Recent privacy protections by browser vendors aim to limit the abuse of third-party cookies for cross-site tracking. While these countermeasures against third-party cookies are widely welcome, there are concerns that they will result in advertisers and trackers abusing first-party cookies instead. We provide the first empirical evidence of how first-party cookies are abused by advertisers and trackers by conducting a differential measurement study on 10K websites with third-party cookies allowed and blocked. We find that advertisers and trackers implement cross-site tracking despite third-party cookie blocking by storing identifiers, based on probabilistic and deterministic attributes, in first-party cookies. As opposed to third-party cookies, outright first-party cookie blocking is not practical because it would result in major breakage of legitimate website functionality. We propose CookieGraph, a machine learning approach that can accurately and robustly detect first-party tracking cookies. CookieGraph detects first-party tracking cookies with 91.06% accuracy, outperforming the state-of-the-art CookieBlock approach by 10.28%. We show that CookieGraph is fully robust against cookie name manipulation while CookieBlock's accuracy drops by 15.68%. We also show that CookieGraph does not cause any major breakage while CookieBlock causes major breakage on 8% of the websites with SSO logins. Our deployment of CookieGraph shows that first-party tracking cookies are used on 93.43% of the 10K websites. We also find that the most prevalent first-party tracking cookies are set by major advertising entities such as Google as well as many specialized entities such as Criteo.
翻译:浏览器供应商最近提供的隐私保护旨在限制滥用第三方饼干进行跨场跟踪。 虽然这些对抗第三方饼干的对策受到广泛欢迎, 但人们担心它们将导致广告商和跟踪者滥用第一党饼干。 我们提供了第一个经验性证据,说明广告商和跟踪者如何滥用第一党饼干,在10K网站上进行差异计量研究,允许和封锁第三方饼干;我们发现广告商和跟踪者实施跨场跟踪,尽管第三方饼干通过储存标识符阻塞了93个第三方饼干,在第一党饼干中则广泛受到欢迎。相对于第三方饼干,公开的第一党饼干封锁并不实用,因为它会导致合法网站功能的重大破碎。我们建议CookieGraph,这是一个机器学习方法,可以准确和有力地检测第一党的饼干。我们发现,广告商和跟踪者在储存基于性能和确定性属性的标识符中,储存了93个第三方饼干。我们显示,CookieGraph公司在首次使用饼干时,在C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-Lock-C-Lock-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-C-