Skip to main content
Back

Cookies

7 results across all content

Publications (1)

2023ConferenceTop-Tier

COOKIEGRAPH: Measuring and Countering First-Party Tracking Cookies

ACM SIGSAC Conference on Computer and Communications Security(CCS) · 19% acceptance

Shaoor Munir, Sandra Siby, Umar Iqbal, Steven Englehardt, Zubair Shafiq, Carmela Troncoso

TL;DR:First-party tracking cookies exist on 89.86% of websites. CookieGraph detects them with 90% accuracy without breaking SSO.

As third-party cookie blocking is becoming the norm in mainstream web browsers, advertisers and trackers have started to use first-party cookies for tracking. To understand this phenomenon, we conduct a differential measurement study with versus without third-party cookies. We find that first-party cookies are used to store and exfiltrate identifiers to known trackers even when third-party cookies are blocked. As opposed to third-party cookie blocking, first-party cookie blocking is not practical because it would result in major breakage of website functionality. We propose CookieGraph, a machine learning-based approach that can accurately and robustly detect and block first-party tracking cookies. CookieGraph detects first-party tracking cookies with 90.18% accuracy, outperforming the state-of-the-art CookieBlock by 17.31%. We show that CookieGraph is robust against cookie name manipulation, while CookieBlock's accuracy drops by 15.87%. While blocking all first-party cookies results in major breakage on 32% of the sites with SSO logins, and CookieBlock reduces it to 10%, we show that CookieGraph does not cause any major breakage on these sites. Our deployment of CookieGraph shows that first-party tracking cookies are used on 89.86% of the top-million websites. We find that 96.61% of these first-party tracking cookies are in fact ghostwritten by third-party scripts embedded in the first-party context. We also find evidence of first-party tracking cookies being set by fingerprinting scripts. The most prevalent first-party tracking cookies are set by major advertising entities such as Google, Facebook, and TikTok.

Talks (4)

Beyond Third-Party Cookies: Safeguarding User Data from Storage and Exfiltration with CookieGraph and PURL

IMDEA Networks · November 2023

A comprehensive talk covering two complementary approaches to combat emerging tracking techniques: CookieGraph for first-party cookie tracking and PURL for link decoration tracking.

Watch/Listen →

COOKIEGRAPH: Measuring and Countering First-Party Tracking Cookies

ACM CCS 2023 · November 2023

Presenting a machine learning-based approach that accurately detects and blocks first-party tracking cookies that are increasingly used as third-party cookies become blocked by browsers.

Watch/Listen →

COOKIEGRAPH: Measuring and Countering First Party Tracking Cookies

Ad-Filtering Dev Summit 2022 · October 2022

Early presentation of CookieGraph research showing how first-party tracking cookies are used on 89.86% of top websites, with 96.61% being ghostwritten by third-party scripts.

Watch/Listen →

First-Party Tracking Cookies

DataSkeptic Podcast · September 2022

A podcast discussion explaining first-party tracking cookies, how they differ from third-party cookies, and the implications for user privacy as browsers block third-party cookies.

Watch/Listen →

Media Coverage (2)

Cookies Research & Content | Shaoor Munir