Here's a PoC that confirms my hunch. *Neither* of these windows use JavaScript but the position of the cursor in the left window is sent to the right window. This works on Tor Browser with JS disabled.pic.twitter.com/cnfOy5OkUj
-
-
Näytä tämä ketju
-
The server code I hacked together to test this:https://gist.github.com/wybiral/c8f46fdf1fc558d631b55de3a0267771 …
Näytä tämä ketju -
The browser won't reload the background image so this version only tracks the movement on the first :hover ... but ... Since the request is chunked the server can send more CSS to add new :hover selectors each time one triggers.
Näytä tämä ketju -
Aside from making me question everything I know about browser tracking capabilities, this also makes me think that you could build some highly interactive content without using any JS at all.
Näytä tämä ketju
Keskustelun loppu
Uusi keskustelu -
-
-
So a 1024 x 768 single page site with CSS grid using 886 3px x 3px images that covers the entirety of the page? Hover: hidden;
-
I don't think you need to cover the entire page for meaningful analytics. Just a handful of key elements. Keep in mind that when a link is clicked the cursor will be in the same position so beyond exact X,Y you can get stats about which page they were on before clicking.
- Näytä vastaukset
Uusi keskustelu -
-
-
I remember last year, and probably the year before that, and probably the year before that still, people continually rediscover CSS keylogging. Glad to see something more interesting this time. Good work.
-
You mean like [value=] selectors? You can also grab URL data that way too. My focus has been on browser tracking without JS since people who are serious about privacy (usually because there's something at stake) tend to operate in that environment. Web browsers are scary.
- Näytä vastaukset
Uusi keskustelu -
-
-
i don't know why it continues to amaze me how much privacy is a losing battle in browsers but this is really neat
-
It's really unfortunate because we would need to restructure HTTP and HTML/CSS just to get some basic sense of privacy... But people use JS (the most convenient spyware) all over the place without batting an eye so it seems unlikely to change any time soon.
- Näytä vastaukset
Uusi keskustelu -
Lataaminen näyttää kestävän hetken.
Twitter saattaa olla ruuhkautunut tai ongelma on muuten hetkellinen. Yritä uudelleen tai käy Twitterin tilasivulla saadaksesi lisätietoja.
TeChNoLoGy 
