论文标题
Jshelter:给我我的浏览器
JShelter: Give Me My Browser Back
论文作者
论文摘要
网络每天使用数十亿美元。即便如此,默认情况下,用户也没有受到许多威胁的保护。该立场论文以先前的Web隐私和安全研究为基础,并引入了Jshelter,这是一种努力将浏览器退还给用户的Webextension。此外,我们介绍了一个图书馆,可以帮助完成常见的Webextension开发任务,并通过以前的研究滥用漏洞。 Jshelter着重于指纹预防,富含Web API的局限性,预防与时间连接的攻击以及有关设备,浏览器,用户以及周围物理环境和位置的信息。我们在传感器时间戳中发现了一个漏洞,如果在基于铬的浏览器中启用了传感器API,则可以使任何页面都可以观察到设备启动时间。 Jshelter提供了一份指纹报告和其他反馈,该报告可以由未来的安全研究和数据保护当局使用。世界各地成千上万的用户每天都使用Webextension。
The web is used daily by billions. Even so, users are not protected from many threats by default. This position paper builds on previous web privacy and security research and introduces JShelter, a webextension that fights to return the browser to users. Moreover, we introduce a library helping with common webextension development tasks and fixing loopholes misused by previous research. JShelter focuses on fingerprinting prevention, limitations of rich web APIs, prevention of attacks connected to timing, and learning information about the device, the browser, the user, and surrounding physical environment and location. We discovered a loophole in the sensor timestamps that lets any page observe the device boot time if sensor APIs are enabled in Chromium-based browsers. JShelter provides a fingerprinting report and other feedback that can be used by future security research and data protection authorities. Thousands of users around the world use the webextension every day.