Prof. Amit Klein researches tracking methods based on operating system characteristics and TCP/IP protocols, and warns technology companies about loopholes that allow users to be identified across websites even without third-party cookies.
“Let’s say you’re surfing for fun on your phone or laptop and you’re looking for a cure for a certain heart condition,” says Prof. Amit Klein, head of the Federman Center for Cyber Research at the Hebrew University of Jerusalem. “After a week, you’re surfing your favorite news site, and to your surprise, you notice that at the top of the page there’s a banner ad for the drug you were looking for. Okay, strange, but not terrible – right? But another week passes, and you log in through the university’s network at all, and you’re looking to buy health insurance – but the insurance company is offering you broader and more expensive medical coverage. Why? Because it knows you were looking for information about a cure for heart disease.”
Behind the scenes, says Prof. Klein, all these sites cooperate. Even if we change networks, change browsers, and change usernames – as long as we are surfing through the same device, the sites know it is us. Yes, even if we are surfing secretly (incognito mode).
The question is: How do different websites manage to identify us even when we switch networks, browsers, or users?
Such tracking is called cross-site tracking, and in principle there is no problem with it: there are technologies such as third-party cookies that allow completely different websites to collect data about us across the web.
“But today browsers are much more aware of the importance of privacy, and they block and reduce such tracking technologies,” says Prof. Klein. “But the fact is that we are still being tracked between websites. Advertisers, websites and other players are looking for other methods of identification. That’s what my research is about: a specific type of identification method. I found techniques for identifying the device, the computer, using fields in TCP/IP, which its operating system sends as part of the communication protocol between the device and the website. In other words, it doesn’t matter if you switch to Chrome or Firefox, log in as a different user or connect via a different network – I still know it’s you based on the device’s operating system. As long as you don’t reboot the device, I’ll know it’s you on any website on the Internet.”
Prof. Klein emphasizes that he acts ethically and responsibly, and long before the scientific studies on the vulnerabilities he finds are published, he contacts the technology giants and warns them about the vulnerabilities in the operating systems.
“I contact Microsoft or Apple and say, fix this and that loophole in Windows or iOS, and they actually fix it. Every time I find such a technique in a protocol that allows cross-site tracking, I first contact the company and share the technique I found. I say, ‘Hello, I’m a security researcher, and I found a loophole in yours,’ and they go and close it. It’s a public service. They’re happy and I’m happy. I started looking for such loopholes in protocol fields back in my PhD, and I continue to do so to this day. There’s more work to do.”
Prof. Amit Klein finds loopholes in operating systems that allow us to be tracked across websites
As for the claim that tracking also benefits users, as it allows for tailored advertisements that are relevant to their interests, Prof. Klein agrees – with one important caveat.
“There is no doubt that there are also good uses for tracking. If I was searching for a cure for heart disease, and then an advertisement for that medicine appears on another website, I might click on that advertisement because it is relevant to me – right? However, the moment I am asked to pay hundreds of shekels more every month for insurance, at that moment I realize that the loss of my privacy has a price. Therefore, my position is simple: there is no problem with tracking between websites, as long as the surfer is aware of it and gives his consent to it. Moreover, when I contact Microsoft, for example, and warn about such a loophole in the Windows system – it can decide that instead of closing the loophole, it hangs a huge banner every time Windows is entered: 'Our operating system allows websites to track you,' but of course it will not do that, because such a step would be very unpopular.”
This is just one aspect of Prof. Klein's research – which explores many aspects of network and operating system security. But it seems to be one that particularly concerns us, as it directly affects our privacy.
Short FAQ
What is cross-site tracking?
Cross-site tracking is the collection of information about a user as they browse different websites, with the aim of identifying them and building an activity profile.
Is such tracking done only using cookies?
No. Third-party cookies are a well-known method, but there are also other methods, including identifying device, browser, or operating system characteristics.
What did Prof. Amit Klein find?
According to him, a device can be identified using certain fields in the TCP/IP protocols that the operating system sends as part of Internet communication.
Why is this important for privacy?
Because such methods may allow a user to be identified even when they change browsers, networks, or user accounts, and sometimes without the user being aware of it.
Is all tracking problematic?
Not necessarily. Tracking can be used to tailor services and advertisements, but the problem begins when it is done without the user's awareness and consent.
More of the topic in Hayadan: