Brave browser first to nix CNAME deception, the sneaky DNS trick used by marketers to duck privacy controls
- Reference: 1603914026
- News link: https://www.theregister.co.uk/2020/10/28/brave_cname_block/
- Source link:
The browser security model makes a distinction between first-party domains – those being visited – and third-party domains – from the suppliers of things like image assets or tracking code, to the visited site. Many of the online privacy abuses over the years have come from third-party resources like scripts and cookies, which is why third-party cookies are now blocked by default in Brave, Firefox, Safari, and Tor Browser.
Brave, Google, Microsoft, Mozilla gather together to talk web privacy... and why we all shouldn't get too much of it [1]READ MORE
Microsoft Edge, meanwhile, has a tiered scheme that defaults to a "Balanced" setting, which blocks some third-party cookies. Google Chrome has implemented its SameSite cookie scheme as a prelude to its planned 2022 phase-out of third-party cookies, [2]maybe .
While Google tries to win support for its various [3]Privacy Sandbox proposals , which aim to provide marketers with ostensibly privacy-preserving alternatives to increasingly shunned third-party cookies, marketers have been relying on CNAME shenanigans to pass their third-party trackers off as first-party resources.
The developers behind open-source content blocking extension uBlock Origin [4]implemented a defense against CNAME-based tracking in November and now Brave has done so as well.
CNAME by name, cookie by nature
In a [5]blog post on Tuesday, Anton Lazarev, research engineer at Brave Software, and senior privacy researcher Peter Snyder, explain that online tracking scripts may use canonical name DNS records, known as CNAMEs, to make associated third-party tracking domains look like they're part of the first-party websites actually being visited.
They point to the site https://mathon.fr as an example, noting that without CNAME uncloaking, Brave blocks six requests for tracking scripts served by ad companies like Google, Facebook, Criteo, Sirdan, and Trustpilot.
Brave soz about coding snafu that sent search queries to affiliate links, insists practice is 'industry-standard' [6]READ MORE
But the page also makes four requests via a script hosted at a randomized path under the first-party subdomain 16ao.mathon.fr .
"Inspection outside of the browser reveals that 16ao.mathon.fr actually has a canonical name of et5.eulerian.net , meaning it’s a third-party script served by Eulerian," observe Lazarev and Snyder.
When Brave 1.17 ships next month (currently available as [7]a developer build ), it will be able to uncloak the CNAME deception and block the Eulerian script.
Other browser vendors are planning related defenses. Mozilla has been [8]working on a fix in Firefox since last November. And in August, Apple's Safari WebKit team [9]proposed a way to prevent CNAME cloaking from being used to bypass the seven-day cookie lifetime imposed by WebKit's Intelligent Tracking Protection system. ®
Get our [10]Tech Resources
[1] https://www.theregister.com/2020/01/29/browser_security_enigma/
[2] https://www.adexchanger.com/adexchanger-talks/google-ads-gm-jerry-dischler-on-a-cookieless-future-that-happens-when-it-happens/
[3] https://www.theregister.com/2020/02/10/googles_second_stab_at_preserving_both_privacy_and_ad_revenue_raises_concerns/
[4] https://www.theregister.com/2019/11/21/ublock_origin_firefox_unblockable_tracker/
[5] https://brave.com/privacy-updates-6/
[6] https://www.theregister.com/2020/06/09/brave_affiliate_links_bug/
[7] https://github.com/brave/brave-browser/releases/tag/v1.17.52
[8] https://bugzilla.mozilla.org/show_bug.cgi?id=1598969
[9] https://bugs.webkit.org/show_bug.cgi?id=215201
[10] https://whitepapers.theregister.com/
Re: Sooner or later we're going to have to work out a way to fund all this.
Brave rewords users who accept adverts. I find this disturbing because it implies users can be bribed to watch/interact with potentially harmful influence bodies . Well at least it will put a hole in Googles bucket of cash and start spreading it around.
Re: Sooner or later we're going to have to work out a way to fund all this.
Brave rewords users who accept adverts. I find this disturbing ...
But at least when you turn 'rewards' off, it stays off when the browser gets upgraded. This is unlike the so-called "privacy protection features" provided by certain other browsers where the privacy protection controls just get more carefully hidden and reset to default values which, oddly enough, always seem to be 'protection disabled', by the next release.
Must be lazy programmers: surely no company would ever think of doing that reset deliberately . .
Re: Sooner or later we're going to have to work out a way to fund all this.
Why not show the same ad to everyone, like in the dead-tree newspaper days.
YouTubers for example make way more money from sponsorships than they do from Adsense. Picking a one size fits all ad that they think is relevant and interesting to their viewers seems to work a lot better than all this AI stuff.
Sooner or later we're going to have to work out a way to fund all this.
Yes it's all pretty despicable
But how do work out a way that makes it affordable yet rewards people who do the work?
Fook nose.