X-Client-Data mutu ngati njira yodziwira ogwiritsa ntchito Chrome

Pokambirana zoyeserera Google kuti igwirizanitse zomwe zili pamutu wa HTTP User-Agent, wopanga msakatuli wa Kiwi anazindikira kupita kumutu wa "X-Client-Data" HTTP wotsalira mu Chrome, womwe ungathe akuphwanya General Data Protection Regulation ikugwira ntchito ku European Union (GDPR). Nthawi zokambirana Uwiri wa zochita za Google adatsutsidwanso, zomwe kumbali imodzi amalimbikitsa njira kuletsa chizindikiritso chobisika ndikutsata zochita za ogwiritsa ntchito, koma kumbali ina, sikuli kofulumira kuchotsa kuthandizira mutu wa X-Client-Data kuchokera ku Chrome, womwe ungagwiritsidwe ntchito kuzindikira zochitika za osatsegula mukapeza mautumiki a Google.

Mutu wa X-Client-Data siwobisika ndipo machitidwe ake ndi anafotokoza mu zolembedwa. Kupyolera mu X-Client-Data, Google imalandira deta pazochitika zina zoyesera mu Chrome zokhudzana ndi masamba ake (mwachitsanzo, poyesera, Google ikhoza kuyambitsa zina zoyesera mu Youtube ngati zithandizidwa ndi osatsegula kapena kuyesa gwirizanitsani mavuto ndi ntchito zoyeserera zoyambitsa).

Mutu zowonetsedwa zongopempha kumawebusayiti a Google omwe akufanana ndi masks "*.doubleclick.net", "*.googlesyndication.com", "www.googleadservices.com", "*.google.TLD>" ndi "*.youtube. ", ndikutumizidwa kudzera pa HTTPS. Mu mawonekedwe a incognito, mutuwo sunakhale ndi anthu, koma ngati mbiri ya Google yotsimikizika ya wosuta isintha kukhala mbiri ya alendo kapena pamene ntchito yochotsa deta imatchedwa, mutuwo sunakhazikitsidwenso ndipo ukupitiriza kutumizidwa ndi mtengo womwewo.

X-Client-Data mutu ngati njira yodziwira ogwiritsa ntchito Chrome

Mutuwu akuti ulibe zambiri zodziwikiratu ndipo umangofotokoza momwe Chrome yakhazikitsira komanso zoyeserera. Ngati msakatuli wogwiritsa ntchito telemetry ndi malipoti osokonekera azimitsidwa pazikhazikiko, kupanga mutu wa X-Client-Data woyambira umagwiritsa ntchito ma bits 13 okha a entropy (zophatikiza 8000 zosiyanasiyana), zomwe sizokwanira kuzizindikiritsa.

Popeza mutuwo umayikanso zosintha zina zamakina ndi magawo, pamapeto pake zomwe zili mu X-Client-Data ndizoyeneranso ngati gwero lowonjezera lachidziwitso cha ogwiritsa ntchito munthawi yochepa (zoyeserera zimathandizidwa ndikuzimitsa pakapita nthawi, zomwe zimatsogolera ku kusintha kwanthawi ndi nthawi kwa X-Client-Data).

Komabe, kuwonjezera pa entropy yoyambirira, popanga mtengo wa X-Client-Data, palinso mndandanda wambewu womwe umabwezedwa ndi ma seva a Google komanso kutengera dziko, adilesi ya IP ndi njira zina zomwe Google imawona kuti ndizofunikira (mwachitsanzo, palibe chomwe chimalepheretsa. simukubweretsanso mndandanda waukulu wachisawawa , womwe udzakhala chizindikiritso chenicheni).
Kuphatikiza apo, kuyang'ana pogwiritsa ntchito masks a domain la Google potumiza X-Client-Data sikumapatula nthawi pomwe wowukira amatha kulembetsa domain ngati "youtube.xn--55qx5d" ndikuyamba kutolera zozindikiritsa.

Source: opennet.ru

Kuwonjezera ndemanga