Тёмный

Your Browser is Lying 

Matt Sionkowski
Подписаться 2,1 тыс.
Просмотров 17 тыс.
50% 1

Subscribe to not miss out on next releases!
Your browser is a liar. It lies about colors and styles of links.
Go with me through the journey starting on the lie itself, through its history, up to the solution, and back to reintroducing it together with me.
Sources:
seclists.org/bugtraq/2002/Feb...
blog.jeremiahgrossman.com/200...
blog.mozilla.org/security/201...
www.theregister.com/2008/07/2...
www.technologyreview.com/2010...
developer.mozilla.org/en-US/d...
• Browser history re:vis...
thedarkside.frantzmiccoli.com...

Наука

Опубликовано:

 

14 май 2023

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 48   
@andersondamasceno
@andersondamasceno Год назад
I liked how you started by telling the story of the problem, then talked about how you found another way to achieve the same thing, and ended by showing an incorrigible way to leak the same information. Wonderful stuff. 🙂
@mattsionkowski
@mattsionkowski Год назад
Thank you! Couldn't do it any other way. There are vulnerabilities which are considered "small" just because people lack context. And with proper context it starts showing that there is more on the line than meets the eye. Cheers!
@mendhak
@mendhak Год назад
That last part captcha'd my imagination
@WithYouIDisagree
@WithYouIDisagree Год назад
Cool video! One suggestion is to lower the volume of the background music or increase your voice's volume. It was hard to understand what you were saying at some points. The captions helped.
@mattsionkowski
@mattsionkowski Год назад
Thank you for feedback. Will surely do that on the next one. Cheers!
@ko0x
@ko0x Год назад
@@mattsionkowski There's a technique called "ducking" in audio engineering. You can use a compressor with "side chain" to automatically lower the volume of an audio track if there's a signal from another audio source. E.g. automatically lower the background music when voice comes in. It's automatic and gives you nice dynamics.
@davel4030
@davel4030 21 день назад
​​@@ko0x my phone does that when I'm listening to music and it gets a notification or starts reading a text in the car. Good feature. I know it's not exactly what you're talking about but same effect pretty much.
@ThomWalbranA1
@ThomWalbranA1 19 дней назад
I agree 100% , I would not mind cutting the music all together. You content is great and doesn't need any tricks or fluff. Thank you for sharing.
@jakubgluma2189
@jakubgluma2189 Год назад
Amazing stuff! Nice lego car btw :)
@mattsionkowski
@mattsionkowski Год назад
Cannot start a mission without a good ride. It's special agent's 101 :)
@bobcoco6047
@bobcoco6047 18 дней назад
Great presentation ! I wonder if it's possible to build some funnel logic into the captcha characters, so that they could display the color white/black for different functions than directly "did you visit this unique address", but rather "did you visit 1 of those, or this group?" , so that depending on the characters appearing, they could know + about us than just 1 link history... Concerning anyway, & suggests me there is indeed some reason to empty our history, & focus on either randomization of leaks (seems best), hiding 'em when possible & not counterproductive (fingerprint, which ironically can happen from hiding x ) or deleting the data (not always possible nor ideal). Thx
@AI-Restoeations
@AI-Restoeations 16 дней назад
This is the second video of yours I've watched, you've earned my sub. Such professional videos from such a small channel keep it up
@mattsionkowski
@mattsionkowski 16 дней назад
I'm glad you stayed around! Cheers
@daimonismeno
@daimonismeno Год назад
Man, please keep up the excellent work. All your videos are enjoyable and rewatchable. Nice!
@mattsionkowski
@mattsionkowski Год назад
Thank you! You made my day🙂
@CottonInDerTube
@CottonInDerTube 17 дней назад
@@mattsionkowski I watched 2 of your videos and agree: quallity content. The only 2 things i dont like are the backgound music and the inserted video snippets. That makes me fell like somebody is trying to sell me something.
@Mangohawk124
@Mangohawk124 Год назад
Very high quality content nice bro ❤🎉🎉🎉🎉
@mattsionkowski
@mattsionkowski Год назад
Thank you! Means a lot ❤
@artinfopartner
@artinfopartner Год назад
Whoah great content Matt ! I lovw such things !
@mattsionkowski
@mattsionkowski Год назад
Thank you! Will keep going 😀
@inamortz2372
@inamortz2372 Год назад
Nice one man, very informative.
@mattsionkowski
@mattsionkowski Год назад
Thank you, mate. This is still a fresh channel so i very much appreciate the feedback. It helps with maintaining or adjusting direction. Cheers!
@mashpotato832
@mashpotato832 Год назад
The capthcha thing can't really be used for rapid mass scanning of visited links though, yeah it links info but it's nowhere near as bad. Cool video thanks for putting this together, I enjoyed it.
@teambridgebsc691
