Уровень 0 · материалов: 4
В кластер входят документы, описывающие конкретные технические методы или уязвимости браузеров для скрытого отслеживания действий пользователя, и не входят общие обзоры телеметрии или случаи использования аналитики на внутренних страницах.
Общие признаки: скрытый сбор данных, отслеживание истории посещений, технические лазейки в браузерах, нарушение конфиденциальности пользователей
Группа выше: Отслеживание в вебе и фингерпринтинг
Смысл: The text highlights a browser privacy flaw that allows websites to detect a user's browsing history, using the site Startpanic.com as a practical example to encourage browser developers to fix the issue.
The author discusses Startpanic.com, a site that demonstrates a browser vulnerability allowing the detection of a user's browsing history to advocate for better privacy protections.
Смысл: The text explains how a website claiming to read minds actually uses a CSS trick with the :visited pseudo-class to detect which popular websites are in a user's history based on which elements the user clicks.
The 'Who Am I?' website doesn't read minds but uses the CSS :visited pseudo-class to leak users' browsing history through their interactions.
Смысл: The main idea is that a simple technical loophole in how websites handle authentication redirects allows third-party sites to covertly track which accounts a user is logged into, a privacy flaw that major tech corporations largely ignore because it doesn't allow for direct data theft.
Websites can use image-loading tricks and redirect URLs to secretly detect if you are logged into services like Facebook or Twitter, a privacy risk mostly dismissed by the companies themselves.
Смысл: The main idea is that many popular browsers silently record the download source of files in hidden system metadata (extended attributes), which can be used for tracking and surveillance, and users should be aware of how to identify and remove this data.
Chromium-based browsers store the download source URL in hidden file system extended attributes across Linux, macOS, and Windows, posing a privacy risk.