Search Engine News|December 6, 2010 7:30 pm

History Sniffing and Your Browser Security


Theme Zoom Architect Sue Bell recently lectured the Theme Zoom team on “history sniffing” and we thought to bring this to the attention of our readers, since it is definitely not something everyone knows about.

The original article that brought this topic to light was called Your Web Surfing History Is Accessible (Without Your Permission) Via JavaScript.

The meat of the article is summarized:

History sniffing takes place without your knowledge or permission and relies on the fact that browsers display links to sites you’ve visited differently than ones you haven’t: by default, visited links are purple, unvisited links blue. History sniffing JavaScript code running on a Web page checks to see if your browser displays links to specific URLs as blue or purple.

More disturbing for those of us who perform a lot of  online commerce:

History sniffing can be used by website owners to learn which competitor sites visitors have or have not been to. History sniffing can also be deployed by advertising companies looking to build user profiles, or by online criminals collecting information for future phishing attacks. Learning what banking site you visit, for example, suggests which fake banking page to serve up during a phishing attack aimed at collecting your bank account login information.

Sue Bell suggested that all TZ team members stick with the latest version of Mozilla Firefox, Chrome or Safari because the updated versions of each browser now block the history sniffing attacks during tests. She also recommends that you make sure that your latest version is updated with recent recommended patch from each company.

I have to say, Sue Bell has a special interest in this topic because she was messing around with fairly heavy concepts that would allow websites to utilize such technology. (That is all I can really say about it). She pretty much ‘sees the matrix’ if you know what I mean, and is always looking for security holes where data could be extracted . . . yeah, like Inception. (grin)

Thank you Sue, updates in progress.

Guys, this means that the big “E” browser (Explorer) is not recommended until they actively address this problem!

About

Russell Wright is a search engine optimization auditor and co-inventor of the Theme Zoom (Krakken) keyword research tool. This tool was founded on Russell's proprietary keyword reporting system and the 9 different keyword types. This keyword system is designed to unveil the unique keyword fingerprint of your website that will assist you in dominating your niche at a high level.

Related posts:

Network Theory Just Went to an HNL.
Another Weird Week In Tech: News Round-Up
Is There A Better Content Model Than Content Curation?

4 Comments