{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,12]],"date-time":"2025-07-12T01:29:31Z","timestamp":1752283771438,"version":"3.41.0"},"reference-count":73,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T00:00:00Z","timestamp":1608595200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Basque Government under a pre-doctoral grant given to Iskander Sanchez-Rola"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2020,12,31]]},"abstract":"<jats:p>Cookies were originally introduced as a way to provide state awareness to websites, and they are now one of the backbones of the current web. However, their use is not limited to store the login information or to save the current state of user browsing. In several cases, third-party cookies are deliberately used for web tracking, user analytics, and for online advertisement, with the subsequent privacy loss for the end-users.<\/jats:p>\n          <jats:p>\n            However, cookies are not the only technique capable of retrieving the users\u2019 browsing history. In fact,\n            <jats:italic>history sniffing<\/jats:italic>\n            techniques are capable of tracking the users\u2019 browsing history without relying on any specific code in a third-party website, but only on code executed within the visited site. Many sniffing techniques have been proposed to date, but they usually have several limitations, and they are not able to differentiate between multiple possible states within the target application.\n          <\/jats:p>\n          <jats:p>\n            We propose B\n            <jats:sc>aking<\/jats:sc>\n            T\n            <jats:sc>imer<\/jats:sc>\n            , a new history-sniffing technique based on timing the execution of server-side request processing code. This method is capable of retrieving partial or complete user browsing history, it does not require any permission, and it can be performed through both first- and third-party scripts. We studied the impact of our timing side-channel attack to detect prior visits to websites and discovered that it was capable of detecting the users\u2019 state in more than half of the 10K websites analyzed, which is the largest test performed to date to test this type of technique. We additionally performed a manual analysis to check the capabilities of the attack to differentiate between three states: never accessed, accessed, and logged in. Moreover, we performed a set of stability tests to verify that our time measurements are robust with respect to changes both in the network RTT and in the servers workload. This extended version additionally includes a comprehensive analysis of existing countermeasures, starting from its evolution\/adoption, and finishing with a large-scale experiment to asset the repercussions on the presented technique.\n          <\/jats:p>","DOI":"10.1145\/3419473","type":"journal-article","created":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T22:11:26Z","timestamp":1608675086000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Cookies from the Past"],"prefix":"10.1145","volume":"1","author":[{"given":"Iskander","family":"Sanchez-Rola","sequence":"first","affiliation":[{"name":"University of Deusto and NortonLifeLock Research Group, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor","family":"Santos","sequence":"additional","affiliation":[{"name":"University of Deusto and Mondragon University, Arrasate, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,12,22]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201913)","author":"Acar Gunes","year":"2013","unstructured":"Gunes Acar , Marc Juarez , Nick Nikiforakis , Claudia Diaz , Seda G\u00fcrses , Frank Piessens , and Bart Preneel . 2013 . FPDetective: Dusting the web for fingerprinters . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201913) . Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Diaz, Seda G\u00fcrses, Frank Piessens, and Bart Preneel. 2013. FPDetective: Dusting the web for fingerprinters. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201913)."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CSS\u201912)","author":"Akkus Istemi Ekin","year":"2012","unstructured":"Istemi Ekin Akkus , Ruichuan Chen , Michaela Hardt , Paul Francis , and Johannes Gehrke . 2012 . Non-tracking web analytics . