Mozilla set to patch eight-year-old CSS history leak
By Martin James,
The Mozilla Foundation has announced it is close to plugging a privacy hole that has plagued all major web browsers for nearly a decade.
The vulnerability in question is a Cascading Style Sheet (CSS) issue that leaves an internet user's web history potentially visible to attackers because of how CSS displays visited and unvisited links in different colours.
In a post on the Mozilla blog, Mozilla Security's Sid Stamm said the Foundation was close to plugging the so-called “CSS History Leak”, saying the matter would be addressed in a forthcoming Firefox fix, though he didn't specify exactly when.
“We’re close to landing some changes in the Firefox development tree that will fix a privacy leak that browsers have been struggling with for some time,” Stamm wrote. “We’re really excited about this fix, we hope other browsers will follow suit. It’s a tough problem to fix, though.”
Currently, all an attacker needs to do to get an accurate picture of any web user's browsing history is bombard the browser with huge lists of possible URLs and filter out those with differently coloured links, indicating the site in question has been visited.
Regularly clearing your web history is one way to tackle the issue, but with all major browsers vulnerable to a problem that has been around for some eight years, it has become a well-known – and well-exploited – security hole.
However, the proposed patch – developed by Mozilla employee David Baron – claims to fix the problem by effectively making elements within the browser and various CSS functions believe that all links are unvisited.
In a post on his own blog, Baron said the patches were complete and only had to be put through various testing structures before being ready to send out to Firefox users.
“I have patches implementing this solution that I believe are largely complete, and which I will soon be requesting reviews on to begin the process of incorporating them into a future version of Gecko, the layout engine used by Firefox.”
In reporting the news, however, Stamm did warn that there would potentially be some effect on day-to-day browsing – at least until websites adapted to the new measures.
“For the most part, users shouldn’t notice a change in how the web works. A few websites may look a little different, but visited links will still show up differently coloured. A few sites that use more than colour to differentiate visited links may look slightly broken at first while they adjust to these changes, but we think it’s the right trade-off to be sure we protect our users’ privacy," he added.
“This is a troubling and well-understood attack; as much as we hate to break any portion of the web, we need to shut the attack down to the extent we can.”
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Networking Analysis & Insight
Bring you own device: the $600 question
Inside the enterprise: A recent Cisco report claims bring your own device is gaining support from IT departments. But how much are staff willing to invest in personal technology?
- Interop 2012: Q&A, Saar Gillai, CTO, HP Networking
- Is BT the key to broadband Britain?
- Tencent: the biggest web company you’ve never heard of
- The truth about spam
- Have ISPs finally lost the DEA fight?
- Are you ready to launch IPv6 securely?
- Broadband, pricing and small businesses
- Welcome to the stay-at-home Olympics
- Q&A: Cisco on servers, storage and strategy
Latest Networking Reviews
HP t410 All-in-One Thin Client review: First look
- Swyx SwyxExpress X20 review
- Ipswitch WhatsUp Gold Premium 15
- ForeScout Technologies CounterACT 6.3.4
- ThinPrint Printer Dashboard review: First Look
- TITUS Aware for Microsoft Outlook review
- Windows Phone 7 Mango review: First Look
- Dartware InterMapper review
- Kemp Technologies LoadMaster 3600 review
- Sangfor WANACC M5500 review
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Dell EqualLogic PS6100XS review
- Chromebooks: What's gone wrong?
- ICO: Fines for cookie law breakers
- UK regulator shuts down Angry Birds scam
- Open source software driving cloud-based innovation
- Fujitsu targets enterprises with Android ICS tablet
- IBM bans use of Siri on iPhones
- Dell PowerEdge R820 review
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