@teambridgebsc691 18 дней назад
Enjoyed and informed. Doing a great service here.
@CottonInDerTube
@CottonInDerTube 17 дней назад
And again i must say: the problem is that we execute programs (JS) on our machines just because we wanted to read text like the news or so.
@mattm1982
@mattm1982 Год назад
I don't know why I clicked this or watched it but it was very well done... good job man :) Also to echo what someone else said, I would decrease the music volume a bit.
@Obiika
@Obiika Год назад
Very informative video, tells a lot more than just the story initially covered !
@desiredditor
@desiredditor Год назад
very good video just try to sit in a different place which doesnt have a slanting side right on the right side of the video regarding bg music just lower it by 5 db and it should be better
@NorthernChimp
@NorthernChimp Год назад
Wathehack couldn't browsers just disable the ":visited" css pseudo-class? (for websites, even if the browser uses it itself) How is this unpatchable?
@mattsionkowski
@mattsionkowski Год назад
The problem is - users expect this functionality to work as it is as old as browsers. And if you disable the pseudo class, the browser internally might turn links purple, but it will not allow the webmaster to use a custom color. ... tradeoffs ... But also keep in mind that my last use case required users action. Making a leak far smaller in size and in potential risk. The "lying" solution is really quite good. It prevents the massive leaks (automatic ones)
@davel4030
@davel4030 21 день назад
They can patch to make text not be able to be the same color as the surrounding background. I can't think of any legit use, only malicious uses. Who would need to hide text? And if they do want a uniquely generated finger print they can just throw it to the bottom of the page where it won't disrupt the sites experience.
@chmielewskibartek
@chmielewskibartek Год назад
Favorite host :) Best wishes and looking forward for new stuff!
@mattsionkowski
@mattsionkowski Год назад
Work in progress :D Thank you, and will keep going.
@freddrune8315
@freddrune8315 19 дней назад
Great video sir.
@danieldahl7186
@danieldahl7186 Год назад
Glad i stuck around for the end
@MisterZizzy23
@MisterZizzy23 Год назад
Nice video sir! Keep it sir ❤. Love from India 🇮🇳 ❤
@sgramstrup
@sgramstrup Год назад
Learned a lot.. Scary shit. I'm less worried about a single hacker on a dark site, than big scumcorp spying on me. Thx.
@mattsionkowski
@mattsionkowski Год назад
The history leak took 8 years for a patch - but still, it got resolved at some point. Yet this is not the last privacy threat. I'm in the making of a video about browser fingerprinting, which is an issue very much alive. Stay tuned!
@3vonline
@3vonline 23 дня назад
Great video!
@joyraina
@joyraina Год назад
You content is good , please don't add stupid memes like that doing why action in between. I haven't seen other videos yet, so i don't know whether this was one off or not
@aboaliu657
@aboaliu657 Год назад
nice explain, love from iraq 🇮🇶
@EnglishRain
@EnglishRain Год назад
Great video subscribed! But please get rid of the music
@mattsionkowski
@mattsionkowski Год назад
Thank you. Yep, received a lot of feedback of music being too loud. Will get it better next time!
@m1cannas
@m1cannas 22 дня назад
😀
@aglimmerofhope5321
@aglimmerofhope5321 Год назад
Again wishing Mozilla was the backbone of Brave browser (instead of Chrome). Someone get on that please ... 😞 Saw this on reddit BTW. Good info. TY. :peace:
@mattsionkowski
@mattsionkowski Год назад
Chromium is a well managed project too. Yet we cannot undermine the continous positive impact Mozilla had on the shaping of browsers as whole. Now we see Mozilla being pushed aside. I'm not saying everyone should use firefox, but as it's loosing users - we're all loosing a very good player on the browsers scene. Some day other browsers will not have that competition. And such monopoly is never a good thing.
@aglimmerofhope5321
@aglimmerofhope5321 Год назад
@@mattsionkowski well said 👏
@NorthernChimp
@NorthernChimp Год назад
Nobody should be using a single browser for everything anyway. The fact that so many people do is concerning in itself.
Далее
Why This New CD Could Change Storage
14:42
Просмотров 1,1 млн
Browser Fingerprinting Explained (You're Tracked!)
19:48
Я ПОКУПАЮ НОВУЮ ТАЧКУ - МЕЧТУ!
39:05
Копия iPhone с WildBerries
01:00
Просмотров 5 млн
God-Tier Developer Roadmap
16:42
Просмотров 7 млн
Why VPNs are a WASTE of Your Money (usually…)
14:40
What is the Smallest Possible .EXE?
17:57
Просмотров 304 тыс.
The HACKER's Laptop #shorts
0:50
Просмотров 10 млн
Young People Try Windows 98
21:18
Просмотров 5 млн
A Tale of 14 Million Passwords - Rockyou
9:59
Просмотров 2,4 тыс.
Do you know this Gmail hack??
0:57
Просмотров 2,2 млн
Здесь упор в процессор
18:02
Просмотров 397 тыс.
Телефон-електрошокер
0:43
Просмотров 1,3 млн
Samsung laughing on iPhone #techbyakram
0:12
Просмотров 2,4 млн