07 June 2011

URL Shortening Security and Privacy Risks

Having travelled to Dublin the day before the training courses begin at OWASP AppSec Europe 2011, I have had time to catch up on some reading in my accommodation at Trinity College.

Photograph of a white van parked at Trinity College Dublin, with the words 'Trinity College Security Emergency Line 01 896 1999' written on the side

Alexander Neumann, Johannes Barnickel, Ulrike Meyer of the IT Security Group at RWTH Aachen University have published Security and Privacy Implications of URL Shortening Services. The paper includes a thorough review of related work and their own research into the security and privacy risks of URL shortening services (USS).

The risks discussed include:

  • redirecting people to malicious web sites
  • exposure of "secret URLs" (by search engine or enumeration)
  • tracking by the USS provider
  • information leakage (via HTTP referer header)
  • use to attack web sites
  • loss of shortened URL
  • SSL-only circumvention

The paper is a useful reference for undertaking privacy impact assessments (PIAs) relating to the use of USS, or for designing similar systems.

On a related topic, Elke Roth-Mandutz from Georg Simon Ohm University, is discussing "A Critical Look at the Classification Schemes for Privacy Risks" at AppSec EU this Friday morning.

I will keep you updated with the talks I attend on Thursday and Friday.

Posted on: 07 June 2011 at 07:29 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
URL Shortening Security and Privacy Risks
http://www.clerkendweller.com/2011/6/7/URL-Shortening-Security-and-Privacy-Risks
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2011/6/7/URL-Shortening-Security-and-Privacy-Risks
Requested by 38.107.179.224 on Thursday, 17 May 2012 at 23:13 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2011-2012 clerkendweller.com