A First Look at the Privacy Harms of the Public Suffix List

Stephen McQuistin, Peter Snyder, Colin Perkins, Hamed Haddadi, Gareth Tyson

Research output: Chapter in Book/Conference Proceeding/ReportConference Paper published in a bookpeer-review

Abstract

The public suffix list is a community-maintained list of rules that can be applied to domain names to determine how they should be grouped into logical organizations or companies. We present the first large-scale measurement study of how the public suffix list is used by open-source software on the Web and the privacy harm resulting from projects using outdated versions of the list. We measure how often developers include out-of-date versions of the public suffix list in their projects, how old included lists are, and estimate the real-world privacy harm with a model based on a large-scale crawl of the Web. We find that incorrect use of the public suffix list is common in open-source software, and that at least 43 open-source projects use hard-coded, outdated versions of the public suffix list. These include popular, security-focused projects, such as password managers and digital forensics tools. We also estimate that, because of these out-of-date lists, these projects make incorrect privacy decisions for 1313 effective top-level domains (eTLDs), affecting 50,750 domains, by extrapolating from data gathered by the HTTP Archive project.

Original languageEnglish
Title of host publicationIMC 2023 - Proceedings of the 2023 ACM on Internet Measurement Conference
PublisherAssociation for Computing Machinery
Pages383-390
Number of pages8
ISBN (Electronic)9798400703829
DOIs
Publication statusPublished - 24 Oct 2023
Event23rd ACM Internet Measurement Conference, IMC 2023 - Montreal, Canada
Duration: 24 Oct 202326 Oct 2023

Publication series

NameProceedings of the ACM SIGCOMM Internet Measurement Conference, IMC
ISSN (Print)2150-3761

Conference

Conference23rd ACM Internet Measurement Conference, IMC 2023
Country/TerritoryCanada
CityMontreal
Period24/10/2326/10/23

Bibliographical note

Publisher Copyright:
© 2023 ACM.

Keywords

  • domain boundaries
  • web privacy

Fingerprint

Dive into the research topics of 'A First Look at the Privacy Harms of the Public Suffix List'. Together they form a unique fingerprint.

Cite this