Back to main
Lukasz Olejnik
Security, Privacy & Tech Inquiries

Posts for "w3c"

Total 23 Posts

Initial privacy analysis of Google’s Privacy Sandbox - Federated Learning of Cohorts leaking information about browsing in incognito mode

Digital web advertising is an ecosystem undergoing strategic changes. Google’s Privacy Sandbox is promising to redesign web advertising technology in ways that will respect user’s privacy, including based on some previous designs. Detailed technically-enabled analysis should wait until more design features are known. In this post I focus Read More

Large-scale Analysis of DNS-based Tracking Evasion - broad data leaks included?

User tracking technologies are ubiquitous on the web. In recent times web browsers try to fight abuses. This led to an arms race where new tracking and anti-tracking measures are being developed. The use of one of such evasion techniques, the CNAME cloaking technique is recently quickly gaining popularity. Our Read More

Are we reaching privacy preserving digital advertising? Historical view

We may be in the middle of a  process of redesigning how the web economy functions. Considerations include web advertisements. Such works involve many actors. Some big platforms. Some web browser vendors. Some ads companies, with a modest list of analysts or researchers keeping a close eye. I believe it’ Read More

Shedding light on designing web features with privacy: risks, impact assessments, case study

This post is built around my paper (presented to/at the International Workshop on Privacy Engineering) devoted to privacy assessment in web standards. After the previous one (Battery Status Not Included: Assessing Privacy in W3C Web Standards) this is the next insight in this domain. While I point out the Read More

Privacy of Web Request API

Simple payment standard will be the new cool thing web browsers can do. This happens thanks to W3C Payment Request API. Early on it has been even featured in the New York Times and rightly so, as it has a big potential. Why? Introduction Chances are that the days of Read More

Stealing sensitive browser data with the W3C Ambient Light Sensor API

In this post we describe and demonstrate a neat trick to exfiltrate sensitive information from your browser using a surprising tool: your smartphone or laptop’s ambient light sensor. In short: 1. We provide background about the light sensor API and current discussions to expose it more broadly to websites. Read More

Web Bluetooth API Privacy

Web Bluetooth - a web API under development, and will be one of the core components of Web of Things, the application layer of Internet of Things. It will enable sensors, beacons and user devices to communicate with each other. But at first: it will enable a web browser to Read More

Privacy of W3C Vibration API

Vibrating devices are a familiar thing. From the era of flip-phones, to vibrations induced by mobile apps. Or websites. [Edit 15/11/19: Firefox is limiting access to Vibration API] Vibration API The mechanism allowing websites to utilize device's vibration motor is called Vibration API. The mechanism allows Read More