/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

How third-party scripts on websites exploit a flaw in browsers' built-in password managers to identify and track users

In this second installment of the No Boundaries series, we show how a long-known vulnerability in browsers' built-in password managers is abused by third-party scripts for tracking on more than a thousand sites.

Freedom to Tinker Gunes Acar

Discussion

  • @collabjonathan Jonathan Schulenberg on x
    This is simultaneously very clever and alarming. Let's see how long it takes for every browser & password manager to change their behavior and whether the solution is more elegant than requiring user acknowledgement before auto-filling. http://twitter.com/...
  • @julianor Juliano Rizzo on x
    We've seen variants of this password autocomplete stealing bug for years. Do not use “save password” feature of browsers or password managers integrated to the browser. Bugs in domain name parsers, race conditions, injections and attackers have Javascript power to exploit them. h…
  • @tedonprivacy Ted on x
    Abusing security features to track people without knowledge or consent is my favorite kind of Eldritch creepiness. Here, an invisible login form is auto-filled by your browser's credential manager. The page can then retrieve your email address and use it as a tracking ID. http://…
  • @troyhunt Troy Hunt on x
    Good detail on exploit scripts snooping on data stored in browser password managers http://twitter.com/...