Researchers from Princeton University recently shared that your browser auto-fill function may be allowing you to be tracked. Theft of credentials from login managers is not a new exploit but previously it has all been through malicious scripts. However, this is the first time it is being abused for the purpose of tracking users.
The tracking script is not present on the initial login where the user enters their credentials and the browser saves the login info. As the user visits subsequent pages at the site, tracking scripts are inserting invisible forms that are automatically filled in by the browser. The scripts retrieve the user's email address from the form and forwards hashes of the emails to third-party aggregators.
By sending a hash of your email address, they claim it is anonymous data. Since it is quite common for users to use their email address as a login across many sites, the aggregators can use the hash to correlate data from multiple sites, across multiple devices and link browser history before and after cookie clears. Since your email almost never changes, it is hard to break out of the tracking. Furthermore, anyone can see if your data is in the dataset by simply hashing your email and doing a search. So it is not anonymous in my book.
Two companies are identified as abusers of scripts that extract from login managers.
1. OnAudience
Except from the website:
The website also makes marketing claims such as: (Italicized highlighting done by me.)
Anonymous marketing is a waste of money
Dynamic optimization
- Custom segments improved by machine learning and '3rd party data'
Fingerprints
- Use wide variety of 'behaviorally assigned attributes'
2. AudienceInsights
The website states: Italicized highlighting and (comments) are mine.
What is it?
AudienceInsights is a Web application offering analysis and statistics based on 'anonymous data collection.'
How information is collected?
Our partners' websites and applications host our program that collects information (by using hidden forms to trick your browser into auto filling) and sends it to our servers where it is stored and analyzed.
What is collected?
We collect only 'anonymous data' through anonymous cookies and technologies that record:
- events related to your activity on the partner’s website (such as the number of pages viewed or your searches made on the partner's website),
- information provided by trusted partners that may include socio-demographic data such as age range.
We do not collect any personal information. We do not know who you are. We do not know your residential address (How about my city & state?), your email address, your phone number or any other personally identifiable information about you.
We do not collect sensitive information (such as medical condition, bank account...). (Are you sure?)
So you ask, how can they provide all this analytic data if it is anonymous?
The Princeton researchers looked into these scripts that exploit your auto-fill and found very detailed category definitions of data they are capable of tracking.
birth date,
age,
gender,
nationality,
height,
weight,
BMI (body mass index),
hair_color (black, brown, blond, auburn, chestnut, red, gray, white),
eye_color (amber, blue, brown, grey, green),
education,
occupation,
net_income,
raw_income,
relationship states,
seek_for_gender (m, f, transman, transwoman, couple),
pets,
location (postcode, town, state, country),
loan (type, amount, duration, overindebted),
insurance (car, motorbike, home, pet, health, life),
card_risk (chargeback, fraud_attempt),
has_car(make, model, type, registration, model year, fuel type),
tobacco,
alcohol,
travel (from, to, departure, return),
car_hire_driver_age, hotel_stars
So they claim anonymity because they don't have your name, street address, or email. But by using a hash of your email they can know pretty much every other detail of your life, right down to the age of your taxi cab driver or if you have insurance on your pet!......
How broad is the exposure
The scripts where found on 1110 of the Alexa top 1 million sites. A comprehensive list of sites can be found HERE.
I did a quick cursory scan of the list and did not find any that I recognized. Out of curiosity I also search the list for the term 'steem' and nothing came up.
So what can you do?
Steve Gibson from the Security Now! podcast recommends everyone change their hosts files to prevent the scripts from connecting to the aggregators.
You will want to add the following two lines of code:
127.0.0.1 static.audienceinsights.net
127.0.0.1 api.behavioralengine.com
If you are not familiar with editing your hosts files, here is a How-To Geek article that you can follow.
This will prevent these particular two scripts from getting your data, but how many more will there be?
One of the researchers has set up a demo page where you can see if your browser is susceptible to these scripts.
Perhaps the safest method is to turn off password managing and auto-fill options in your browser. If you use a password manager such as LastPass, which I do, you will need to turn off the autofill feature as well.
Although a little more tedious, another thing you can do is use a non-email user name for your log-ins when you can. Even better yet, use a different user name for different sites. This does become impractical if you are not using a password manager.
Be safe and protect your information!
Sources
http://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/ -(Princeton Research)
https://www.grc.com/sn/sn-644.pdf -(Security Now! podcast transcript)
Beekeep On!
@bushkill