In-Depth Evaluation of Redirect Tracking and Link Usage

In today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block...

Full description

Bibliographic Details
Main Authors: Koop Martin, Tews Erik, Katzenbeisser Stefan
Format: Article
Language:English
Published: Sciendo 2020-10-01
Series:Proceedings on Privacy Enhancing Technologies
Subjects:
Online Access:https://doi.org/10.2478/popets-2020-0079
id doaj-1e4403cbcd8141e792fac8c5f8ee2f8a
record_format Article
spelling doaj-1e4403cbcd8141e792fac8c5f8ee2f8a2021-09-05T14:01:11ZengSciendoProceedings on Privacy Enhancing Technologies2299-09842020-10-012020439441310.2478/popets-2020-0079popets-2020-0079In-Depth Evaluation of Redirect Tracking and Link UsageKoop Martin0Tews Erik1Katzenbeisser Stefan2Universität PassauUniversity of TwenteUniversität PassauIn today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block third-party elements. However, there exist various tracking techniques that are not covered by those tools, such as redirect link tracking. Here, tracking is hidden in ordinary website links pointing to further content. By clicking those links, or by automatic URL redirects, the user is being redirected through a chain of potential tracking servers not visible to the user. In this scenario, the tracker collects valuable data about the content, topic, or user interests of the website. Additionally, the tracker sets not only thirdparty but also first-party tracking cookies which are far more difficult to block by browser settings and ad-block tools. Since the user is forced to follow the redirect, tracking is inevitable and a chain of (redirect) tracking servers gain more insights in the users’ behavior. In this work we present the first large scale study on the threat of redirect link tracking. By crawling the Alexa top 50k websites and following up to 34 page links, we recorded traces of HTTP requests from 1.2 million individual visits of websites as well as analyzed 108,435 redirect chains originating from links clicked on those websites. We evaluate the derived redirect network on its tracking ability and demonstrate that top trackers are able to identify the user on the most visited websites. We also show that 11.6% of the scanned websites use one of the top 100 redirectors which are able to store nonblocked first-party tracking cookies on users’ machines even when third-party cookies are disabled. Moreover, we present the effect of various browser cookie settings, resulting in a privacy loss even when using third-party blocking tools.https://doi.org/10.2478/popets-2020-0079trackingredirectprivacybrowser
collection DOAJ
language English
format Article
sources DOAJ
author Koop Martin
Tews Erik
Katzenbeisser Stefan
spellingShingle Koop Martin
Tews Erik
Katzenbeisser Stefan
In-Depth Evaluation of Redirect Tracking and Link Usage
Proceedings on Privacy Enhancing Technologies
tracking
redirect
privacy
browser
author_facet Koop Martin
Tews Erik
Katzenbeisser Stefan
author_sort Koop Martin
title In-Depth Evaluation of Redirect Tracking and Link Usage
title_short In-Depth Evaluation of Redirect Tracking and Link Usage
title_full In-Depth Evaluation of Redirect Tracking and Link Usage
title_fullStr In-Depth Evaluation of Redirect Tracking and Link Usage
title_full_unstemmed In-Depth Evaluation of Redirect Tracking and Link Usage
title_sort in-depth evaluation of redirect tracking and link usage
publisher Sciendo
series Proceedings on Privacy Enhancing Technologies
issn 2299-0984
publishDate 2020-10-01
description In today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block third-party elements. However, there exist various tracking techniques that are not covered by those tools, such as redirect link tracking. Here, tracking is hidden in ordinary website links pointing to further content. By clicking those links, or by automatic URL redirects, the user is being redirected through a chain of potential tracking servers not visible to the user. In this scenario, the tracker collects valuable data about the content, topic, or user interests of the website. Additionally, the tracker sets not only thirdparty but also first-party tracking cookies which are far more difficult to block by browser settings and ad-block tools. Since the user is forced to follow the redirect, tracking is inevitable and a chain of (redirect) tracking servers gain more insights in the users’ behavior. In this work we present the first large scale study on the threat of redirect link tracking. By crawling the Alexa top 50k websites and following up to 34 page links, we recorded traces of HTTP requests from 1.2 million individual visits of websites as well as analyzed 108,435 redirect chains originating from links clicked on those websites. We evaluate the derived redirect network on its tracking ability and demonstrate that top trackers are able to identify the user on the most visited websites. We also show that 11.6% of the scanned websites use one of the top 100 redirectors which are able to store nonblocked first-party tracking cookies on users’ machines even when third-party cookies are disabled. Moreover, we present the effect of various browser cookie settings, resulting in a privacy loss even when using third-party blocking tools.
topic tracking
redirect
privacy
browser
url https://doi.org/10.2478/popets-2020-0079
work_keys_str_mv AT koopmartin indepthevaluationofredirecttrackingandlinkusage
AT tewserik indepthevaluationofredirecttrackingandlinkusage
AT katzenbeisserstefan indepthevaluationofredirecttrackingandlinkusage
_version_ 1717810578297192448