A First Look at the Privacy Harms of the Public Suffix List

McQuistin, S. , Snyder, P., Perkins, C. , Haddadi, H. and Tyson, G. (2023) A First Look at the Privacy Harms of the Public Suffix List. In: 23rd ACM Internet Measurement Conference (IMC '23), Montréal, QC, Canada, 24-26 Oct 2023, pp. 383-390. ISBN 9798400703829 (doi: 10.1145/3618257.3624836)

[img] Text
305977.pdf - Accepted Version
Available under License Creative Commons Attribution.

847kB

Abstract

The public suffix list is a community-maintained list of rules that can be applied to domain names to determine how they should be grouped into logical organizations or companies. We present the first large-scale measurement study of how the public suffix list is used by open-source software on the Web and the privacy harm resulting from projects using outdated versions of the list. We measure how often developers include out-of-date versions of the public suffix list in their projects, how old included lists are, and estimate the real-world privacy harm with a model based on a large-scale crawl of the Web. We find that incorrect use of the public suffix list is common in open-source software, and that at least 43 open-source projects use hard-coded, outdated versions of the public suffix list. These include popular, security-focused projects, such as password managers and digital forensics tools. We also estimate that, because of these out-of-date lists, these projects make incorrect privacy decisions for 1313 effective top-level domains (eTLDs), affecting 50,750 domains, by extrapolating from data gathered by the HTTP Archive project.

Item Type:Conference Proceedings
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:McQuistin, Dr Stephen and Perkins, Dr Colin
Authors: McQuistin, S., Snyder, P., Perkins, C., Haddadi, H., and Tyson, G.
College/School:College of Science and Engineering > School of Computing Science
ISBN:9798400703829
Copyright Holders:Copyright © 2023 The Authors
First Published:First published in 23rd ACM Internet Measurement Conference (IMC '23): 383-390
Publisher Policy:Reproduced in accordance with the publisher copyright policy
Related URLs:

University Staff: Request a correction | Enlighten Editors: Update this record

Project CodeAward NoProject NamePrincipal InvestigatorFunder's NameFunder RefLead Dept
304292Streamlining Social Decision Making for Improved Internet StandardsColin PerkinsEngineering and Physical Sciences Research Council (EPSRC)EP/S036075/1Computing Science