New issue
Advanced search Search tips

Issue 902461 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Nov 13
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: ----



Sign in to add a comment

Cross browser/incognito PII tracking

Project Member Reported by strydercrown@google.com, Nov 6

Issue description

What steps will reproduce the problem?

1. Visit https://www.shinesty.com
2. Should be your first visit, should get a pop-up for emails/newsletters
3. Provide any random email address, "SomethingSuperSpammy@gmail.com"
4. Click on Submit
5. Visit the Account login page by clicking the 'person' icon in the upper right.
6. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form.

7. Open an Incognito instance and visit the same login page.
8. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form.

9. Open Firefox and visit the same login page.
10. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form.

11. Open an instance of Private Browsing in Firefox
12. Verify that the email address "SomethingSuperSpammy@gmail.com" appears in the email address field of the login form.


What is the expected result?
Firefox, Incognito, and Private Browsing (FF) should not be auto-populating that email address.


What happens instead of that?
The email address is being pre-populated by the site which means I'm being tracked across platforms. This shouldn't be possible. 

Please provide any additional information below. Attach a screenshot if
possible.

I've reproduced this on my home computer, my phone, and my pixel book. Tracking is limited to the device.  Clearing cookies/cache/etc...hasn't helped.  I've not been able to repro it multiple times on the same device, it seems to start with that first 'email sign up' box.  

UserAgentString: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36



 
Components: -Privacy Privacy>Fingerprinting
Labels: -Pri-3 Pri-1
Owner: tnagel@chromium.org
Status: Assigned (was: Untriaged)
Thanks for the report! I could repro in incognito mode, closing and reopening the incognito window between the first and the second visit.
Just to clarify, can we reproduce the tracking between

Chrome regular mode -> Chrome Incognito
Firefox regular mode -> Firefox Private Browsing

Or also Chrome->Firefox? Which would mean fingerprinting not just the browser, but the OS (and likely primarily IP) itself?
I was able to reproduce it on my gLinux workstation and on my Pixel book, but not my Windows 10 PC at home. 
Status: WontFix (was: Assigned)
I could repro across Chrome and Firefox, but changing my IP destroyed the repro. Thus it seems pretty sure that the website is using IP address for tracking. Unfortunately there's nothing we can do at this time. Closing this issue, but thanks for reporting anyways!

Sign in to add a comment