15 ms·
Cname cloaking, a disguise of third-party trackers
- stefan_ 7y agoSo block content, as always? That's not possible for NextDNS, which I guess is their concern, but then DNS blocking was always going to be a very very blunt instrument.
- bufferout 7y ago"NextDNS is proud to announce that all your blocklists are now applied to each intermediate CNAMEs in addition to the queried domain name.": https://medium.com/nextdns/nextdns-added-cname-uncloaking-support-becomes-the-first-cross-platform-solution-to-the-problem-e3f437f84342 https://medium.com/nextdns/nextdns-added-cname-uncloaking-su...
- 9dl 7y ago>Security implications of CNAME Cloaking >While this is considered bad practice for a website to set cookies as accessible to all subdomains (i.e., *.website.com), many do this. >In that case, those cookies are automatically sent to the cloaked third-party tracker.
- stefan_ 7y agoSo website.com decided to sellout and now the cookies you send to website.com that betrayed your trust are also sent to it's chosen third-party tracker? That is a distinction without difference. The security implication is storing any data with website.com!
- dgoldstein0 7y agoYes, but www.website.com cookies won't be sent. But you'll have to crack open devtools to figure out which one each website is doing.
- stefan_ 7y agoYes, the cookies of the website that installed a third-party tracker to spy on you will be sent to the website and the tracker. They could always do that.
- iforgotpassword 7y agoAt home I'm using it in addition to ad blocking in the browser, for apps and other things that might slip through. Currently it's just dnsmasq with a huge blacklist, and I guess it doesn't support checking the whole CNAME chain against that list, which would be really cool.
- muppetman 7y agoIt doesn't need to have every cname in it. The cname resolves to the actual "bad" domain, which should be in your list already. That's why DNS blocking can still combat this method easily, while it's much harder at the browser level. uBlock Origin for Firefox beta has a "run all non-local domains back through and check for cname redirection" feature, which can also block the cname trick, but it will increase DNS latency because it has to check each external domain again for the "true" domain.
- iforgotpassword 7y ago> It doesn't need to have every cname in it. The cname resolves to the actual "bad" domain, which should be in your list already. That doesn't help if dnsmasq only checks the incoming request against the list, and not the whole cname chain of the result.
- gorhill 7y ago> [uBO] will increase DNS latency because it has to check each external domain again for the "true" domain. The browser API used by uBO returns the last CNAME in the chain. I consider the DNS lookup itself to be an non-issue overhead-wise in uBO because: - The browser would need to do it anyways - DNS lookup results are cached at both the browser and uBO level
- sneak 7y agothe NextDNS people are really smart; I just submitted a request for the ability to blacklist replies (for any hostname) that match a given IP/mask or originating AS number. This would solve the problem, especially if it is supported in blocking lists.
- matheusmoreira 7y agouBlock Origin issues: https://github.com/uBlockOrigin/uBlock-issues/issues/780 https://github.com/uBlockOrigin/uBlock-issues/issues/780 https://github.com/NanoAdblocker/NanoCore/issues/296 https://github.com/NanoAdblocker/NanoCore/issues/296
- jwilk 7y agoDiscussed on HN 3 days ago: https://news.ycombinator.com/item?id=21582698 https://news.ycombinator.com/item?id=21582698
- 9dl 7y agoSooooo I suppose we are going back to the roots White lists in hosts file with ips and good sites
- fwxwi 7y agoYou can't block an IP address with a hosts file; you can't even use wildcards in them. You will need a firewall rule.
- 9dl 7y ago>You will need a firewall rule. Yes Or DNS
- progval 7y agoYou can also use uMatrix or NoScript to disable all JS/XHR (or even CSS and images) from third-party domains by default; and whitelist those you need.
- 9dl 7y agoHmm How can I block cookies with uMatrix for sub domains like *.domain.com for any site? PS: I assume that just temporary solution. Because nextsstep is just hosting some js from "analytics" on main domain and/or solutions like cloudflare for e-commerce / google news / etc. And for filtering that bs we need deep filtering and api inside JS VM
- zelly 7y agoI knew something like this would come up. I always wondered why ad/tracking companies never proxied through the first-party domain (or in a more extreme case, the first-party server itself) to skirt adblock. Suppose you load example.com/article. Ad Agency serves ad/tracking assets from example.com/article/Zqj7MOm.js. When you reload, it serves from example.com/article/llc9h76.js. How do you block it? You can't. Getting this to work in a pluggable fashion is an implementation detail (maybe some on-the-fly statistical generation of URLs + passing nonces to and from Ad Agency as a mitigation for spoofing by example.com). Another way to implement it is a custom URL router that dynamically reverse proxies to Ad Agency on the generated ad trojan horse URL. The only reason this hasn't happened yet is because still very few people use adblock, esp. on mobile. P.S. please don't do this.
- hunter2_ 7y agoI've been wondering the exact same thing for a long time. However, browser extensions could probably still use good enough heuristics. It's the pihole category of solutions that would be defeated.
- brian-armstrong 7y agoAs I understand it, ad companies and the people who sell their websites to ad companies have some base level of distrust of one another, which has kept them from integrating like this. Ad companies want to serve the code to be sure that no click fraud is occurring, and people who run websites don't want to completely hand over their domain. But it's easy to see them forging this alliance if ad delivery depended on it.
- zelly 7y agoWhat if they didn't need to trust the website operators because they only pay them if users click? When the user clicks, it goes through the ad company's domain with the Referrer who would be paid for it.
- onion2k 7y agoMost ad fraud is the referrer owner faking clicks on ads on their own site. To trust a click you need to trust that the ad was displayed to a legitimate user. That's the hard bit. Ad companies could move to only paying when ads result in a sale, but that only works if there's a sale that can be tracked. If I click a BMW ad and then buy one in the showroom that's really hard to track.
- going_to_800 7y agoI worked in ad space 7 years ago. Companies that provide content need to get paid for the content one way or another, either paying a fee or ads, nobody can argue with this. There needs to be an organization that imposes ad guidelines(like only specific formats, not being intrusive, etc) for both websites and ad companies. They should verify the ads/websites based on user reports and if they find something, to kick the company out. All companies that follow those guidelines should be whitelisted by ad blockers, probably something implemented at browser level. Otherwise is just a useless chase.
- tsimionescu 7y agoThere are other alternatives. Alternative monetization schemes, such as those offered by Patreon or Twitch or Kickstarter can be found. Also, ads can be placed teh same way they were in newspapers - the ad company would submit ads to the content creator, who would manually chose which ads to include, and where.
- going_to_800 7y agoIt's not that easy as you may think. Also, small companies won't benefit from that, nobody will submit an ad to websites with lower traffic. Besides this, there's the issue with the tracking server and so on.
- tsimionescu 7y agoI didn't say it was easy. But perhaps it is important enough that it should even be regulated.
- ignoramous 7y agohttps://eyeo.com https://eyeo.com, home to the world's most installed ad-blocker, AdBlock+, has an acceptable ads policy already in place; whilst Google is trying to tackle the data-collection problem via the controversial privacy-sandbox proposal [0]. Safari [1] and Firefox [2] seem to have the right idea abt it all, whilst Brave is trying a radically new approach [3]. As for the online services needing ads to keep lights on: 1. The pervasive dragnet that the online ad-industry has birthed is a massive reason behind content-blocking. 2. Ads are freq used to spread source of malware, scareware, spyware, ransomware, fake-news among other totally unreasonable things. 3. The end-users should be free to chose what they want to view and what they don't. The service providers are free to refuse service. 4. The tracking that goes on is so covert that it seems to me that it is borderline unethical [4]. 5. The online ads business is a scam [5]? --- [0] https://news.ycombinator.com/item?id=20767891 https://news.ycombinator.com/item?id=20767891 [1] https://news.ycombinator.com/item?id=20700914 https://news.ycombinator.com/item?id=20700914 [2] https://news.ycombinator.com/item?id=21497488 https://news.ycombinator.com/item?id=21497488 [3] https://news.ycombinator.com/item?id=21525592 https://news.ycombinator.com/item?id=21525592 [4] https://news.ycombinator.com/item?id=20336762 https://news.ycombinator.com/item?id=20336762 [5] https://news.ycombinator.com/item?id=13992576 https://news.ycombinator.com/item?id=13992576
- wnevets 7y agoAt some point why shouldn't the (US) government step in?
- hombre_fatal 7y agoThen we'll just get more pointless legislation that led to the cookie banner and ads/trackers will be trivially cloaked/proxied to the point where any publisher has full deniability. We'll look back at the good old days when ads were mostly just banner ads. Idea: Start paying for content and support the sites that offer this option. The entire concept of adblocking lives on borrowed time: hoping your content creators are making enough money off the suckers that don't use adblockers. It's hard for me to envision legislation that wouldn't just be a clusterfuck as the government encroaches further onto our internet.
- gingerlime 7y agoAdguard is also starting to tackle this[0]. Found on [1] (not affiliated with any of those in any way, I'm just a user of Adguard home) [0] https://adguard.com/en/blog/disguised-trackers.html https://adguard.com/en/blog/disguised-trackers.html [1] https://www.reddit.com/r/pfBlockerNG/comments/e0bsto/defence_against_cname_cloaking_pfblockerng_or/ https://www.reddit.com/r/pfBlockerNG/comments/e0bsto/defence...
- TheKIngofBelAir 7y agoAdd this[1] host list for first-party trackers for those who don't want to use these dns solutions or/and they use a Chromium based browser. [1] https://git.frogeye.fr/geoffrey/eulaurarien https://git.frogeye.fr/geoffrey/eulaurarien With third-party trackers: https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt First-party trackers only: https://hostfiles.frogeye.fr/firstparty-only-trackers-hosts.txt https://hostfiles.frogeye.fr/firstparty-only-trackers-hosts....
- cheald 7y agoUse a Pihole + your adblocker of choice - defense in depth. It's easy to set up, brainless to keep updated, and helps to protect all devices on your network, not just the things that can run uBlock. I've got mine running in a Docker container, which upstreams to a stubby container, which gets DNS-over-TLS, so I get adblocking and DNS query encryption out to Cloudflare for the whole network, and it's really not all that hard to set up. (Edit: Here's the bash script I used. docker-compose would probably be better, but whatever. https://gist.github.com/cheald/23da384908404b0757eadda74124a602 https://gist.github.com/cheald/23da384908404b0757eadda74124a...) If you're unwilling to do that, just set your DNS servers to the Adguard servers (https://adguard.com/en/adguard-dns/overview.html https://adguard.com/en/adguard-dns/overview.html) and you get most of the same benefit, though obviously without the control that the Pihole offers you. On Android devices, you can go to Settings - > Wifi & Internet - > Private DNS and set "Private DNS provider hostname" to dns.adguard.com (or your own exposed Pihole server, if you're so inclined) and get the same benefit when you're on LTE.
- syshum 7y agoThat will only work for so long, as more and more browsers are forcing DoH for "privacy" on users, making them bypass traditional DNS in-favor of DNS over HTTPS to a provider selected by the Browser removing user control Mozilla for example is going to force everyone to use CloudFlare as a Resolver
- yegle 7y agoThen run your own DoH server, the same way you run your own pihole. Shameless plug: https://GitHub.com/yegle/your-dns https://GitHub.com/yegle/your-dns
- snailmailman 7y agoYou can change your DoH resolver, so you could setup a raspberry pi as a DoH server theoretically, and still keep the benefits of a PiHole. Mozilla is making CloudFlare the default but they aren't forcing it, you can use another server.
- z3t4 7y agoThere are many banks to choose from. Put your money elsewhere. Then explain to the bank why you did.
- ve55 7y agoEvery bank I've used has had a pretty absurd amount of trackers that I've blocked, often 5-10+ third party javascript domains. I don't know of any that don't have any, but I'm sure some small ones exist somewhere. There doesn't appear to be a huge market for services that do little/no tracking, as users are all unaware of the tracking that services do to begin with, so they would not even notice the difference.
- amluto 7y agoContact the regulators, perhaps? To me, allowing untrustworthy third-party scripts on a bank website sounds like a huge security risk.
