Prevent tracking via "Crooked Style Sheets" attack #818
Labels
priority/P5
Not scheduled. Don't anticipate work on this any time soon.
privacy/tracking
Preventing sites from tracking users across the web
privacy
Without any JS, a site can use CSS to track and report some information about entered-but-not-submitted text, mouse hovers, and link clicks, as well as performing some simple fingerprinting via resolution, UA, & typefaces.
Much of this can be mitigated by optimistically loading all CSS-referenced content so that none of those loads are conditioned on user behavior.
The text was updated successfully, but these errors were encountered: