Feeds

Safari purged of decade-old browser history leak

Free at last

The essential guide to IT transformation

Apple Safari has become the first major browser to be purged of one of the web's longest-running privacy defects: The ability for any site owner to effortlessly steal a complete copy of your recent browsing history.

The browser history disclosure leak is as old as the World Wide Web itself, and it afflicted every major browser – until now. Starting with versions released Monday, Safari no longer coughs up the list of websites a user has visited. The change is one of almost 50 security fixes Apple engineers added to versions 4.1 and 5.0 of the browser.

In characteristic Apple fashion, the company buried news of the change at the bottom of this page. We pointed the new Safari version at sites here and here, which exploit the weakness, and neither worked. The attacks succeeded just fine against Google Chrome and Firefox, and one of them succeeded even when Firefox was running the NoScript add-on.

According to the results of more than 271,000 visits captured in a recent study, the vast majority of people browsing the web are vulnerable to attacks that expose detailed information about their viewing habits, including news articles they've read and the Zip Codes they've entered into online forms. Surprisingly, the proportion was even higher for those using Safari and Chrome and among browsers that turned off JavaScript.

The history leak is the result of the same CSS, or cascading style sheet, technology that causes a browser to display links that have been visited in a different color than addresses that have not been visited. It also allows webmasters to customize content and user interfaces on their sites based on the links individual users regularly visit. Browser makers have long been aware that it can reveal potentially sensitive websites users visit, but have been reluctant to patch the hole for fear it will remove functionality people have come to depend on.

In April, Mozilla said it planned to fix the browser history leakage in an upcoming version of Firefox. While recent beta versions of the browser have the feature turned on, the latest production version remains wide open. Chrome and Internet Explorer are also vulnerable.

Because Safari is based on the same code base as Chrome, it wouldn't be surprising to see the latter browser fixed soon too. That will leave IE as the only major browser with no stated plans to fix the weakness. Microsoft has so far been tight-lipped about its plans, offering only half-baked work-arounds and the warning that browser fixes could break websites.

The history fix is by no means the only security improvement added to the latest version of Safari. The browser now ships with a filter designed to prevent XSS, or cross-site scripting, attacks from working. Microsoft introduced a similar feature to IE 8 and Firefox with NoScript achieves the same result. But as reported by the 0x0Lab Blog, Safari's implementation is easily bypassed. ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?