Computer security news 2018: Ad targeters exploit autofill password managers to take confidential user information

Ad targeters exploit autofill information to farm data, unbeknownst to browsers. Pixabay/blickpixel

There are reports that ad targeters are exploiting browser password managers to get data from users. People may browse the web not knowing that information about them are being farmed through the use of these extensions.

Password managers are a convenient and seamless way to browse the internet. This feature is almost present in almost every browser, and they are harmless enough on their own.

However, a study by Princeton University's Center for Information Technology found out that ad targeters are exploiting the autofill feature of the password managers to get data from the users. They can then take these data and add them to their database. Future use may include custom targeted ads for the user.

The study was conducted to detect password theft in most websites. Fortunately, the researchers from Princeton did not find any such case for any of the 50,000 sites they analyzed.

What they uncovered instead are the scripts that make autofill data-farming possible.

According to the study, the exploit works when the browser first autofills the "username/email" and "password" field on a page's login site. It should be noted that there are no tracking scripts present yet on the login page.

The tracking scripts are actually on the subsequent pages on the same domain. The script inserts invisible "username" and "password" forms on the page, without the user knowing. Meanwhile, as the browser does detect these forms, it will then autofill the fields because of the password manager.

The tracking script will then retrieve this data and add it to the database of users who will then be served targeted advertisements in the future.

The researchers studied two password manager tracking scripts — AdThink and OnAudience. They claim that both scripts work in the same way: by baiting the password managers to autofill invisible forms with confidential usernames and passwords.

News
'Light of hope for us': Christmas lights illuminate Bethlehem and Jerusalem for the first time in two years
'Light of hope for us': Christmas lights illuminate Bethlehem and Jerusalem for the first time in two years

Bethlehem and Jerusalem have ushered in the Christmas season with public celebrations and glittering lights for the first time in two years, marking a poignant moment of hope in cities still grappling with the humanitarian and economic fallout of the Gaza war.

Church of England bishops were right to halt same-sex blessing plans - Bishop of Winchester 
Church of England bishops were right to halt same-sex blessing plans - Bishop of Winchester 

The Bishop of Winchester has defended the recent decision of the House of Bishops to pause plans to introduce standalone same-sex blessing services. 

Protecting girls and young women in the digital age
Protecting girls and young women in the digital age

It’s a missional priority for us as Christian communities to have open discussions about both the benefits and downsides of being online.

Rev Dr Richard Turnbull: former principal of Wycliffe Hall, Oxford
Rev Dr Richard Turnbull: former principal of Wycliffe Hall, Oxford

Richard Turnbull brought an unusual combination of skills to his life’s work. He died on 26 October, aged 65, having been diagnosed with terminal cancer.