[saag] Re: Covert Web-to-App Tracking via Localhost

Shivan Kaul Sahib <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAG3f7MgVL-QMwmy5oGbY1E8YQL4ULHfM1m5f9WK-LEDBC4627w@mail.gmail.com>
Just FYI, this paper ("Covert Web-to-App Tracking via Localhost") will be
presented at the upcoming PEARG session on Friday (Session II, the session
after SAAG):
https://datatracker.ietf.org/meeting/123/materials/agenda-123-pearg

On Wed, 4 Jun 2025 at 06:55, John Mattsson <john.mattsson=
[email protected]> wrote:

> Hi,
>
> A recently published attack [1] showcases how IETF-developed technologies
> can be (and are being) exploited to perform severe privacy intrusions. The
> assumptions baked into many protocols — that endpoints are inherently
> trustworthy — no longer hold in a world dominated by data-hoarding,
> surveillance-driven tech giants.
>
>
>
> This is not a theoretical threat. It is an operational, real-world
> exploitation of protocol designs that have prioritized endpoint trust over
> user privacy. The attack demonstrates how easily users’ data can be
> exfiltrated via mechanisms that were standardized with good intentions but
> deployed in environments that weaponize those intentions against the users
> they’re meant to protect.
>
>
>
> The Snowden revelations over a decade ago should have been the final
> warning bell. They revealed the extent to which surveillance capabilities
> can be embedded and abused by leveraging assumptions in infrastructure and
> endpoint control. Yet, the IETF and many “privacy” groups continues to
> treat endpoints as trustworthy.
>
>
>
> How long will the IETF continue to design protocols under the illusion
> that endpoints act in the interest of the user? How long will it allow its
> standards to be co-opted by corporations whose business models rely on the
> systematic exploitation of privacy-sensitive data?
>
>
>
> It is long past time for the IETF to reconsider its architectural
> assumptions. Trust should not be assigned freely to endpoints, especially
> in an environment where users have little choice or visibility into what
> those endpoints actually do. Privacy cannot survive if protocol design
> continues to ignore adversarial endpoints as a realistic and pervasive
> threat model.
>
>
>
> I urge the broader Internet community to reevaluate current approaches,
> and to prioritize user privacy and safety over monetary donations from
> data-hoarding, surveillance-driven tech giants.
>
>
>
> Cheers,
>
> John
>
> [1] https://localmess.github.io/
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.