Your Browser is Lying

Поділитися
Вставка
  • Опубліковано 14 тра 2023
  • Subscribe to not miss out on next releases!
    Your browser is a liar. It lies about colors and styles of links.
    Go with me through the journey starting on the lie itself, through its history, up to the solution, and back to reintroducing it together with me.
    Sources:
    seclists.org/bugtraq/2002/Feb...
    blog.jeremiahgrossman.com/200...
    blog.mozilla.org/security/201...
    www.theregister.com/2008/07/2...
    www.technologyreview.com/2010...
    developer.mozilla.org/en-US/d...
    • Browser history re:vis...
    thedarkside.frantzmiccoli.com...
  • Наука та технологія

КОМЕНТАРІ • 48

  • @andersondamasceno
    @andersondamasceno Рік тому +22

    I liked how you started by telling the story of the problem, then talked about how you found another way to achieve the same thing, and ended by showing an incorrigible way to leak the same information. Wonderful stuff. 🙂

    • @mattsionkowski
      @mattsionkowski  Рік тому +5

      Thank you! Couldn't do it any other way. There are vulnerabilities which are considered "small" just because people lack context. And with proper context it starts showing that there is more on the line than meets the eye. Cheers!

  • @jakubgluma2189
    @jakubgluma2189 Рік тому +6

    Amazing stuff! Nice lego car btw :)

    • @mattsionkowski
      @mattsionkowski  Рік тому +2

      Cannot start a mission without a good ride. It's special agent's 101 :)

  • @mendhak
    @mendhak Рік тому +8

    That last part captcha'd my imagination

  • @WithYouIDisagree
    @WithYouIDisagree Рік тому +22

    Cool video! One suggestion is to lower the volume of the background music or increase your voice's volume. It was hard to understand what you were saying at some points. The captions helped.

    • @mattsionkowski
      @mattsionkowski  Рік тому +3

      Thank you for feedback. Will surely do that on the next one. Cheers!

    • @ko0x
      @ko0x Рік тому +3

      @@mattsionkowski There's a technique called "ducking" in audio engineering. You can use a compressor with "side chain" to automatically lower the volume of an audio track if there's a signal from another audio source. E.g. automatically lower the background music when voice comes in. It's automatic and gives you nice dynamics.

    • @davel4030
      @davel4030 11 днів тому +1

      ​​@@ko0x my phone does that when I'm listening to music and it gets a notification or starts reading a text in the car. Good feature. I know it's not exactly what you're talking about but same effect pretty much.

    • @ThomWalbranA1
      @ThomWalbranA1 10 днів тому

      I agree 100% , I would not mind cutting the music all together. You content is great and doesn't need any tricks or fluff.
      Thank you for sharing.

  • @AI-Restoeations
    @AI-Restoeations 6 днів тому +1

    This is the second video of yours I've watched, you've earned my sub. Such professional videos from such a small channel keep it up

  • @teambridgebsc691
    @teambridgebsc691 8 днів тому +1

    Enjoyed and informed. Doing a great service here.

  • @artinfopartner
    @artinfopartner Рік тому +5

    Whoah great content Matt ! I lovw such things !

  • @inamortz2372
    @inamortz2372 Рік тому +4

    Nice one man, very informative.

    • @mattsionkowski
      @mattsionkowski  Рік тому +1

      Thank you, mate. This is still a fresh channel so i very much appreciate the feedback. It helps with maintaining or adjusting direction. Cheers!

  • @daimonismeno
    @daimonismeno Рік тому +4

    Man, please keep up the excellent work. All your videos are enjoyable and rewatchable. Nice!

    • @mattsionkowski
      @mattsionkowski  Рік тому +2

      Thank you! You made my day🙂

    • @CottonInDerTube
      @CottonInDerTube 7 днів тому

      @@mattsionkowski I watched 2 of your videos and agree: quallity content.
      The only 2 things i dont like are the backgound music and the inserted video snippets. That makes me fell like somebody is trying to sell me something.

  • @Mangohawk124
    @Mangohawk124 Рік тому +5

    Very high quality content nice bro ❤🎉🎉🎉🎉

  • @bobcoco6047
    @bobcoco6047 9 днів тому +1

    Great presentation !
    I wonder if it's possible to build some funnel logic into the captcha characters, so that they could display the color white/black for different functions than directly "did you visit this unique address", but rather "did you visit 1 of those, or this group?" , so that depending on the characters appearing, they could know + about us than just 1 link history...
    Concerning anyway, & suggests me there is indeed some reason to empty our history, & focus on either randomization of leaks (seems best), hiding 'em when possible & not counterproductive (fingerprint, which ironically can happen from hiding x ) or deleting the data (not always possible nor ideal).
    Thx

  • @mattm1982
    @mattm1982 Рік тому +1

    I don't know why I clicked this or watched it but it was very well done... good job man :)
    Also to echo what someone else said, I would decrease the music volume a bit.

