Sciweavers

POPETS
2016

Are You Sure You Want to Contact Us? Quantifying the Leakage of PII via Website Contact Forms

8 years 19 days ago
Are You Sure You Want to Contact Us? Quantifying the Leakage of PII via Website Contact Forms
: The majority of commercial websites provide users the ability to contact them via dedicated contact pages. In these pages, users are typically requested to provide their names, email addresses, and reason for contacting the website. This effectively makes contact pages a gateway from being anonymous or pseudonymous, i.e., identified via stateful and stateless identifiers, to being eponymous. As such, the environment where users provide their personally identifiable information (PII) has to be trusted and free from intentional and unintentional information leaks. In this paper, we report on the first large-scale study of PII leakage via contact pages of the 100,000 most popular sites of the web. We develop a reliable methodology for identifying and interacting with contact forms as well as techniques that allow us to discover the leakage of PII towards thirdparties, even when that information is obfuscated. Using these methods, we witness the leakage of PII towards third-parties ...
Oleksii Starov, Phillipa Gill, Nick Nikiforakis
Added 09 Apr 2016
Updated 09 Apr 2016
Type Journal
Year 2016
Where POPETS
Authors Oleksii Starov, Phillipa Gill, Nick Nikiforakis
Comments (0)