Page 1 of 1

Any protection against browser history snooping via CSS?

Posted: Tue May 25, 2010 7:57 pm
by bslade
According to the article Feasibility and Real-World Implications of Web Browser History Detection at http://w2spconf.com/2010/papers/p26.pdf , the authors were able to snoop the browser history via CSS style sheets for 74% of the users who accessed their test websites.

Any chance NoScript might someday protect against this?

Ben

Re: Any protection against browser history snooping via CSS?

Posted: Tue May 25, 2010 8:13 pm
by therube
Alternative views: http://docs.google.com/viewer?a=v&q=cac ... LoEr_z99DQ

Isn't Mozilla doing something about browser history snooping ;-).

Plugging the CSS History Leak

A New Type of Phishing Attack

Re: Any protection against browser history snooping via CSS?

Posted: Tue May 25, 2010 10:26 pm
by GµårÐïåñ
I'm pretty sure this was previously discussed and NoScript indeed does protect against it. You might also take a look at Giorgio's blog, its on there as well IIRC.