Page 1 of 1

Advertisers can track users via TLS session resumption

Posted: Tue 23 Oct 2018, 17:18
by 6502coder ... esumption/
The concept is simple. If an online advertising firm loads ads via a TLS (HTTPS) server, then it can enable TLS Session Resumption for that server.

When a user access Website A showing ads from the advertising firm, it also establishes a TLS session with the advertising firm's server. When the user visits Website B with ads from the same firm, instead of negotiating another TLS session, the user resumes the existing one, allowing the advertising firm to track the user as he moves across sites.

Posted: Wed 24 Oct 2018, 09:10
by rufwoof
Even a simple 1 pixel ad image can be used to track you across sites. Just part of big-data that ultimately is intended to serve direct to individual advertisements/data flows (control the media and you can focus mind control at each individual).

Posted: Wed 24 Oct 2018, 09:19
by s243a
Can we block third party TSL?