Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Deanonymize Facebook Users by Exploiting CSP-Implementation of Google Chrome (myseosolution.de)
10 points by Hirnhamster on Aug 14, 2014 | hide | past | favorite | 1 comment



Short summary:

By exploiting a flawed implementation of the content security policy in Google Chrome it's possible to identify a (random) user's Facebook profile. At least Google Plus and Youtube are vulnerable as well.

The technique is based on an intelligent "bruteforcing" of URLs in the CSP Header by using a binary search.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: