Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Safari purged of decade-old browser history leak
The Register ^ | June 8, 2010 | By Dan Gooden

Posted on 06/08/2010 6:13:01 PM PDT by Swordmaker

Free at last.

Apple Safari has become the first major browser to be purged of one of the web's longest-running privacy defects: The ability for any site owner to effortlessly steal a complete copy of your recent browsing history.

The browser history disclosure leak is as old as the World Wide Web itself, and it afflicted every major browser – until now. Starting with versions released Monday, Safari no longer coughs up the list of websites a user has visited. The change is one of almost 50 security fixes Apple engineers added to versions 4.1 and 5.0 of the browser.

In characteristic Apple fashion, the company buried news of the change at the bottom of this page. We pointed the new Safari version at sites here and here, which exploit the weakness, and neither worked. The attacks succeeded just fine against Google Chrome and Firefox, and one of them succeeded even when Firefox was running the NoScript add-on.

According to the results of more than 271,000 visits captured in a recent study, the vast majority of people browsing the web are vulnerable to attacks that expose detailed information about their viewing habits, including news articles they've read and the Zip Codes they've entered into online forms. Surprisingly, the proportion was even higher for those using Safari and Chrome and among browsers that turned off JavaScript.

The history leak is the result of the same CSS, or cascading style sheet, technology that causes a browser to display links that have been visited in a different color than addresses that have not been visited. It also allows webmasters to customize content and user interfaces on their sites based on the links individual users regularly visit. Browser makers have long been aware that it can reveal potentially sensitive websites users visit, but have been reluctant to patch the hole for fear it will remove functionality people have come to depend on.

In April, Mozilla said it planned to fix the browser history leakage in an upcoming version of Firefox. While recent beta versions of the browser have the feature turned on, the latest production version remains wide open. Chrome and Internet Explorer are also vulnerable.

Because Safari is based on the same code base as Chrome, it wouldn't be surprising to see the latter browser fixed soon too. That will leave IE as the only major browser with no stated plans to fix the weakness. Microsoft has so far been tight-lipped about its plans, offering only half-baked work-arounds and the warning that browser fixes could break websites.

The history fix is by no means the only security improvement added to the latest version of Safari. The browser now ships with a filter designed to prevent XSS, or cross-site scripting, attacks from working. Microsoft introduced a similar feature to IE 8 and Firefox with NoScript achieves the same result. But as reported by the 0x0Lab Blog, Safari's implementation is easily bypassed. ®


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: apple; ilovebillgates; iwanthim; iwanthimbad; mac; microsoftfanboys; safari
Navigation: use the links below to view more comments.
first 1-2021-4041-44 next last

1 posted on 06/08/2010 6:13:02 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; 50mm; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ...
Safari 5 and updated Safari 4.1 are the first browsers to NOT reveal to anyone on demand your browsing history... PING!


Apple Safari 5 Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 06/08/2010 6:19:48 PM PDT by Swordmaker (Remember, the proper pronunciation of IE isAAAAIIIIIEEEEEEE!Apple could simply require that any iPho)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
The ability for any site owner to effortlessly steal a complete copy of your recent browsing history.

Can it be done with GoDaddy's "Website Tonight"? How do I do it? Its not really "stealing" is it?

3 posted on 06/08/2010 6:22:16 PM PDT by Brugmansian
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Safari 5 and updated Safari 4.1 are the first browsers to NOT reveal to anyone on demand your browsing history... PING!

Now that is newsworthy, Swordmaker, and thanks for the
Image Hosted by ImageShack.us !

4 posted on 06/08/2010 6:28:46 PM PDT by vox_freedom (America is being tested as never before in its history. May God help us.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

And why doesn’t Firefox do the same???


5 posted on 06/08/2010 6:29:49 PM PDT by vox_freedom (America is being tested as never before in its history. May God help us.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

Just installed Safari 5 last night and I love it. It is faster loading than my other browsers and speed is important.


6 posted on 06/08/2010 6:31:27 PM PDT by rj45mis
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

7 posted on 06/08/2010 6:33:21 PM PDT by JoeProBono (A closed mouth gathers no feet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: vox_freedom

From the article: “In April, Mozilla said it planned to fix the browser history leakage in an upcoming version of Firefox.”


8 posted on 06/08/2010 6:42:13 PM PDT by BullDog108 (A Smith & Wesson beats four aces)
[ Post Reply | Private Reply | To 5 | View Replies]

To: vox_freedom
And why doesn’t Firefox do the same???