  • @freddrune8315
    @freddrune8315 9 днів тому +1

    Great video sir.

  • @3vonline
    @3vonline 13 днів тому +1

    Great video!

  • @mashpotato832
    @mashpotato832 Рік тому +1

    The capthcha thing can't really be used for rapid mass scanning of visited links though, yeah it links info but it's nowhere near as bad.
    Cool video thanks for putting this together, I enjoyed it.

  • @Obiika
    @Obiika Рік тому +1

    Very informative video, tells a lot more than just the story initially covered !

  • @chmielewskibartek
    @chmielewskibartek Рік тому +2

    Favorite host :) Best wishes and looking forward for new stuff!

    • @mattsionkowski
      @mattsionkowski  Рік тому

      Work in progress :D
      Thank you, and will keep going.

  • @CottonInDerTube
    @CottonInDerTube 7 днів тому

    And again i must say: the problem is that we execute programs (JS) on our machines just because we wanted to read text like the news or so.

  • @danieldahl7186
    @danieldahl7186 Рік тому +1

    Glad i stuck around for the end

  • @MisterZizzy23
    @MisterZizzy23 Рік тому +1

    Nice video sir! Keep it sir ❤. Love from India 🇮🇳 ❤

  • @desiredditor
    @desiredditor Рік тому +1

    very good video just try to sit in a different place which doesnt have a slanting side right on the right side of the video regarding bg music just lower it by 5 db and it should be better

  • @aboaliu657
    @aboaliu657 Рік тому

    nice explain, love from iraq 🇮🇶

  • @davel4030
    @davel4030 11 днів тому

    They can patch to make text not be able to be the same color as the surrounding background. I can't think of any legit use, only malicious uses. Who would need to hide text? And if they do want a uniquely generated finger print they can just throw it to the bottom of the page where it won't disrupt the sites experience.

  • @NorthernChimp
    @NorthernChimp Рік тому

    Wathehack couldn't browsers just disable the ":visited" css pseudo-class? (for websites, even if the browser uses it itself) How is this unpatchable?

    • @mattsionkowski
      @mattsionkowski  Рік тому +1

      The problem is - users expect this functionality to work as it is as old as browsers.
      And if you disable the pseudo class, the browser internally might turn links purple, but it will not allow the webmaster to use a custom color.
      ... tradeoffs ...
      But also keep in mind that my last use case required users action. Making a leak far smaller in size and in potential risk. The "lying" solution is really quite good. It prevents the massive leaks (automatic ones)

  • @sgramstrup
    @sgramstrup Рік тому +1

    Learned a lot.. Scary shit. I'm less worried about a single hacker on a dark site, than big scumcorp spying on me. Thx.

    • @mattsionkowski
      @mattsionkowski  Рік тому

      The history leak took 8 years for a patch - but still, it got resolved at some point. Yet this is not the last privacy threat. I'm in the making of a video about browser fingerprinting, which is an issue very much alive. Stay tuned!

  • @joyraina
    @joyraina Рік тому +1

    You content is good , please don't add stupid memes like that doing why action in between.
    I haven't seen other videos yet, so i don't know whether this was one off or not

  • @m1cannas
    @m1cannas 12 днів тому

    😀

  • @EnglishRain
    @EnglishRain Рік тому

    Great video subscribed! But please get rid of the music

    • @mattsionkowski
      @mattsionkowski  Рік тому +2

      Thank you. Yep, received a lot of feedback of music being too loud. Will get it better next time!

  • @aglimmerofhope5321
    @aglimmerofhope5321 Рік тому

    Again wishing Mozilla was the backbone of Brave browser (instead of Chrome). Someone get on that please ... 😞
    Saw this on reddit BTW. Good info. TY. :peace:

    • @mattsionkowski
      @mattsionkowski  Рік тому +1

      Chromium is a well managed project too. Yet we cannot undermine the continous positive impact Mozilla had on the shaping of browsers as whole. Now we see Mozilla being pushed aside. I'm not saying everyone should use firefox, but as it's loosing users - we're all loosing a very good player on the browsers scene. Some day other browsers will not have that competition. And such monopoly is never a good thing.

    • @aglimmerofhope5321
      @aglimmerofhope5321 Рік тому

      @@mattsionkowski well said 👏

    • @NorthernChimp
      @NorthernChimp Рік тому

      Nobody should be using a single browser for everything anyway. The fact that so many people do is concerning in itself.