- dredmorbius 7y agoBanks rely on a very small number of software vendors, so that the apparent abunance of bank options is all but eliminated at the middleware tier. "What Is Your Bank’s Security Banking On?" FIS, Fiserv or Jack Henry ... collectively control approximately 70 percent of the market for bank core processors (according to FedFIS.com, Fiserv is by far the largest). https://krebsonsecurity.com/2018/03/what-is-your-banks-security-banking-on/ https://krebsonsecurity.com/2018/03/what-is-your-banks-secur... Covered at HN: https://news.ycombinator.com/item?id=20203482 https://news.ycombinator.com/item?id=20203482
- kerpele 7y agoI can’t believe Ars Technica would do this. Do they not realize who their audience is?
- homero 7y agoThat also means most of their audience blocks ads. What are they to do?
- kerpele 7y agoif their audience blocks ads this isn’t going to help, it’ll only make people mad. I know I’m upset.
- nashashmi 7y agoBrowse those sites with js blocked. If not js blocked, then third-party cookies blocked. If not that, then ublock to block all cookies and allow only specific cookies. This is my recipe for browsing the web. Blocking specific cookies. Blocking all third-party cookies. A1llowing specific third-party cookies. Still, in recent months, I have noticed some have started getting smarter. So I block js there. But every browser is different with ease of use. Love brave browser capabilities. Like Chrome ease. Hate Firefox features. So using extensions to fill in those gaps.
- na85 7y agoStart providing content that users are willing to pay for?
- jrockway 7y agoThe problem is that subscription models are flawed, at least for things like Ars Technica. In most cases, people don't want to commit a portion of their monthly budget to a specific website for the rest of their life. I don't know how often I read Ars Technica, but it's probably a couple of articles a month. That is worth maybe $0.10 to me, so they can never collect that profitably. They use ads because then I "pay" whenever I visit, without having to approve any payment. More people visit, they automatically get more money. I wish there were some sort of globally-accepted micropayment system. With the billions of cryptocurrencies floating around, it surprises me that nobody has attempted this yet. I buy $10 of cryptocurrency. It gets loaded into my web browser. The webserver says "hey, you have to pay for this". My browser asks me if I want to do that. If I pick yes, then the server sends me the rest of the HTML after it agrees that the money was in fact transferred. (The closest thing I've seen to this are Twitch "bits". That is a micropayment platform that seems to be working pretty well, but it's used by the same people that want to pay their favorite content creators a stipend and so real-money recurring subscriptions are just as good. For that reason, I'm not sure we can infer much from that model, except that people will buy value in bulk and then dole it out to individuals at random intervals... which is pretty interesting if you think about it.) I think what is stopping this from being a thing is not any technical issue, but rather just greed from the content creators. I am sure that anyone that sells a subscription service is making money from people that have forgotten to cancel or don't get the maximum value out of their subscription, and it's probably a lot of money. Nobody is going to give that up. I also think advertisers pay too much for ads. I bet the "brand awareness" ads aren't worth nearly as much money as they pay. Meanwhile, publishers are making a lot of money off of selling impressions, and are probably hesitant to turn off free money from dumb people. Remember, serving an ad requires no input or investment from the end user; the website loads, they get money. If there were "brakes" applied every so often ("are you sure you want to pay the content creator using your real-world hard-earned cash?") revenue would go down. So I think the problems here are: 1) Advertisers want to advertise. If you remove your publication from the list of places where they can get something advertised, they'll go elsewhere. The money won't be removed from the ecosystem, and your competition will be enriched. That's not strictly a PROBLEM, but your investors will not be making happy faces at you when you leave money on the table. Only some sort of law could change that, and there will never be any such law. 2) Publishers are making a lot of money on unused subscriptions, so they continue to push subscriptions over micropayments. A lot of people are making content worth paying for. It's just that we can't afford it, but the advertisers can.
- 1996 7y agoAbusing cname is an old trick. You used to have domain.com and declare ns1.domain.com pointing to your host so it would show domain.com instead of host.com
- smitty1e 7y agoAt some point, having a cloud instance acceessed by VPN and proxing all traffic through that could be good. Until your proxy is hacked, I suppose. Resistance is feudal.
