Hackers Corner Passive Advertising Profiling STRICTLY CONFIDENTIAL - - PowerPoint PPT Presentation

hacker s corner
SMART_READER_LITE
LIVE PREVIEW

Hackers Corner Passive Advertising Profiling STRICTLY CONFIDENTIAL - - PowerPoint PPT Presentation

Hackers Corner Passive Advertising Profiling STRICTLY CONFIDENTIAL 13 Agosto 2011 Tonacci & Mensurati ...& Matteo Flora :) Entropia.... (http://panopticlick.eff.org/browser-uniqueness.pdf) Entropia....


slide-1
SLIDE 1 STRICTLY CONFIDENTIAL

Hacker’s Corner

Passive Advertising Profiling

slide-2
SLIDE 2

13 Agosto 2011 Tonacci & Mensurati ...& Matteo Flora :)

slide-3
SLIDE 3

Entropia....

(http://panopticlick.eff.org/browser-uniqueness.pdf)

slide-4
SLIDE 4

Entropia....

(http://panopticlick.eff.org/browser-uniqueness.pdf)

slide-5
SLIDE 5
slide-6
SLIDE 6

WebMail Motore di ricerca

User

Sito di Notizie Sito Generalista Sito di Approfondimento Blog Embed di Mappe Embed sito di Video WebMail Sito Generalista Sito Generalista Sito di Approfondimento Sito Generalista

script di statitiche script di statitiche advertising advertising advertising gestione di feed

99.9993%

!

slide-7
SLIDE 7

EverCookie

  • Evercookie is a javascript API available that produces 2 extremely persistent

cookies in a browser. Its goal is to identify a client even after they've removed standard cookies, Flash cookies (Local Shared Objects or LSOs), and others. Evercookie accomplishes this by storing the cookie data in several types of storage mechanisms that are available on the local browser. Additionally, if evercookie has found the user has removed any of the types of cookies in question, it recreates them using each mechanism available.

  • Samy Kamkar (@samykamkar) - http://samy.pl/evercookie/
slide-8
SLIDE 8

Utente

EVER-COOKIE (UUID) Profilo Personale

dati sensibili digital profiling behaviural advertising dati aziendali dati decisionali

EVER-COOKIE (UUID)

Utente

slide-9
SLIDE 9

Utente

ACCOUNT! Profilo Personale

dati sensibili digital profiling behaviural advertising dati aziendali dati decisionali

ACCOUNT!

Utente

slide-10
SLIDE 10
slide-11
SLIDE 11
slide-12
SLIDE 12
slide-13
SLIDE 13
slide-14
SLIDE 14

Profiling Firewall

slide-15
SLIDE 15

Profiling Firewall

slide-16
SLIDE 16

Profiling Firewall

slide-17
SLIDE 17

Profiling Firewall

slide-18
SLIDE 18

Profiling Firewall

slide-19
SLIDE 19

Profiling Firewall

  • Standard HTTP Cookies
  • Flash Cookies (LSOs)
  • Silverlight Isolated Storage
  • Storing cookies in RGB values of auto-

generated, force-cached PNGs using HTML5 Canvas tag to read pixels (cookies) back out

  • Storing cookies in Web History
  • window.name caching

Internet Explorer userData storage

  • Storing cookies in HTTP ETags
  • HTML5 Session Storage
  • HTML5 Local Storage
  • HTML5 Global Storage
  • HTML5 Database Storage via SQLite
  • Firewalling sistemi di Statistics e Counters
  • Proxying di Redirector e di Click Trackers

avoidance

  • ReTargeting Users
slide-20
SLIDE 20

Contromisure

slide-21
SLIDE 21

Contromisure

slide-22
SLIDE 22

Contromisure

slide-23
SLIDE 23

Contromisure

slide-24
SLIDE 24

Contromisure

slide-25
SLIDE 25 STRICTLY CONFIDENTIAL

estote parati...