Re: [Full-disclosure] Using CSS :visited to steal your history (again, zzzz...)

2013-05-05 Thread Dan Kaminsky
...you are a magnificent bastard. On Sun, May 5, 2013 at 5:43 PM, Michal Zalewski wrote: > I guess this may be somewhat amusing... > > As you probably know, most browser vendors have fixed the ability to > enumerate your browsing history through the CSS :visited > pseudo-selector. The fix sever

[Full-disclosure] Using CSS :visited to steal your history (again, zzzz...)

2013-05-05 Thread Michal Zalewski
I guess this may be somewhat amusing... As you probably know, most browser vendors have fixed the ability to enumerate your browsing history through the CSS :visited pseudo-selector. The fix severely constraints the styling possible for visited links, and hides it from APIs such as window.getCompu