- sneak 7y agoAt what point does adblocking need to start taking IP address reputation and/or originating AS number into account?
- dredmorbius 7y agoNow. Seriously.
- deleted 7y ago[deleted]
- jefftk 7y agoThe easiest way for site-owners to delegate control has been to include third-party javascript. With new browser restrictions, we're starting to see companies switching to loading JS via CNAMEd subdomains, because that's nearly as easy. The next step is probably reverse proxies, though, where the third-party JS comes from the same server that gives you the rest of the site's JS. (Disclosure: I work in ads; speaking only for myself)
- poitrus 7y agoThey might yes, but it is orders of magnitude harder to setup and maintain than this, and as a website owner, you have to put even more trust in your ad serving solution than today.
- jefftk 7y agoReverse proxying is a little harder, but not much. In NGINX, for example: location /adtech/ { proxy_pass https://adtech.example/; } What additional trust are you thinking about? HttpOnly cookies are already sent when you use the subdomain approach.
- x0x0 7y agojs running on your domain can read eg login cookies at least if you cname definitelynotads.yourdomain.com to js.ads.com, the javascript running on definitelynotads... can't read host-only login cookies on yourdomain.com.
- jefftk 7y agoSites generally set Domain= on their cookies, and so include subdomains. For example, if you click "sign in" on apple.com it brings you to secure2.store.apple.com and after entering your password it sets a cookie with "Path=/; Domain=apple.com; Secure; HttpOnly". You're right that this does reduce security on some sites: if domain.example doesn't set Domain= on their cookies then ads.domain.example (CNAMED to js.ads.example) won't see the cookies but domain.example/ads would. This is pretty rare, though, because sites you log into generally do need their cookies to work across subdomains. Except this problem is easier to handle with reverse proxies than with subdomains: with subdomains the cookies are sent whether you want to or not, while with a reverse proxy the site owner can configure it to strip cookies.
- buboard 7y agoShouldn't neglect to discuss the proposed Signed HTTP Exchanges by google who will make this kind of thing far worse. Not just for the tracking implications, but how easy it will become for some countries to outright fake the news.
- poitrus 7y agoMore info on NextDNS solution to this problem here: https://medium.com/nextdns/nextdns-added-cname-uncloaking-support-becomes-the-first-cross-platform-solution-to-the-problem-e3f437f84342 https://medium.com/nextdns/nextdns-added-cname-uncloaking-su...
- TACIXAT 7y agoI have done something similar as an experiment. I wanted mixpanel analytics on a site for element interaction. I proxied mixpanel through a URL endpoint (maybe it was a subdomain). I had it not load analytics if DNT was set. It was a fun hack but more work than it was worth for my low traffic site.
- fwxwi 7y agoWhat's the difference between this and what Instart Logic has been doing for years now? https://github.com/gorhill/uBO-Extra#purpose https://github.com/gorhill/uBO-Extra#purpose
- hk__2 7y agoWow it goes even further: https://github.com/gorhill/uBO-Extra/wiki/Sites-on-which-uBO-Extra-is-useful https://github.com/gorhill/uBO-Extra/wiki/Sites-on-which-uBO... > Instart Logic will detect when the developer console opens, and cleanup everything then to hide what it does. I had to trick IL's script into thinking the dev console was not open to take the pic above.
- IAM2019 7y agoThe article explains that trackers traditionally loaded some external JS which then phoned home and tracked users via third-party cookies. I would like to point out that it has never been the case for Google Analytics and possibly other trackers. The developers of a website are supposed to copy/paste the Google Analytics snippet directly into their own JS, such that GA has access to first-party cookies. And then GA phones home some tracking data leveraged by this first-party cookie. Blocking third-party cookies never blocked this kind of tracking. You needed to block the domains that the script requested via AJAX. But it is indeed made difficult with CNAME Cloaking, because the domains requested are subdomains of the current domain, and can be changed regularly as explained by the article. There is no end-game solution against tracking. It will all come down to tracking companies ordering websites to install some library directly in their back-end and pass it user data as well as behavioral data captured from some other library installed in the front-end. Tracking data will pass through applicative pipes and it will be impossible to block reliably.
