Cross browser/incognito PII tracking |
||
Issue descriptionWhat steps will reproduce the problem? 1. Visit https://www.shinesty.com 2. Should be your first visit, should get a pop-up for emails/newsletters 3. Provide any random email address, "SomethingSuperSpammy@gmail.com" 4. Click on Submit 5. Visit the Account login page by clicking the 'person' icon in the upper right. 6. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form. 7. Open an Incognito instance and visit the same login page. 8. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form. 9. Open Firefox and visit the same login page. 10. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form. 11. Open an instance of Private Browsing in Firefox 12. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form. What is the expected result? Firefox, Incognito, and Private Browsing (FF) should not be auto-populating that email address. What happens instead of that? The email address is being pre-populated by the site which means I'm being tracked across platforms. This shouldn't be possible. Please provide any additional information below. Attach a screenshot if possible. I've reproduced this on my home computer, my phone, and my pixel book. Tracking is limited to the device. Clearing cookies/cache/etc...hasn't helped. I've not been able to repro it multiple times on the same device, it seems to start with that first 'email sign up' box. UserAgentString: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
,
Nov 9
Just to clarify, can we reproduce the tracking between Chrome regular mode -> Chrome Incognito Firefox regular mode -> Firefox Private Browsing Or also Chrome->Firefox? Which would mean fingerprinting not just the browser, but the OS (and likely primarily IP) itself?
,
Nov 9
I was able to reproduce it on my gLinux workstation and on my Pixel book, but not my Windows 10 PC at home.
,
Nov 13
I could repro across Chrome and Firefox, but changing my IP destroyed the repro. Thus it seems pretty sure that the website is using IP address for tracking. Unfortunately there's nothing we can do at this time. Closing this issue, but thanks for reporting anyways! |
||
►
Sign in to add a comment |
||
Comment 1 by tna...@google.com
, Nov 9Labels: -Pri-3 Pri-1
Owner: tnagel@chromium.org
Status: Assigned (was: Untriaged)