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CSS\u201912) . Istemi Ekin Akkus, Ruichuan Chen, Michaela Hardt, Paul Francis, and Johannes Gehrke. 2012. Non-tracking web analytics. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CSS\u201912)."},{"key":"e_1_2_1_3_1","unstructured":"Amazon Web Services. 2018. Alexa Top Sites. Retrieved from https:\/\/aws.amazon.com\/es\/alexa-top-sites\/.  Amazon Web Services. 2018. Alexa Top Sites. Retrieved from https:\/\/aws.amazon.com\/es\/alexa-top-sites\/."},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Backes Michael","year":"2012","unstructured":"Michael Backes , Aniket Kate , Matteo Maffei , and Kim Pecina . 2012 . Obliviad: Provably secure and practical online behavioral advertising . In Proceedings of the IEEE Symposium on Security and Privacy. Michael Backes, Aniket Kate, Matteo Maffei, and Kim Pecina. 2012. Obliviad: Provably secure and practical online behavioral advertising. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the Privacy Enhancing Technologies Symposium (PETS\u201911)","author":"Bilenko Mikhail","year":"2011","unstructured":"Mikhail Bilenko , Matthew Richardson , and Janice Tsai . 2011 . Targeted, not tracked: Client-side solutions for privacy-friendly behavioral advertising . In Proceedings of the Privacy Enhancing Technologies Symposium (PETS\u201911) . Mikhail Bilenko, Matthew Richardson, and Janice Tsai. 2011. Targeted, not tracked: Client-side solutions for privacy-friendly behavioral advertising. In Proceedings of the Privacy Enhancing Technologies Symposium (PETS\u201911)."},{"key":"e_1_2_1_6_1","unstructured":"Blocksi. 2018. Web content filtering. Retrieved from http:\/\/www.blocksi.net\/.  Blocksi. 2018. Web content filtering. Retrieved from http:\/\/www.blocksi.net\/."},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the International Conference on World Wide Web (WWW\u201907)","author":"Bortz Andrew","year":"2007","unstructured":"Andrew Bortz and Dan Boneh . 2007 . Exposing private information by timing web applications . In Proceedings of the International Conference on World Wide Web (WWW\u201907) . Andrew Bortz and Dan Boneh. 2007. Exposing private information by timing web applications. In Proceedings of the International Conference on World Wide Web (WWW\u201907)."},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the Network and Distributed System Symposium (NDSS\u201917)","author":"Cao Yinzhi","year":"2017","unstructured":"Yinzhi Cao , Song Li , and Erik Wijmans . 2017 . (Cross-)browser fingerprinting via OS and hardware level features . In Proceedings of the Network and Distributed System Symposium (NDSS\u201917) . Yinzhi Cao, Song Li, and Erik Wijmans. 2017. (Cross-)browser fingerprinting via OS and hardware level features. In Proceedings of the Network and Distributed System Symposium (NDSS\u201917)."},{"key":"e_1_2_1_9_1","unstructured":"ChromeDevTools. 2019. DevTools Protocol API. Retrieved from https:\/\/github.com\/ChromeDevTools\/debugger-protocol-viewer.  ChromeDevTools. 2019. DevTools Protocol API. Retrieved from https:\/\/github.com\/ChromeDevTools\/debugger-protocol-viewer."},{"key":"e_1_2_1_10_1","unstructured":"Chromium Blog. 2016. Chrome 51 Beta: Credential Management API and reducing the overhead of offscreen rendering. Retrieved from https:\/\/blog.chromium.org\/2016\/04\/chrome-51-beta-credential-management.html.  Chromium Blog. 2016. Chrome 51 Beta: Credential Management API and reducing the overhead of offscreen rendering. Retrieved from https:\/\/blog.chromium.org\/2016\/04\/chrome-51-beta-credential-management.html."},{"key":"e_1_2_1_11_1","unstructured":"Chromium Blog. 2020. Temporarily rolling back SameSite Cookie Changes. Retrieved from https:\/\/blog.chromium.org\/2020\/04\/temporarily-rolling-back-samesite.html.  Chromium Blog. 2020. Temporarily rolling back SameSite Cookie Changes. Retrieved from https:\/\/blog.chromium.org\/2020\/04\/temporarily-rolling-back-samesite.html."},{"key":"e_1_2_1_12_1","first-page":"2019","volume":"201","unstructured":"Cisco Adaptive Security Appliance. 201 9. CVE- 2019 - 1713 . Retrieved from https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2019-1713. Cisco Adaptive Security Appliance. 2019. CVE-2019-1713. Retrieved from https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2019-1713.","journal-title":"Cisco Adaptive Security Appliance."