The Firefox team will fix this eventually. I would think fairly soon now that Safari has fixed it. But writing software is a complex task, and programming teams have to set priorities. This bug will work itself to the top of the list at some point.

9 posted on 06/08/2010 6:46:57 PM PDT by stripes1776 ("That if gold rust, what shall iron do?" --Chaucer)
[ Post Reply | Private Reply | To 5 | View Replies]

To: BullDog108

Thanks BullDog108. Saw that, but hope it is sooner rather than later...


10 posted on 06/08/2010 6:53:09 PM PDT by vox_freedom (America is being tested as never before in its history. May God help us.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: stripes1776

Appreciate the response and this should be on the top of the Firefox list — since it is “consumer first” issue.


11 posted on 06/08/2010 6:54:16 PM PDT by vox_freedom (America is being tested as never before in its history. May God help us.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Swordmaker

I loaded Safari 5 last night and have been using it almost exclusively .

I like it. Just wish they would expand the font size selection.


12 posted on 06/08/2010 7:05:53 PM PDT by Vinnie (You're Nobody 'Til Somebody Jihads You)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

I loaded Safari 5 last night and have been using it almost exclusively .

I like it.
Just wish they would expand the font size selection.
Going from Times New Roman 18 to 24 is too big of a jump.


13 posted on 06/08/2010 7:08:14 PM PDT by Vinnie (You're Nobody 'Til Somebody Jihads You)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rj45mis
Just installed Safari 5 last night and I love it. It is faster loading than my other browsers and speed is important.

I've installed it on my MacBook Pro and my Dell PC. Seems to be impressive in speed. I had been using Chrome, but now intend to go to Safari 5.

14 posted on 06/08/2010 7:09:52 PM PDT by Ole Okie
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker

I tried Safari 5 today. Whoa, that thing is fast. And the Reader!! If you’re trying to read an article on some site festooned with ads and junk, and with the article spread over several pages to boost the site’s hit-count, just click the “Reader” button that pops up next to the URL. And: up slides a page with just the text and links— no ads! And the whole article will be there, automatically stitched-together instead of requiring you to click link after link to get the whole article. Really useful.

It’s free for Windows and Mac: http://www.apple.com/safari/whats-new.html


15 posted on 06/08/2010 7:28:02 PM PDT by RightOnTheLeftCoast (Obama: running for re-election in '12 or running for Mahdi now? [http://en.wikipedia.org/wiki/Mahdi])
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thanks for the news.

I installed Safari 5 last night, and have run into a strange problem today.

When I follow a link from FR to any other publication, I can no longer use either the red button or the black < to return to FR. Also, History will take me back to the same thread on FR, but won’t let me finish reading that thread and push < to continue on that page. It’s been driving me nuts all day because I keep losing where I was.


16 posted on 06/08/2010 7:29:32 PM PDT by kitkat (OBAMA hates us. Well, maybe a LOT of Kenyans do.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ole Okie
"I had been using Chrome, but now intend to go to Safari 5."

Smart choice. The fact that Google has merged the URL and search fields in Chrome means all your URLs are potentially being fed to Google. I don't trust 'em.
17 posted on 06/08/2010 7:29:46 PM PDT by RightOnTheLeftCoast (Obama: running for re-election in '12 or running for Mahdi now? [http://en.wikipedia.org/wiki/Mahdi])
[ Post Reply | Private Reply | To 14 | View Replies]

To: Swordmaker

Anyone using either the update or 5 yet? Any problems? I usually wait to see what happens to others befoe downloading.


18 posted on 06/08/2010 8:09:03 PM PDT by chris_bdba
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thank God they have stopped the leak. Ever since I visited that porn site good looking women have been knocking on my door. Maybe now I can get some sleep!


19 posted on 06/08/2010 8:09:21 PM PDT by Mind-numbed Robot (Not all that needs to be done needs to be done by the government)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vinnie
I like it. Just wish they would expand the font size selection.

I might be misunderstanding the problem, but you can select 'Preferences' under the 'Safari' menu item, then click the 'Appearance' tab. This shows the standard font used on web pages (unless pages set their own font, which many do via CSS). You can then change the default to a font and size of your choice.

Another option which you might find useful is to use the 'zoom in' and 'zoom out' functions under the 'View' menu to scale up or scale down a web page. To make this more convenient, you can add the 'zoom' icons to the toolbar by going to 'customize toolbar' under the 'view' menu.

20 posted on 06/08/2010 8:22:00 PM PDT by 6SJ7 (atlasShruggedInd = TRUE)
[ Post Reply | Private Reply | To 12 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-44 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson