2011 IEEE Symposium on Security and Privacy 2011
DOI: 10.1109/sp.2011.23
|View full text |Cite
|
Sign up to set email alerts
|

I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel Attacks

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
50
0

Year Published

2011
2011
2021
2021

Publication Types

Select...
5
2
1

Relationship

0
8

Authors

Journals

citations
Cited by 83 publications
(50 citation statements)
references
References 12 publications
0
50
0
Order By: Relevance
“…After the disclosure, a prevention mechanism was proposed by L. David Baron of Mozilla [30] and has been adopted in the latest version of major browsers. Right after that, in May 2011, Weinberg et al [31] demonstrated a new kind of history sniffing attack that circumvents even Baron's defense and to date, no newer protection measure has been proposed.…”
Section: Protectionmentioning
confidence: 99%
“…After the disclosure, a prevention mechanism was proposed by L. David Baron of Mozilla [30] and has been adopted in the latest version of major browsers. Right after that, in May 2011, Weinberg et al [31] demonstrated a new kind of history sniffing attack that circumvents even Baron's defense and to date, no newer protection measure has been proposed.…”
Section: Protectionmentioning
confidence: 99%
“…This includes for instance attacks at the network level (eavesdropping on or tampering with network traffic), attacks that trick users into manually propagating sensitive information [56] or CSRF attacks that do not make use of scripts [9]. Heiderich et al [28] show that such scriptless attacks can be surprisingly powerful.…”
Section: Out-of-scope Threatsmentioning
confidence: 99%
“…Finally, users can also create such leaks by being tricked into manually propagating confidential information. These leaks are important in practice: Chen et al [17] and Weinberg et al [56] give examples of attacks such as the one discussed above. As a consequence, an important challenge when setting policies on the API is to set the policy in such a way that the world does not have any leaks itself with respect to the policy that is set.…”
Section: Non-interference Of Flowfoxmentioning
confidence: 99%
See 1 more Smart Citation
“…For protecting apps on the same host, the current web API imposes complicated restrictions on inter-domain communication that admit subtle flaws [22]. By contrast, Zoog provides no cross-app communication other than a layer-3 network interface, which introduces seven CEI calls to support zero-copy packet I/O.…”
Section: Support For Networked Applicationsmentioning
confidence: 99%