Google inotarisira kumira kutsigira wechitatu-bato makuki muChrome panosvika 2022

Google yakaziviswa yechinangwa mukati memakore maviri anotevera kumisa zvachose rutsigiro muChrome kune wechitatu-bato makuki akafumurwa kana uchiwana mawebhusaiti kunze kweiyo domain yeizvino peji. Makuki akadaro anoshandiswa kuteedzera mafambiro evashandisi pakati pemasaiti mune kodhi yekushambadzira network, social network widget uye web analytics system.

Uyewo akazivisa nezuro chinangwa chekubatanidza Mushandisi-Mumiriri musoro, kurambwa kwechitatu-bato Cookies kuri kuenderera mberi sechikamu chedanho. Zvekuvanzika Sandboxyakanangana nekuwana kuwirirana pakati pekudiwa kwevashandisi kuchengetedza zvakavanzika uye chishuwo chekushambadzira network nemasaiti kuteedzera zvido zvevashanyi. Kusvikira kupera kwegore rino mumodhi mavambo kuedza inotarisirwa kuverengerwa mubrowser mamwe maAPI kuyera shanduko uye kugadzirisa ads pasina kushandisa yechitatu-bato makuki.

Kuti uone chikamu chezvido zvevashandisi pasina chiziviso chemunhu uye pasina kutaurwa kune nhoroondo yekushanyira chaiwo masaiti, kushambadzira network inokurudzirwa kushandisa iyo API. Floc, kuongorora basa remushandisi mushure mekuchinja kune ads - API Chiyero chekushandura, uye kuparadzanisa vashandisi pasina kushandisa cross-saiti identifiers - API Trust Chiratidzo. Kuvandudzwa kwezvakatemwa zvine chekuita nekuratidzwa kwekwakanangwa kushambadzira
pasina kukanganisa zvakavanzika boka rinoshanda rakaparadzanayakagadzirwa neW3C.

Parizvino, mumamiriro ekudzivirira kubva mukufambiswa kwemakuki panguva CSRF inorwisa inoshandisa iyo SameSite hunhu hwakatsanangurwa muSet-Cookie musoro, iyo kubva Chrome 76 yakaiswa ku "SameSite=Lax" nekusarudzika, kurambidza kutumira maCookie ekuisirwa kubva kune yechitatu-bato masaiti, asi mawebhusaiti anogona kudarika kurambidzwa nekuisa pachena Cookie kuSameSite=Hapana . Iwo SameSite hunhu hunogona kutora maviri maitiro, 'akasimba' kana 'kurembesa'. Mune 'yakasimba' modhi, makuki anochengetwa kuti arege kutumirwa kune chero rudzi rwekuyambuka-saiti chikumbiro. Mune 'lax' modhi, zvakarerutswa zvirambidzo zvinoshanda uye kufambisa kwekuki kunovharwa chete kune mhiri-saiti subrequests, sekukumbira mufananidzo kana kudhawunirodha zvirimo kuburikidza neiframe.

Chrome 80, yakarongerwa Kukadzi 4, ichava nechirambidzo chakasimba chinodzivirira echitatu-bato makuki kuti asagadziriswe kune zvisiri zveHTTPS zvikumbiro (ine iyo SameSite=Hapana hunhu, Cookies inogona chete kusetwa mune Yakachengeteka mode). Pamusoro pezvo, basa rinoenderera mberi pakuitwa kwezvishandiso zvekuona nekudzivirira kubva pakushandiswa kwenzira dzekunzvenga dzekutevera nekuzivikanwa kwakavanzika ("browser fingerprinting").

Rangarira kuti muFirefox, kubva pakaburitswa 69, Makuki eese echitatu-bato rekutevera masisitimu anongove asina kufuratirwa. Google inoona kuvharika uku sekwakarurama, asi zvinoda gadziriro yeWebhu ecosystem uye kupihwa kwemamwe maAPI ekuita mabasa ayo echitatu-bato makuki aimboshandiswa, pasina kutyora zvakavanzika uye pasina kukanganisa maitiro ekuita mari emasaiti anotsigirwa nemari. . Mukupindura kuvharisa makuki pasina kupa imwe imwe nzira, ad network haina kumira kuteedzera, asi yakangoenda kune dzimwe nzira dzakaomarara zvichienderana nekuzivikanwa kwemushandisi wakavanzika (fingerprinting) kana kuburikidza. zvisikwa ye tracker yehotera subdomain mudura resaiti iyo ad inoratidzwa.

Source: opennet.ru

Voeg