
- aasasd 7y agoExploits rely on interactions between parts of a system, not on crunching numbers. A pure Turing machine is perfectly un-exploitable since <s>its only i/o is supposed to be to the keyboard and the screen</s> (edit: it has no i/o whatsoever). CSS would have more holes than JS if it offered more APIs (which it might do unknowingly by mistakes in programming).
- _bxg1 7y agoReminds me of this: https://github.com/videlalvaro/gifsockets https://github.com/videlalvaro/gifsockets
- leowoo91 7y agoInteresting. If I understand correctly, this one doesn't receive data from the client. Maybe it can be combined with the css idea?
- zghst 7y agoI am consistently surprised at the mass creativity with CSS over the years, never ever disappointed!
- woah 7y agoYou could do this with no CSS, only html.
- chapium 7y agoCreate a demo then.
- Romanulus 7y agoNo, you.
- miguelmota 7y agoSkeptical because there needs to be some dynamic component to it which is what the CSS pseudo-selectors are achieving. Would love to see a working demo.
- driverdan 7y agoYou could do it with iframed buttons. Clicking a letter button posts to the server, an image is sent back in the forever loading page.
- lawl 7y agoYou don't need letter buttons. You can have a regular text box in an iframe and submit the form with the text. I actually remember websites doing exactly that years ago. Some would display the chat like here, by never closing the connection, as described in the repo. And another trick was to just send a refresh header (or use a meta tag) to automatically reload the iframe displaying the chat every $x seconds. The latter one was iirc more prominent because you could do it on any web host with PHP and MySQL as it doesn't require any long living processes.
- nwellnhof 7y agoThat's exactly how I implemented a web chat around 2002. IIRC, Internet Explorer didn't update the iframe with the chat messages reliably, so I had to fall back to reloading. The whole thing was rather inefficient, simply polling a database for new messages every second, but it worked fine for about 10-20 users.
- leshokunin 7y agoDefinitely the most creative code I'll be seeing this week! I realize this is really bad practice and likely to be fixed since it can be used for tracking users, but: are there any advantages to using CSS over Javascript, in theory?
- mirekrusin 7y agoIt doesn't look like it's going to be easily fixable.
- altfredd 7y agoWhat exactly do you want to block here? The user clicked a form control, the form control sent a request to server. It is no different from clicking a link. You know, that HTTP allows websites to "track" you each time you visit them, right? The horror!
- edjroot 7y agoJust a few hours earlier, this discussion on Turing-complete stuff hit HN's front page: https://news.ycombinator.com/item?id=19847939 https://news.ycombinator.com/item?id=19847939 Now I don't know if there's any causal relationship between the two (or the three) or if it's just a big coincidence, since it says on the README that the inspiration for it came from a Tweet posted a few days ago.
- st0p 7y agoI've gotta admit: hats off for this clever hack.
- thesandlord 7y agoReminds me of this: https://harmless.herokuapp.com/ https://harmless.herokuapp.com/ HN Discussion: https://news.ycombinator.com/item?id=16319248 https://news.ycombinator.com/item?id=16319248 Basically the same idea, but it does refresh when you submit. The CSS buttons are quite a clever workaround to not refresh the page.
- busymom0 7y agoThis is what it reminded me of too! I wonder if this would break too as that one does of you press escape key.
- RodgerTheGreat 7y agoSeems like a compelling argument for not lazily loading urls referenced in CSS rules. If the browser progressively loaded everything in the stylesheet without user interaction it would presumably consume more bandwidth in many situations but it would also blast this server with a continuous stream of the entire alphabet.
- QuinnWilton 7y agoYou could write a UI framework using these ideas to provide rich client-sided functionality to Tor hidden services, where users typically disable JavaScript.
- t0mbstone 7y agoNow this is a proper hacker project perfect for being featured on this site
- laszlokorte 7y agoIt seems all those css tracking tricks (a:visted, [value=...], now :hover) depend on external resouces (background-images) being loaded lazily only once the selector is matched. Wouldn't a easy solution be for browsers to always download all url('...') references found the the stylesheets even if the selector is never matched?
- calcifer 7y agoThat could potentially be bandwith heavy, but even then it's not a solution since you could just add more CSS at runtime as the Github repo shows.
- mcv 7y agoIt would only be bandwidth heavy for sites that abuse this feature, so that's actually fine by me. And when CSS gets added at runtime, you can prefetch that too.
