a memo

Browsers Leak History Through Visited Links

Jeremiah Grossman has posted some proof-of-concept javascript that can determine if you have visited any of a number of popular websites. (Select the "I Know Where You've Been" div on the right and View selection source to see it.)

In a nutshell, if you want to find out whether someone has visited a particular url you simply render a link to that url on your page, and then use javascript to check the computed color of the link. If it matches the color of visited links, you can guess that they've seen the page.

Clever, because the visited link behavior is old-school and seems safe enough, but it's actually leaking private information about your browsing habits.

By Chris Snyder on August 22, 2006 at 9:42am

Source: jeremiahgrossman.blogspot.com

jump to top