Show simple item record

Files in this item

Thumbnail

Item metadata

dc.contributor.authorMcQuistin, Stephen
dc.contributor.authorSnyder, Peter
dc.contributor.authorPerkins, Colin
dc.contributor.authorHaddadi, Hamed
dc.contributor.authorTyson, Gareth
dc.date.accessioned2023-10-25T15:30:06Z
dc.date.available2023-10-25T15:30:06Z
dc.date.issued2023-10-24
dc.identifier295070433
dc.identifiera8e8b910-9304-47d8-9da9-28691dab6a54
dc.identifier85177617219
dc.identifier.citationMcQuistin , S , Snyder , P , Perkins , C , Haddadi , H & Tyson , G 2023 , A first look at the privacy harms of the public suffix list . in IMC '23: Proceedings of the 2023 ACM on Internet Measurement Conference . ACM , New York, NY , pp. 383–390 , ACM Internet Measurement Conference 2023 , Montreal , Canada , 24/10/23 . https://doi.org/10.1145/3618257.3624836en
dc.identifier.citationconferenceen
dc.identifier.isbn9798400703829
dc.identifier.otherORCID: /0000-0002-0616-2532/work/141228256
dc.identifier.urihttps://hdl.handle.net/10023/28567
dc.descriptionFunding: This work was supported in part by the UK Engineering and Physical Sciences Research Council under grant EP/S036075/1.en
dc.description.abstractThe public suffix list is a community-maintained list of rules that can be applied to domain names to determine how they should be grouped into logical organizations or companies. We present the first large-scale measurement study of how the public suffix list is used by open-source software on the Web and the privacy harm resulting from projects using outdated versions of the list. We measure how often developers include out-of-date versions of the public suffix list in their projects, how old included lists are, and estimate the real-world privacy harm with a model based on a large-scale crawl of the Web. We find that incorrect use of the public suffix list is common in open-source software, and that at least 43 open-source projects use hard-coded, outdated versions of the public suffix list. These include popular, security-focused projects, such as password managers and digital forensics tools. We also estimate that, because of these out-of-date lists, these projects make incorrect privacy decisions for 1313 effective top-level domains (eTLDs), affecting 50,750 domains, by extrapolating from data gathered by the HTTP Archive project.
dc.format.extent8
dc.format.extent733542
dc.language.isoeng
dc.publisherACM
dc.relation.ispartofIMC '23: Proceedings of the 2023 ACM on Internet Measurement Conferenceen
dc.subjectWeb privacyen
dc.subjectDomain boundariesen
dc.subjectQA75 Electronic computers. Computer scienceen
dc.subjectDASen
dc.subjectMCCen
dc.subject.lccQA75en
dc.titleA first look at the privacy harms of the public suffix listen
dc.typeConference itemen
dc.contributor.institutionUniversity of St Andrews. School of Computer Scienceen
dc.identifier.doihttps://doi.org/10.1145/3618257.3624836
dc.identifier.urlhttps://doi.org/10.1145/3618257en


This item appears in the following Collection(s)

Show simple item record