URL Shortening Security and Privacy Risks
Having travelled to Dublin the day before the training courses begin at OWASP AppSec Europe 2011, I have had time to catch up on some reading in my accommodation at Trinity College.
Alexander Neumann, Johannes Barnickel, Ulrike Meyer of the IT Security Group at RWTH Aachen University have published Security and Privacy Implications of URL Shortening Services. The paper includes a thorough review of related work and their own research into the security and privacy risks of URL shortening services (USS).
The risks discussed include:
- redirecting people to malicious web sites
- exposure of "secret URLs" (by search engine or enumeration)
- tracking by the USS provider
- information leakage (via HTTP referer header)
- use to attack web sites
- loss of shortened URL
- SSL-only circumvention
The paper is a useful reference for undertaking privacy impact assessments (PIAs) relating to the use of USS, or for designing similar systems.
On a related topic, Elke Roth-Mandutz from Georg Simon Ohm University, is discussing "A Critical Look at the Classification Schemes for Privacy Risks" at AppSec EU this Friday morning.
I will keep you updated with the talks I attend on Thursday and Friday.
Posted on: 07 June 2011 at 07:29 hrs

Comments are filtered automatically and should appear shortly after they been checked.