},{"key":"e_1_2_1_13_1","unstructured":"Cisco Umbrella. 2019. Umbrella Popularity List.Retrieved from https:\/\/umbrella-static.s3-us-west-1.amazonaws.com\/index.html.  Cisco Umbrella. 2019. Umbrella Popularity List.Retrieved from https:\/\/umbrella-static.s3-us-west-1.amazonaws.com\/index.html."},{"key":"e_1_2_1_14_1","unstructured":"Cloudacl. 2018. Web security service. Retrieved from http:\/\/www.cloudacl.com\/.  Cloudacl. 2018. Web security service. Retrieved from http:\/\/www.cloudacl.com\/."},{"key":"e_1_2_1_15_1","volume-title":"CSS visited","author":"Clover Andrew","year":"2002","unstructured":"Andrew Clover . 2002. CSS visited pages disclosure. BUGTRAQ Mailing List Posting ( 2002 ). https:\/\/lists.w3.org\/Archives\/Public\/www-style\/2002Feb\/0039.html. Andrew Clover. 2002. CSS visited pages disclosure. BUGTRAQ Mailing List Posting (2002). https:\/\/lists.w3.org\/Archives\/Public\/www-style\/2002Feb\/0039.html."},{"key":"e_1_2_1_16_1","unstructured":"Dymo. 2017. Missing Accept_languages in Request for Headless Mode. Retrieved from https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id&equals;775911.  Dymo. 2017. Missing Accept_languages in Request for Headless Mode. Retrieved from https:\/\/bugs.chromium.org\/p\/chromium\/issues\/detail?id&equals;775911."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978313"},{"key":"e_1_2_1_18_1","unstructured":"2009. \n      Directive\n       2009\/136\/EC of the European parliament and of the council of 25 November 2009. \n      Off\n    . \n      J.\n      Eur\n    . Union\n   (\n  2009\n  ). Retrieved from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri&equals;celex:32009L0136.  2009. Directive 2009\/136\/EC of the European parliament and of the council of 25 November 2009. Off. J. Eur. Union (2009). Retrieved from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri&equals;celex:32009L0136."},{"key":"e_1_2_1_19_1","unstructured":"2016. \n      Regulation\n     (EU) 2016\/679 of the European parliament and of the council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing \n      Directive\n       95\/46\/EC (\n      General Data Protection\n     Regulation). Off. \n      J.\n      Eur\n    . Union\n   (\n  2016\n  ). Retrieved from http:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri&equals;OJ:L:2016:119:TOC.  2016. Regulation (EU) 2016\/679 of the European parliament and of the council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). Off. J. Eur. Union (2016). Retrieved from http:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri&equals;OJ:L:2016:119:TOC."},{"volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201900)","author":"Edward","key":"e_1_2_1_20_1","unstructured":"Edward W. Felten and Michael A. Schneider. 2000. Timing attacks on web privacy . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201900) . Edward W. Felten and Michael A. Schneider. 2000. Timing attacks on web privacy. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201900)."},{"key":"e_1_2_1_21_1","unstructured":"Fortinet. 2018. FortiGuard web filtering. Retrieved from http:\/\/www.fortiguard.com\/.  Fortinet. 2018. FortiGuard web filtering. Retrieved from http:\/\/www.fortiguard.com\/."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Fredrikson Matthew","year":"2011","unstructured":"Matthew Fredrikson and Benjamin Livshits . 2011 . RePriv: Re-imagining content personalization and in-browser privacy . In Proceedings of the IEEE Symposium on Security and Privacy. Matthew Fredrikson and Benjamin Livshits. 2011. RePriv: Re-imagining content personalization and in-browser privacy. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_23_1","unstructured":"Google. 2018. Leak of visited status of page in Blink. Retrieved from https:\/\/chromereleases.googleblog.com\/2018\/05\/stable-channel-update-for-desktop_58.html.  Google. 2018. Leak of visited status of page in Blink. Retrieved from https:\/\/chromereleases.googleblog.com\/2018\/05\/stable-channel-update-for-desktop_58.html."},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the USENIX Conference on Networked Systems Design and Implementation (NDSI\u201911)","author":"Guha Saikat","year":"2011","unstructured":"Saikat Guha , Bin Cheng , and Paul Francis . 2011 . Privad: Practical privacy in online advertising . In Proceedings of the USENIX Conference on Networked Systems Design and Implementation (NDSI\u201911) . Saikat Guha, Bin Cheng, and Paul Francis. 