- poitrus 7y agoJavascript executed from site's own scripts does not give more or less rights to access first party cookies than Javascript executed from an externally loaded URL. Any Javascript executed on a page as the same access to all those.
- nugget 7y agoHow does the centralized ad server track the user as they move from site A to site B, since no cross-domain cookies can be used? Without resorting to fingerprinting which could be circumvented by the client. Absent behavioral profiles and persistent tracking, most ad formats are worth very little. Isn’t limiting all communication to the first party domain a form of sandboxing?
- yegle 7y agoPihole has an "audit" feature that can be used here: https://pi-hole.net/2017/12/06/pi-hole-v3-2-introduces-long-term-statistics-an-audit-log-colours-and-more/ https://pi-hole.net/2017/12/06/pi-hole-v3-2-introduces-long-...
- strenholme 7y agoThe way to counter this is to know the IP a given CNAME resolves to, and to block “rogue” (read: tracking) IPs. As an open-source DNS implementer, I know this has already been done, since my DNS server (MaraDNS’s Deadwood recursive resolver) has the ability to refuse to resolve DNS names with bad IPs via ip_blacklist. The reason I implemented this is to block NXDOMAIN redirects (when using an ISP’s DNS server and mistyping a domain name, instead of getting “nothing there”, it goes to an ad-filled “search” page provided by the ISP), but the implementation scales and it should work for blocking a large number of rogue CNAME redirects like this one. I’m sure others have implemented something similar out there (I will let someone who knows the pihole ad-blocking DNS server, not to mention NextDNS, better than me tell us how they do this), and I’m sure Firefox, if they do not do so already, will allow ad/privacy blockers to know the IP of a given name to allow blocking at the browser level.
- skunkpocalypse 7y ago> block “rogue” (read: tracking) IPs. With IPv6 that's as impractical as blocking "rogue" FQDNs.
- tambre 7y agoWhy? Just block ranges.
- strenholme 7y agoExactly. If I were to update this code, for IPv4 blocking, I would allow it to block /32 (single IP) and /24 networks. For IPv6 blocking, I would allow blocking a single IPv6 address, a /64 range, and (for extreme offenders) a /48 range. One way to do this is to have multiple hash tables: One for single IPv4 addresses, one for IPv4 /24 ranges, one for single IPv6 addresses, one for /64 IPv6 ranges, and one for /48 IPv6 ranges. Note that while the hashes have (generally speaking) a “big O” of 1, we need to perform one additional operation per range size. IPv4 /32 and /24 blocking requires two lookups, and IPv6 /128, /64, and /48 blocking requires three lookups.
- 7y ago
- woadwarrior01 7y agoI don’t want to name any companies here, but CNAME cloaking is also commonly used in ad-tech for conversion tracking pixel urls.
- kkm 7y agoIn particular case of liberation.fr, anyone who has access to the value of ‘djazsession’ cookie can log in to the users’ account. This is one of the cookies being sent to Eulerian. Here is a demo video: https://twitter.com/konarkmodi/status/1198412297842184192?s=21 https://twitter.com/konarkmodi/status/1198412297842184192?s=...
- Havoc 7y agoI'm back on the Noscript train & just white-listing stuff on the sites I frequent
- finchisko 7y agoI don't get one thing. Isn't CNAME also bad for "them". I mean with CNAME, they can serve adds, cookies ... from site subdomain, bypassing blockers. But how will they track users on different sites, like user vising website1 and then website2? Since their tracking cookies are now part of website1, they won't be sent to website2. I mean is there any replacement for them, not using cookies? Because cookies seems to be the only global storage for user identification data. Since tracking script was hosted on their domains (and included into websites with script tag), cookies were shared across all site, that included that tracking script. IMO when they switch to CNAME trick, they will loose this capability.
- poitrus 7y agoWith fingerprinting.
- beefield 7y agoI wonder if it would be possible to make a whitelist blocker instead of just blacklist? I mean, if a certain domain is in the whitelisted list, you show only responses from whitelisted subdomains. If not, you fall back to blacklist. By possible I do not mean technically possible, but feasible in the resources required maintaining the list as well as good enough user experience.