- altfredd 7y agoYou seem to be confused about meaning of "CSS tracking". Detecting that user clicks on the link, that you have shown him, is harmless — as demonstrated by Google, a website can always track it's own outgoing requests by replacing all it's outgoing links with redirects. This is inherent part of hypertext. The infamous "a:visited" tracking didn't simply track your visits from Google — it tracked all your visits across entire Internet. Browser vendors are bunch of lazy hacks, who can't even implement per-site link history (just like they failed to implement per-site cookies). All "a:visited" states are source from single SQLite database, that stores your full web history. THAT is the "CSS Tracking", because it can tell a page about visits from completely different domains. Instead of separating your web history per-domain those <censored> have crippled :visited selector in several undocumented ways.
- icebraining 7y ago> Browser vendors are bunch of lazy hacks, who can't even implement per-site link history But who asked them to? As far as I know, the spec says nothing about per-site histories, and I find it much more useful to know if I already visited a site, regardless of the origin - for example, if I'm researching a topic, two or more sites might link to the same place, and I don't want to open it multiple times. Plus, the idea that one can look at a modern browser, which are some of the most complex software packages being developed, and think "clearly these people don't know how to add an 'origin' column to a SQLite database", well, it boggles the mind.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- fishtoaster 7y agoHaha, I’m glad to see people enjoy this (author here)! If you like this sort of thing, some other terrible proof-of-concepts I’ve done: A ruby dsl that’s indistinguishable from JavaScript. http://kevinkuchta.com/_site/2017/07/disguising-ruby-as-javascript/ http://kevinkuchta.com/_site/2017/07/disguising-ruby-as-java... ^ and in talk form: http://confreaks.tv/videos/rubyconf2018-ruby-is-the-best-javascript http://confreaks.tv/videos/rubyconf2018-ruby-is-the-best-jav... A url-shortener using AWS lambda - JUST lambda. No data store. http://kevinkuchta.com/_site/2018/03/lambda-only-url-shortener/ http://kevinkuchta.com/_site/2018/03/lambda-only-url-shorten...
- dorgo 7y ago>A url-shortener using AWS lambda - JUST lambda I expected a lambda, which compresses/decompresses the url. This would also work without storing anything.
- brianpgordon 7y agoI was guessing something diabolical like https://code.kryo.se/pingfs/ https://code.kryo.se/pingfs/
- Pmop 7y agoI love hacky things like this one.
- brlewis 7y agoEnjoyed the hack and the FAQ.
- IggleSniggle 7y agoReading your comment is the first time I’ve ever pronounced FAQ in such a way as to rhyme with “hack” instead of as “fax/facts” or “Ef Ay Qu” or “teh Questions.” I am happy to add “the hack FAQ” to my snack pack.
- CM30 7y agoProbably a silly question, but is there a working demo for this? This is one of those things you kinda have to see in action, and there doesn't seem to be a link to anything like that in the readme.
- sara7262 7y agoWho is Satan and why there is evil Best video about this with proofs https://youtu.be/AWNM1-xYI5E https://youtu.be/AWNM1-xYI5E Funny monkey using phone in video Don't think just you can use phone See how he is searching and watching own monkey videos on phone http://bit.ly/2DS4p2R http://bit.ly/2DS4p2R See what happened when a lion was trying to kill man http://bit.ly/2H2zsKc http://bit.ly/2H2zsKc
- westmeal 7y agoI don't know why you did what you did but I am glad you did.
- shoes_for_thee 7y ago> Should I use this in real life? Dear god yes.
- petercooper 7y ago"Css-only-chat" CSS is always CSS. It's CSS on the repo too, but got edited back to "Css" here on the HN title for some reason.
- keyle 7y agoThis is what hacking is all about!
- Endy 7y agoYou know, projects like this make me want to start blocking *.css files in my HOSTS file and browser setups.
- kijin 7y agoIf you could block *.css files using a HOSTS file, that would be a hack worthy of the front page in its own right.
- flying_sheep 7y agoCombining with Turing complete CSS, it can reach the sky higher than our imagination https://rawgit.com/elitheeli/stupid-machines/master/rule110-old/rule110-full.html https://rawgit.com/elitheeli/stupid-machines/master/rule110-...
- mishingo 7y agoYou lost me at ruby
- HiddenChat 7y agoI released a chat using this kind of backend ~1.5 month ago on Tor. It has a few extra features feel free to check it out: http://t4kvzrhhwxc4dumfpvnffovgrp6idjj6wlvuptk3sfnlefnupdpazfqd.onion/ http://t4kvzrhhwxc4dumfpvnffovgrp6idjj6wlvuptk3sfnlefnupdpaz...
- caprese 7y agoWhen the A/B test tells you that you should but you shouldn't
- sevsco 7y agoRather than the forever loading site, couldn't you also include in the html doc something like this to have it simply refresh every few seconds? <meta http-equiv="refresh" content="10; URL='http://new-website.com'" http://new-website.com'" /> So the page would simply refresh itself every 10 seconds.
- gok2 7y agolink?
- chethiya44 7y agogf