2011. Privad: Practical privacy in online advertising. In Proceedings of the USENIX Conference on Networked Systems Design and Implementation (NDSI\u201911)."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CSS\u201912)","author":"Heiderich Mario","year":"2012","unstructured":"Mario Heiderich , Marcus Niemietz , Felix Schuster , Thorsten Holz , and J\u00f6rg Schwenk . 2012 . Scriptless attacks: Stealing the pie without touching the sill . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CSS\u201912) . Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz, and J\u00f6rg Schwenk. 2012. Scriptless attacks: Stealing the pie without touching the sill. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CSS\u201912)."},{"key":"e_1_2_1_26_1","unstructured":"HTTPbis Working Group. 2016. Same-site Cookies (draft-west-first-party-cookies-05). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-first-party-cookies-05#section-4.1.  HTTPbis Working Group. 2016. Same-site Cookies (draft-west-first-party-cookies-05). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-first-party-cookies-05#section-4.1."},{"key":"e_1_2_1_27_1","unstructured":"HTTPbis Working Group. 2016. Same-site Cookies (draft-west-first-party-cookies-06). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-first-party-cookies-06#section-4.1.  HTTPbis Working Group. 2016. Same-site Cookies (draft-west-first-party-cookies-06). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-first-party-cookies-06#section-4.1."},{"key":"e_1_2_1_28_1","unstructured":"HTTPbis Working Group. 2016. Same-site Cookies (draft-west-first-party-cookies-07). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-first-party-cookies-07#section-4.1.  HTTPbis Working Group. 2016. Same-site Cookies (draft-west-first-party-cookies-07). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-first-party-cookies-07#section-4.1."},{"key":"e_1_2_1_29_1","unstructured":"Internet Engineering Task Force. 2016. HTTP State Management Mechanism. Retrieved from https:\/\/tools.ietf.org\/html\/rfc6265.  Internet Engineering Task Force. 2016. HTTP State Management Mechanism. Retrieved from https:\/\/tools.ietf.org\/html\/rfc6265."},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the European Symposium on Research in Computer Security (ESORICS\u201910)","author":"Janc Artur","year":"2010","unstructured":"Artur Janc and Lukasz Olejnik . 2010 . Web browser history detection as a real-world privacy threat . In Proceedings of the European Symposium on Research in Computer Security (ESORICS\u201910) . Artur Janc and Lukasz Olejnik. 2010. Web browser history detection as a real-world privacy threat. In Proceedings of the European Symposium on Research in Computer Security (ESORICS\u201910)."},{"key":"e_1_2_1_31_1","volume-title":"I know where you\u2019ve been: Geo-inference attacks via the browser cache","author":"Jia Yaoqi","year":"2015","unstructured":"Yaoqi Jia , Xinshu Dong , Zhenkai Liang , and Prateek Saxena . 2015. I know where you\u2019ve been: Geo-inference attacks via the browser cache . IEEE Internet Comput . 19 ( 2015 ). Yaoqi Jia, Xinshu Dong, Zhenkai Liang, and Prateek Saxena. 2015. I know where you\u2019ve been: Geo-inference attacks via the browser cache. IEEE Internet Comput. 19 (2015)."},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201913)","author":"Kotcher Robert","year":"2013","unstructured":"Robert Kotcher , Yutong Pei , Pranjal Jumde , and Collin Jackson . 2013 . Cross-origin pixel stealing: Timing attacks using CSS filters . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201913) . Robert Kotcher, Yutong Pei, Pranjal Jumde, and Collin Jackson. 2013. Cross-origin pixel stealing: Timing attacks using CSS filters. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201913)."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.57"},{"key":"e_1_2_1_34_1","unstructured":"Issie Lapowsky. 2018. California Unanimously Passes Historic Privacy Bill. Wired. Retrieved from https:\/\/www.wired.com\/story\/california-unanimously-passes- historic-privacy-bill.  Issie Lapowsky. 2018. California Unanimously Passes Historic Privacy Bill. Wired. Retrieved from https:\/\/www.wired.com\/story\/california-unanimously-passes- historic-privacy-bill."},{"key":"e_1_2_1_35_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201919)","author":"Pochat Victor Le","year":"2019","unstructured":"Victor Le Pochat , Tom Van Goethem , Samaneh Tajalizadehkhoob , Maciej Korczy\u0144ski , and Wouter Joosen . 2019 . Tranco: A research-oriented top sites ranking hardened against manipulation . In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201919) . Victor Le Pochat, Tom Van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczy\u0144ski, and Wouter Joosen. 2019. Tranco: A research-oriented top sites ranking hardened against manipulation. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201919)."},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the Network and Distributed System Symposium (NDSS\u201915)","author":"Lee Sangho","year":"2015","unstructured":"Sangho Lee , Hyungsub Kim , and Jong Kim . 2015 . Identifying cross-origin resource status using application cache . In Proceedings of the Network and Distributed System Symposium (NDSS\u201915) . Sangho Lee, Hyungsub Kim, and Jong Kim. 2015. Identifying cross-origin resource status using application cache. In Proceedings of the Network and Distributed System Symposium (NDSS\u201915)."},{"key":"e_1_2_1_37_1","unstructured":"Majestic. 2019. The Majestic Million.Retrieved from https:\/\/majestic.com\/reports\/majestic-million.  Majestic. 2019. The Majestic Million.Retrieved from https:\/\/majestic.com\/reports\/majestic-million."},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the Web 2.0 Workshop on Security and Privacy (W2SP\u201912)","author":"Mowery Keaton","year":"2012","unstructured":"Keaton Mowery and Hovav Shacham . 2012 . Pixel perfect: Fingerprinting canvas in HTML5 . In Proceedings of the Web 2.0 Workshop on Security and Privacy (W2SP\u201912) . Keaton Mowery and Hovav Shacham. 2012. Pixel perfect: Fingerprinting canvas in HTML5. In Proceedings of the Web 2.0 Workshop on Security and Privacy (W2SP\u201912)."},{"key":"e_1_2_1_39_1","unstructured":"Mozilla. 2007. Public Suffix List. Retrieved from https:\/\/publicsuffix.org\/.  Mozilla. 2007. Public Suffix List. Retrieved from https:\/\/publicsuffix.org\/."},{"key":"e_1_2_1_40_1","unstructured":"Mozilla. 2018. Privacy and the :visited selector. Retrieved from https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/CSS\/Privacy_and_the_:visited_selector.  Mozilla. 2018. Privacy and the :visited selector. Retrieved from https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/CSS\/Privacy_and_the_:visited_selector."},{"key":"e_1_2_1_41_1","unstructured":"Mozilla Bugzilla. 2019. Enable sameSite&equals;lax by default on Nightly. Retrieved from https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id&equals;1604212.  Mozilla Bugzilla. 2019. Enable sameSite&equals;lax by default on Nightly. Retrieved from https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id&equals;1604212."},{"key":"e_1_2_1_42_1","unstructured":"Mozilla Bugzilla. 2019. Implement sameSite lax-by-default 2 minutes tolerance for unsafe methods. Retrieved from https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id&equals;1608384.  Mozilla Bugzilla. 2019. Implement sameSite lax-by-default 2 minutes tolerance for unsafe methods. Retrieved from https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id&equals;1608384."},{"key":"e_1_2_1_43_1","unstructured":"Mozilla Security Blog. 2018. Supporting Same-Site Cookies in Firefox 60. Retrieved from https:\/\/blog.mozilla.org\/security\/2018\/04\/24\/same-site-cookies-in-firefox-60\/.  Mozilla Security Blog. 2018. Supporting Same-Site Cookies in Firefox 60. Retrieved from https:\/\/blog.mozilla.org\/security\/2018\/04\/24\/same-site-cookies-in-firefox-60\/."},{"key":"e_1_2_1_44_1","unstructured":"Network Working Group. 2019. HTTP State Tokens (draft-west-http-state-tokens-00). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-http-state-tokens-00.  Network Working Group. 2019. HTTP State Tokens (draft-west-http-state-tokens-00). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-http-state-tokens-00."},{"key":"e_1_2_1_45_1","unstructured":"Network Working Group. 2019. Incrementally Better Cookies (draft-west-cookie-incrementalism-00). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-cookie-incrementalism-00#section-3.1.  Network Working Group. 2019. Incrementally Better Cookies (draft-west-cookie-incrementalism-00). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-cookie-incrementalism-00#section-3.1."},{"key":"e_1_2_1_46_1","unstructured":"Network Working Group. 2020. Incrementally Better Cookies (draft-west-cookie-incrementalism-01). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-cookie-incrementalism-01#section-3.1.  Network Working Group. 2020. Incrementally Better Cookies (draft-west-cookie-incrementalism-01). Retrieved from https:\/\/tools.ietf.org\/html\/draft-west-cookie-incrementalism-01#section-3.1."},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of IEEE Symposium on Security and Privacy.","author":"Nikiforakis Nick","year":"2013","unstructured":"Nick Nikiforakis , Alexandros Kapravelos , Wouter Joosen , Christopher Kruegel , Frank Piessens , and Giovanni Vigna . 2013 . Cookieless monster: Exploring the ecosystem of web-based device fingerprinting . In Proceedings of IEEE Symposium on Security and Privacy. Nick Nikiforakis, Alexandros Kapravelos, Wouter Joosen, Christopher Kruegel, Frank Piessens, and Giovanni Vigna. 2013. Cookieless monster: Exploring the ecosystem of web-based device fingerprinting. In Proceedings of IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_48_1","first-page":"2019","volume":"201","unstructured":"php MyAdmin. 201 9. CVE- 2019 - 12616 . Retrieved from http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2019-12616. phpMyAdmin. 2019. CVE-2019-12616. Retrieved from http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name&equals;CVE-2019-12616.","journal-title":"MyAdmin."},{"key":"e_1_2_1_49_1","unstructured":"Quantcast. 2019. Audience Insights That Help You Tell Better Stories. Retrieved from https:\/\/www.quantcast.com\/top-sites\/.  Quantcast. 2019. Audience Insights That Help You Tell Better Stories. Retrieved from https:\/\/www.quantcast.com\/top-sites\/."},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the World Wide Web Conference (WWW\u201920)","author":"Sanchez-Rola Iskander","year":"2020","unstructured":"Iskander Sanchez-Rola , Davide Balzarotti , Christopher Kruegel , Giovanni Vigna , and Igor Santos . 2020 . Dirty clicks: A study of the usability and security implications of click-related behaviors on the web . In Proceedings of the World Wide Web Conference (WWW\u201920) . Iskander Sanchez-Rola, Davide Balzarotti, Christopher Kruegel, Giovanni Vigna, and Igor Santos. 2020. Dirty clicks: A study of the usability and security implications of click-related behaviors on the web. In Proceedings of the World Wide Web Conference (WWW\u201920)."},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the Computer Security Applications Conference (ACSAC\u201919)","author":"Sanchez-Rola Iskander","year":"2019","unstructured":"Iskander Sanchez-Rola , Davide Balzarotti , and Igor Santos . 2019 . BakingTimer: Privacy analysis of server-side request processing time . In Proceedings of the Computer Security Applications Conference (ACSAC\u201919) . Iskander Sanchez-Rola, Davide Balzarotti, and Igor Santos. 2019. BakingTimer: Privacy analysis of server-side request processing time. In Proceedings of the Computer Security Applications Conference (ACSAC\u201919)."},{"key":"e_1_2_1_52_1","volume-title":"Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS\u201919)","author":"Sanchez-Rola Iskander","year":"2019","unstructured":"Iskander Sanchez-Rola , Matteo Dell\u2019Amico , Platon Kotzias , Davide Balzarotti , Leyla Bilge , Pierre-Antoine Vervier , and Igor Santos . 2019 . Can I opt out yet? GDPR and the global illusion of cookie control . In Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS\u201919) . Iskander Sanchez-Rola, Matteo Dell\u2019Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, and Igor Santos. 2019. Can I opt out yet? GDPR and the global illusion of cookie control. In Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS\u201919)."},{"key":"e_1_2_1_53_1","volume-title":"Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201918)","author":"Sanchez-Rola Iskander","year":"2018","unstructured":"Iskander Sanchez-Rola and Igor Santos . 2018 . Knockin\u2019 on trackers\u2019 door: Large-scale automatic analysis of web tracking . In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201918) . Iskander Sanchez-Rola and Igor Santos. 2018. Knockin\u2019 on trackers\u2019 door: Large-scale automatic analysis of web tracking. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201918)."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243796"},{"key":"e_1_2_1_55_1","unstructured":"Evan Sangaline. 2017. Making Chrome Headless Undetectable. Retrieved from https:\/\/intoli.com\/blog\/making-chrome-headless-undetectable\/.  Evan Sangaline. 2017. Making Chrome Headless Undetectable. Retrieved from https:\/\/intoli.com\/blog\/making-chrome-headless-undetectable\/."},{"key":"e_1_2_1_56_1","unstructured":"Evan Sangaline. 2018. It Is Not Possible to Detect and Block Chrome Headless. Retrieved from https:\/\/intoli.com\/blog\/not-possible-to-block-chrome-headless\/.  Evan Sangaline. 2018. It Is Not Possible to Detect and Block Chrome Headless. Retrieved from https:\/\/intoli.com\/blog\/not-possible-to-block-chrome-headless\/."},{"key":"e_1_2_1_57_1","unstructured":"John Schwartz. 2001. Giving the Web a Memory Cost Its Users Privacy. Retrieved from http:\/\/www.nytimes.com\/ 2001\/09\/04\/technology\/04COOK.html.  John Schwartz. 2001. Giving the Web a Memory Cost Its Users Privacy. Retrieved from http:\/\/www.nytimes.com\/ 2001\/09\/04\/technology\/04COOK.html."},{"key":"e_1_2_1_58_1","doi-asserted-by":"crossref","unstructured":"Natasha Singer. 2012. Do not track? Advertisers say \u201cdon\u2019t tread on us.\u201d New York Times. Retrieved from http:\/\/www.nytimes.com\/2012\/10\/14\/technology\/do-not-track-movement-is-drawing-advertisers-fire.html.  Natasha Singer. 2012. Do not track? Advertisers say \u201cdon\u2019t tread on us.\u201d New York Times. Retrieved from http:\/\/www.nytimes.com\/2012\/10\/14\/technology\/do-not-track-movement-is-drawing-advertisers-fire.html.","DOI":"10.1016\/S1350-4789(12)70112-5"},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of the USENIX Workshop on Offensive Technologies (WOOT\u201918)","author":"Smith Michael","year":"2018","unstructured":"Michael Smith , Craig Disselkoen , Shravan Narayan , Fraser Brown , and Deian Stefan . 2018 . Browser history re: Visited . In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT\u201918) . Michael Smith, Craig Disselkoen, Shravan Narayan, Fraser Brown, and Deian Stefan. 2018. Browser history re: Visited. In Proceedings of the USENIX Workshop on Offensive Technologies (WOOT\u201918)."},{"volume-title":"Browser Statistics","year":"2020","key":"e_1_2_1_60_1","unstructured":"Stetic. 2020. Browser Statistics March 2020 . Retrieved from https:\/\/www.stetic.com\/market-share\/browser\/. Stetic. 2020. Browser Statistics March 2020. Retrieved from https:\/\/www.stetic.com\/market-share\/browser\/."},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the Black Hat DC Briefings (BHDC\u201909)","author":"Sutton Michael","year":"2009","unstructured":"Michael Sutton . 2009 . A wolf in sheep\u2019s clothing, the dangers of persistent WEB browser storage . In Proceedings of the Black Hat DC Briefings (BHDC\u201909) . Michael Sutton. 2009. A wolf in sheep\u2019s clothing, the dangers of persistent WEB browser storage. In Proceedings of the Black Hat DC Briefings (BHDC\u201909)."},{"key":"e_1_2_1_62_1","unstructured":"Aaron Swartz. 2018. Web.py web framework. Retrieved from http:\/\/webpy.org\/.  Aaron Swartz. 2018. Web.py web framework. Retrieved from http:\/\/webpy.org\/."},{"key":"e_1_2_1_63_1","unstructured":"Symantec. 2017. The Need for Threat Risk Levels in Secure Web Gateways. Retrieved from https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/white-papers\/need-for-threat-tisk-Levels-in-secure-web-gateways-en.pdf.  Symantec. 2017. The Need for Threat Risk Levels in Secure Web Gateways. Retrieved from https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/white-papers\/need-for-threat-tisk-Levels-in-secure-web-gateways-en.pdf."},{"key":"e_1_2_1_64_1","unstructured":"Symantec. 2017. WebPulse. Retrieved from https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/white-papers\/webpulse-en.pdf.  Symantec. 2017. WebPulse. Retrieved from https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/white-papers\/webpulse-en.pdf."},{"key":"e_1_2_1_65_1","unstructured":"The Chromium Projects. 2016. SameSite Updates. Retrieved from https:\/\/www.chromium.org\/updates\/same-site.  The Chromium Projects. 2016. SameSite Updates. Retrieved from https:\/\/www.chromium.org\/updates\/same-site."},{"key":"e_1_2_1_66_1","unstructured":"The Chromium Projects. 2020. Cookie Legacy SameSite Policies. Retrieved from https:\/\/www.chromium.org\/administrators\/policy-list-3\/cookie-legacy-samesite-policies.  The Chromium Projects. 2020. Cookie Legacy SameSite Policies. Retrieved from https:\/\/www.chromium.org\/administrators\/policy-list-3\/cookie-legacy-samesite-policies."},{"key":"e_1_2_1_67_1","unstructured":"The WebKit Open Source Project. 2018. Implement Same-Site cookies. Retrieved from https:\/\/github.com\/WebKit\/webkit\/commit\/91ac5b831f84731aad164b48d53007f6e82d60d2.  The WebKit Open Source Project. 2018. Implement Same-Site cookies. Retrieved from https:\/\/github.com\/WebKit\/webkit\/commit\/91ac5b831f84731aad164b48d53007f6e82d60d2."},{"key":"e_1_2_1_68_1","volume-title":"Proceedings of the Network and Distributed System Symposium (NDSS\u201910)","author":"Toubiana Vincent","year":"2010","unstructured":"Vincent Toubiana , Arvind Narayanan , Dan Boneh , Helen Nissenbaum , and Solon Barocas . 2010 . Adnostic: Privacy preserving targeted advertising . In Proceedings of the Network and Distributed System Symposium (NDSS\u201910) . Vincent Toubiana, Arvind Narayanan, Dan Boneh, Helen Nissenbaum, and Solon Barocas. 2010. Adnostic: Privacy preserving targeted advertising. In Proceedings of the Network and Distributed System Symposium (NDSS\u201910)."},{"key":"e_1_2_1_69_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201915)","author":"Goethem Tom Van","year":"2015","unstructured":"Tom Van Goethem , Wouter Joosen , and Nick Nikiforakis . 2015 . The clock is still ticking: Timing attacks in the modern web . In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201915) . Tom Van Goethem, Wouter Joosen, and Nick Nikiforakis. 2015. The clock is still ticking: Timing attacks in the modern web. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS\u201915)."},{"key":"e_1_2_1_70_1","unstructured":"WebKit Bugzilla. 2019. Bug 198181: Cookies with SameSite&equals;None or SameSite&equals;invalid treated as Strict. Retrieved from https:\/\/bugs.webkit.org\/show_bug.cgi?id&equals;198181.  WebKit Bugzilla. 2019. Bug 198181: Cookies with SameSite&equals;None or SameSite&equals;invalid treated as Strict. Retrieved from https:\/\/bugs.webkit.org\/show_bug.cgi?id&equals;198181."},{"volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Weinber Z.","key":"e_1_2_1_71_1","unstructured":"Z. Weinber , E. Chen , P. R. Jayaraman , and C. Jackson . 2011. I still know what you visited last summer . In Proceedings of the IEEE Symposium on Security and Privacy. Z. Weinber, E. Chen, P. R. Jayaraman, and C. Jackson. 2011. I still know what you visited last summer. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_72_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy.","author":"Wondracek Gilbert","year":"2010","unstructured":"Gilbert Wondracek , Thorsten Holz , Engin Kirda , and Christopher Kruegel . 2010 . A practical attack to de-anonymize social network users . In Proceedings of the IEEE Symposium on Security and Privacy. Gilbert Wondracek, Thorsten Holz, Engin Kirda, and Christopher Kruegel. 2010. A practical attack to de-anonymize social network users. In Proceedings of the IEEE Symposium on Security and Privacy."},{"key":"e_1_2_1_73_1","unstructured":"World Wide Web Consortium. 2018. User Timing. Retrieved from https:\/\/www.w3.org\/TR\/user-timing\/.  World Wide Web Consortium. 2018. User Timing. Retrieved from https:\/\/www.w3.org\/TR\/user-timing\/."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3419473","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3419473","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:42Z","timestamp":1750197702000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3419473"}},"subtitle":["Timing Server-side Request Processing Code for History Sniffing"],"short-title":[],"issued":{"date-parts":[[2020,12,22]]},"references-count":73,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,12,31]]}},"alternative-id":["10.1145\/3419473"],"URL":"https:\/\/doi.org\/10.1145\/3419473","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"type":"print","value":"2692-1626"},{"type":"electronic","value":"2576-5337"}],"subject":[],"published":{"date-parts":[[2020,12,22]]},"assertion":[{"value":"2020-05-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-12-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}