- xyzal 7y agoPlease correct me if I am wrong, but would not such a tracking be circumvented by enabling first party isolation in the browser? As far as I know, Firefox has such feature implemented: https://www.ghacks.net/2017/11/22/how-to-enable-first-party-isolation-in-firefox/ https://www.ghacks.net/2017/11/22/how-to-enable-first-party-...
- vsto 7y agoI was also wondering about the that. Sadly, it is still not enabled by default in the latest Firefox release (version 70). Furthermore would the Firefox Multi-Account Containers https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/ https://addons.mozilla.org/en-US/firefox/addon/multi-account... with container per site prevent such tracking (has to be done manually ATM) ?
- air7 7y agoHow does this work with SSL certification? The 3rd party server needs to be in possession of a certificate for eir63gd.mywebsite.com
- tatersolid 7y agoLet’s Encrypt makes this trivial and automatic if foobar.example.com has been CNAMEed to the tracking provider.
- tinus_hn 7y agoCute, but now they can’t use their cookies to track you around the web because on every site their page has a different domain name. So this is actually an improvement.
- greatgib 7y agoWe can use that to add the domains to 'spam' lists as they host a lot of ads/spy subdomain.
- belorn 7y agoOnline advertisement are constantly using the same exploits that malware and can be seen as part of the progression ladder when walking from being zero-day to universally patched. A while back ago malware started to use a scheme similar to fast flux, but rather than changing the IP address they used a chain of cnames to hide the malware network. In order to combat this researchers developed detection tools to find algorithmic generated domain names and flag them as suspicious at the resolver layer. I would expect to see the same mitigation method to travel into ad-blocking.
- aberforth123 7y agoOk, so how to we kill the ad industry? This is ridiculous.
- air7 7y agoSomething is missing here: HTTPS links and SSL. Either website.com hands over its certificate to dnsdelegation.io (which is unlikely and definitely not a 2 min trust-less process) or dnsdelegation.io has the ability to generate any certificate like a certificate authority which is really terrible (and also unlikely).
- hiciu 7y agoDV certificate (cheapest, most common one) does require only proof of control over the domain. So dnsdelegation.io can just request certificate for the domain you've delegated via cname from any CA.
- sildur 7y agoThey are (ab)using let’s encrypt.
- poitrus 7y agoWith ACME enabled CAs like letsencrypt, having a domain pointing to an IP you control is all you need to obtain a valid certificate.
- air7 7y ago> It also only takes 2 minutes to change dg3fkn.website.com to 3j4vdl.website.com (Hell, you can probably automate this). We mentioned above how much work it takes to gather all subdomains being used as a front for CNAME Cloaking. Now imagine they change every week, every day, or every hour. It’s just impossible to keep track. That's fear mongering. The ad company can't pester their clients to make changes to the DNS on a regular basis. I'd say that anything beyond initial setup would be unaccepted to most clients. And clients won't give control of their DNS to ad company, so automation is also not really possible. Also, because this setup is substantially more friction than a simple 3rd party tracking "just copy-paste this code", I'd guess it will only be used by high profile clients. This all means that while annoying, it shouldn't be too hard to find and add these subdomains to the ever-updating ad url blacklists.
- depr 7y ago>The ad company can't pester their clients to make changes to the DNS on a regular basis. Many DNS providers have APIs. >And clients won't give control of their DNS to ad company, so automation is also not really possible. Sure they will. Or they'll use another party that does it. They already add JS from the ad provider that does god knows what to all their pages, and give full control over their content to Cloudflare. So why wouldn't they give an ad provider API access to their DNS?
- bigkm 7y agoWhat if there were restrictions on these with regards to ttl, it would put the burden back on the trackers, they wouldn't be able to swap and change them as quick and very quickly run out of options.
- cx42net 7y agoI don't get it, why ad-blockers can't request a DNSBL managed by them to know if that CNAME is authorized or not? Granted, it requires a bit more network request, but completely breaks the CNAME cloacking method.