Description
May-25-2020: update from the researcher:
Hi, I've done a retrospective analysis of Firefox versions, up until Firefox 76. All issues discussed in the original report appear to be resolved, except for one; the request initiated by the WebSocket API is not blocked [by Tracking Protection] when directed to a blacklisted domain
This issue is really just for myself, and FYI - I'll fix the title one day when I get the time to read the docs etc and understand what is going on
- Article: https://www.bleepingcomputer.com/news/security/academics-discover-new-bypasses-for-browser-tracking-protections-and-ad-blockers/
- Bypasses are new, not used in the wild yet
- ghacks article: https://www.ghacks.net/2018/08/18/browsers-have-cookie-and-anti-tracking-enforcement-issues/
- Website: https://wholeftopenthecookiejar.eu/
- Github: https://github.com/DistriNet/xsr-framework
- Paper: https://wholeftopenthecookiejar.eu/static/tpc-paper.pdf
Discussions
- r/firefox: https://old.reddit.com/r/firefox/comments/97racx/academics_discover_new_bypasses_for_browser/
- r/privacy: https://old.reddit.com/r/privacy/comments/97rare/academics_discover_new_bypasses_for_browser/
- r/uBlockOrigin: https://old.reddit.com/r/uBlockOrigin/comments/97tzw9/academics_discover_new_bypasses_for_browser/
- Schneier on Security: https://www.schneier.com/blog/archives/2018/08/new_ways_to_tra.html
I had a quick skim of the reddit link and article last night, and
-
- gorhill has us covered, assuming your config is "right" (good gorhill, good boy!) 💋
-
- I'm not worried personally, as I lock down basically all persistent storage
My assumption has always been that any persistent storage of website data can and will be used against you. Hence why the default user.js essentially blocked everything (until recently where we allowed first party cookies). Anyway, that's all for now
PS: I do not care about ABP, Disconnect, SafeScript etc, I only care about uM, uBO (and Firefox)
@gorhill Thanks, feel free to chime in if and when you have time (and feel it necessary), just don't like talking behind yer back :)