3 ms·
It is important to be aware that >64 bit supercookies ("impressions") are now being stored outside of the cookies subsystem in their own PrivateAttribution.sqli
by dhx 2y ago
It is important to be aware that >64 bit supercookies ("impressions") are now being stored outside of the cookies subsystem in their own PrivateAttribution.sqlite database.[1]
The implications are numerous:
1. There is no user interface or settings yet available to change the whitelist of Google-enrolled (Google being the only enrollment option today as far as I have discovered) ad-tech domains that are allowed to set the supercookies or use these supercookies to track users between sites.[2] By contrast, users can currently configure cookie settings such that they are only allowed for certain user-whitelisted sites.
2. There is no user interface yet to view and delete the supercookies, as one can currently do with normal cookies.[3]
3. Supercookies are shared across all Firefox containers breaking existing expectations of container isolation.[4]
4. Supercookies were shared across private browsing and non-private-browsing sessions until v120.b5, then Private Attribution was disabled in private browsing sessions (for now, and pending decisions on whether supercookies should persist across private browsing sessions).[5]
5. The setting privacy.firstparty.isolate is not honoured by Firefox's Private Attribution feature.[6]
6. Users are at greater security and privacy risk due to implementation of an extremely complicated and obfuscated draft standard that is full of technobabble bullshit which deliberately avoids real security and privacy impacts.[7] For example, the specification hand waves away the significance of a 64-bit supercookie as somehow being difficult to use to track users between sites. Reality is that only 33 bits is needed to uniquely identify every human alive today, and 37 bits for every human who has ever lived. The specification's section on privacy and security impacts does not address, for example, a website including an ad that proceeds to fingerprint John's browser as an 18 bit identifier as demonstrated at [8], then combine it with other identifiers such as the netblock/ASN of John's home internet connection. Later when John is in a completely different Firefox container connected to his employer's WiFi network browsing another site, the browser fingerprint or other tracking data within the 64-bit supercookie can trivially be used to associate John with his employer.
This Firefox partial implementation of "Private Attribution API" is just a small part of the full set of "Privacy Sandbox" anti-features Google is busy adding to Chrome, including, and of much greater concern:
1. "Private Attribution API" event-level reporting. Currently Firefox appear to have just implemented aggregate-level reporting, so the supercookie values aren't shared outside of the browser. The full specification from Google also allows event-level reporting where the supercookie values (which are set by an ad-tech company such as Google when the user visits site A) are later re-shared with the ad-tech company when the user visits a completely different site B.
2. "Protected Audience API". Execute within the browser auction bidding JavaScript bots from multiple advertisers where the bot can peek at private user data in order to bid on the impression, and then the winning bot will display the ad and report back the winning impression.
3. "Topics API". Summarise browser history in order to tell ad companies what categories of websites the user has been visiting. For example, John is interested in boats, fishing, car racing, beer and travel. Jane is interested in rock climbing, exercising in gyms, yoga, Italian cuisine and furniture.
[1] https://searchfox.org/mozilla-central/source/dom/privateattribution/PrivateAttributionService.sys.mjs https://searchfox.org/mozilla-central/source/dom/privateattr...
[2] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Attribution-Reporting-Register-Source https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/At...
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=1901106 https://bugzilla.mozilla.org/show_bug.cgi?id=1901106
[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1901103 https://bugzilla.mozilla.org/show_bug.cgi?id=1901103
[5] https://bugzilla.mozilla.org/show_bug.cgi?id=1901792 https://bugzilla.mozilla.org/show_bug.cgi?id=1901792
[6] https://searchfox.org/mozilla-central/source/dom/privateattribution/PrivateAttribution.cpp https://searchfox.org/mozilla-central/source/dom/privateattr...
[7] https://wicg.github.io/attribution-reporting-api/ https://wicg.github.io/attribution-reporting-api/
[8] https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/