UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

CoStricTor: Collaborative HTTP Strict Transport Security in Tor Browser

Davitt, Killian; Ristea, Dan; Russell, Duncan; Murdoch, Steven J; (2024) CoStricTor: Collaborative HTTP Strict Transport Security in Tor Browser. Proceedings on Privacy Enhancing Technologies , 2024 (1) pp. 343-356. 10.56553/popets-2024-0020. (In press). Green open access

[thumbnail of popets-2024-0020.pdf]
Preview
Text
popets-2024-0020.pdf - Published Version

Download (1MB) | Preview

Abstract

HTTP Strict Transport Security (HSTS) is a widely-deployed security feature in modern web browsing. It is also, however, a potential vector for user tracking and surveillance. Tor Browser, a web browser primarily concerned with online anonymity, disables HSTS as a result of this tracking potential. We present the CoStricTor protocol which crowdsources HSTS data among Tor Browser clients. It gives Tor Browser users increased resistance to man-in-the-middle attacks without exposing them to HSTS tracking. Our protocol adapts other privacy-preserving data aggregation algorithms to share data effectively among users with strong local differential privacy guarantees. The CoStricTor protocol resists denial of service attacks by design through our innovative use of Bloom filters to represent complementary data. Our simulations show our protocol can model up to 150,000 websites, providing 10,000 upgrades to HSTS for users.

Type: Article
Title: CoStricTor: Collaborative HTTP Strict Transport Security in Tor Browser
Open access status: An open access version is available from UCL Discovery
DOI: 10.56553/popets-2024-0020
Publisher version: https://doi.org/10.56553/popets-2024-0020
Language: English
Additional information: This article is published under a Creative Commons Attribution 4.0 license. https://creativecommons.org/licenses/by/4.0/
Keywords: anonymous communications, differential privacy, web privacy
UCL classification: UCL
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science
URI: https://discovery.ucl.ac.uk/id/eprint/10181054
Downloads since deposit
68Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item