Member-only story

One Click May Reveal Your Naughty Page

Tom Smykowski
3 min readAug 4, 2023

--

Researchers are working relentlessly to make the browsing the safest experience possible. One of the honeypots are links.

Links have different state based if you visited a page before or not. Regular color for a not visited page is blue, while for visited is dark violet (#551A8B).

At least these were the colors used for years. Then CSS allowed us to change these colors, so some pages use different ones. Sometimes they even don’t differentiate between, a bad practice, because you want to know what link you’ve visited so far.

Anyway, the color changing feature of links doesn’t let security researchers sleep like a baby. Because sometimes a website can discover what color is the link, hence, learn if you visited a particular website or not.

In case of legitimate websites it’s not a big deal, but for malicious trackers and hackers an information of what pages you’ve visited is useful.

Varun Biniwale, web developer and cybersecurity researcher demonstrated in March 2022 that it’s possible to trick you into revealing pages you visited with a captcha.

Before you read further. Check it out. Because below is the explanation how it works!

The method he introduced is based on the fact that you can set not only a different color for the…

--

--

Tom Smykowski
Tom Smykowski

Written by Tom Smykowski

🚀 Senior/Lead Frontend Engineer | Angular · Vue.js · React | Design Systems, UI/UX | Looking for a new project! 📩 contact@tomasz-smykowski.com

Responses (1)