In-Depth Evaluation of Redirect Tracking and Link Usage
In today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Sciendo
2020-10-01
|
Series: | Proceedings on Privacy Enhancing Technologies |
Subjects: | |
Online Access: | https://doi.org/10.2478/popets-2020-0079 |
id |
doaj-1e4403cbcd8141e792fac8c5f8ee2f8a |
---|---|
record_format |
Article |
spelling |
doaj-1e4403cbcd8141e792fac8c5f8ee2f8a2021-09-05T14:01:11ZengSciendoProceedings on Privacy Enhancing Technologies2299-09842020-10-012020439441310.2478/popets-2020-0079popets-2020-0079In-Depth Evaluation of Redirect Tracking and Link UsageKoop Martin0Tews Erik1Katzenbeisser Stefan2Universität PassauUniversity of TwenteUniversität PassauIn today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block third-party elements. However, there exist various tracking techniques that are not covered by those tools, such as redirect link tracking. Here, tracking is hidden in ordinary website links pointing to further content. By clicking those links, or by automatic URL redirects, the user is being redirected through a chain of potential tracking servers not visible to the user. In this scenario, the tracker collects valuable data about the content, topic, or user interests of the website. Additionally, the tracker sets not only thirdparty but also first-party tracking cookies which are far more difficult to block by browser settings and ad-block tools. Since the user is forced to follow the redirect, tracking is inevitable and a chain of (redirect) tracking servers gain more insights in the users’ behavior. In this work we present the first large scale study on the threat of redirect link tracking. By crawling the Alexa top 50k websites and following up to 34 page links, we recorded traces of HTTP requests from 1.2 million individual visits of websites as well as analyzed 108,435 redirect chains originating from links clicked on those websites. We evaluate the derived redirect network on its tracking ability and demonstrate that top trackers are able to identify the user on the most visited websites. We also show that 11.6% of the scanned websites use one of the top 100 redirectors which are able to store nonblocked first-party tracking cookies on users’ machines even when third-party cookies are disabled. Moreover, we present the effect of various browser cookie settings, resulting in a privacy loss even when using third-party blocking tools.https://doi.org/10.2478/popets-2020-0079trackingredirectprivacybrowser |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Koop Martin Tews Erik Katzenbeisser Stefan |
spellingShingle |
Koop Martin Tews Erik Katzenbeisser Stefan In-Depth Evaluation of Redirect Tracking and Link Usage Proceedings on Privacy Enhancing Technologies tracking redirect privacy browser |
author_facet |
Koop Martin Tews Erik Katzenbeisser Stefan |
author_sort |
Koop Martin |
title |
In-Depth Evaluation of Redirect Tracking and Link Usage |
title_short |
In-Depth Evaluation of Redirect Tracking and Link Usage |
title_full |
In-Depth Evaluation of Redirect Tracking and Link Usage |
title_fullStr |
In-Depth Evaluation of Redirect Tracking and Link Usage |
title_full_unstemmed |
In-Depth Evaluation of Redirect Tracking and Link Usage |
title_sort |
in-depth evaluation of redirect tracking and link usage |
publisher |
Sciendo |
series |
Proceedings on Privacy Enhancing Technologies |
issn |
2299-0984 |
publishDate |
2020-10-01 |
description |
In today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block third-party elements. However, there exist various tracking techniques that are not covered by those tools, such as redirect link tracking. Here, tracking is hidden in ordinary website links pointing to further content. By clicking those links, or by automatic URL redirects, the user is being redirected through a chain of potential tracking servers not visible to the user. In this scenario, the tracker collects valuable data about the content, topic, or user interests of the website. Additionally, the tracker sets not only thirdparty but also first-party tracking cookies which are far more difficult to block by browser settings and ad-block tools. Since the user is forced to follow the redirect, tracking is inevitable and a chain of (redirect) tracking servers gain more insights in the users’ behavior. In this work we present the first large scale study on the threat of redirect link tracking. By crawling the Alexa top 50k websites and following up to 34 page links, we recorded traces of HTTP requests from 1.2 million individual visits of websites as well as analyzed 108,435 redirect chains originating from links clicked on those websites. We evaluate the derived redirect network on its tracking ability and demonstrate that top trackers are able to identify the user on the most visited websites. We also show that 11.6% of the scanned websites use one of the top 100 redirectors which are able to store nonblocked first-party tracking cookies on users’ machines even when third-party cookies are disabled. Moreover, we present the effect of various browser cookie settings, resulting in a privacy loss even when using third-party blocking tools. |
topic |
tracking redirect privacy browser |
url |
https://doi.org/10.2478/popets-2020-0079 |
work_keys_str_mv |
AT koopmartin indepthevaluationofredirecttrackingandlinkusage AT tewserik indepthevaluationofredirecttrackingandlinkusage AT katzenbeisserstefan indepthevaluationofredirecttrackingandlinkusage |
_version_ |
1717810578297192448 |