{"id":8760,"date":"2018-11-14T09:00:11","date_gmt":"2018-11-14T17:00:11","guid":{"rendered":"https:\/\/www.privateinternetaccess.com\/blog\/?p=8760"},"modified":"2024-01-28T02:14:58","modified_gmt":"2024-01-28T10:14:58","slug":"supercookey-a-supercookie-built-into-tls-1-2-and-1-3","status":"publish","type":"post","link":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/","title":{"rendered":"SuperCooKey &#8211; A SuperCookie Built Into TLS 1.2 and 1.3"},"content":{"rendered":"<p>In doing my research around the impact of TLS 1.3 for Private Internet Access, I came across some peculiar items in the new standards.<\/p>\n<p>TLS 1.3 represents a relatively large shift in cryptography, so much so that it was debated whether it should be called TLS 2.0 rather than 1.3. It throws away a lot of old cryptography in favor of newer algorithms that adhere to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Forward_secrecy\">perfect forward secrecy<\/a>. That is, by never reusing security keys throughout multiple sessions, you gain privacy and security benefits.<\/p>\n<h2>The Benefits of Perfect Forward Secrecy are Two-Fold:<\/h2>\n<p><strong>Security:<\/strong> Cryptography using ephemeral (one-time) keys is harder to break, because an attacker has to break each session to fully decrypt a user. With static (unchanging) keys, you are reusing the same keys for every session, which means that if one session is broken through a security vulnerability or bad cryptography, all of the previous sessions are also broken because they were using the same keys.<\/p>\n<p><strong>Privacy:<\/strong> If you\u2019re not signing in to a website, and not outed through other browser settings, an ephemeral session should look like a new visit every time you go to a website, because you\u2019re using a new secure session on each visit.<\/p>\n<h2>One of the Flagship Features of TLS 1.3 Abandons the Privacy Benefit:<\/h2>\n<p>TLS 1.3 has a heavily touted feature called 0-RTT that has been paraded by <a href=\"https:\/\/blog.cloudflare.com\/introducing-0-rtt\/\">CloudFlare<\/a> as a huge speed benefit to users because it allows sessions to be resumed quickly from previous visits. This immediately raised an eyebrow for me because this means that full negotiation is not taking place.<\/p>\n<p>After more research, I\u2019ve discovered that 0-RTT <a href=\"https:\/\/eprint.iacr.org\/2017\/223.pdf\">does skip renegotiation steps that involve generating new keys<\/a>.<\/p>\n<blockquote>\n<div>As authentication and establishment of cryptographic keys in 0-RTT without prior knowledge is impossible, 0-RTT key-exchange protocols must leverage keying material obtained in some prior communication to establish 0-RTT keys.<\/div>\n<\/blockquote>\n<div><\/div>\n<p>This means that every time 0-RTT is used, the server knows that you\u2019ve been to the site before, and it knows all associated IPs and sign-in credentials attached to that particular key.<\/p>\n<h2>Hand Waving by the Security Community Ignores Serious Privacy Risks:<\/h2>\n<p>\u201cThat\u2019s just surveillance with extra steps!\u201d<\/p>\n<p>The 0-RTT design focuses on keeping \u201cforward secrecy\u201d by changing the keys between each session in a predictable way (hashing \/ salting \/ raising the key by an exponent \/ etc) to generate a new key. This (sort of) fixes the security problems with 0-RTT, but this has multiple serious privacy problems that are not forward secret.<\/p>\n<p>1. The client has to store this key for future use, instead of destroying it. This opens up these stored session keys to the attack surface of the entire web browser for the time period that the session information is stored.<\/p>\n<p>2. The server has to store this key for future use, instead of destroying it. This means that the TLS 1.3 0-RTT process is fundamentally flawed, as it specifically requires the server to delete information with no verifiable method of doing so. This means that a malicious server can easily follow these keys without deleting them, and associate the 0-RTT session with all previous visits from that original first key. <strong>A design that requires internet users to \u201ctrust\u201d that no one will do this is a fundamentally broken design.<\/strong><\/p>\n<p>Here is further scholarly research on how damaging these security practices can be:<br>\n<a href=\"https:\/\/jhalderm.com\/pub\/papers\/forward-secrecy-imc16.pdf\">https:\/\/jhalderm.com\/pub\/papers\/forward-secrecy-imc16.pdf<\/a><\/p>\n<p>An excerpt from section 7 of the paper:<\/p>\n<blockquote>\n<div>In particular, the \u201cshape\u201d of the vulnerability windows created by session tickets is ideally suited for exploitation by intelligence agencies for surveillance purposes.<\/div>\n<\/blockquote>\n<h2>The Use-Case That is Threatened by 0-RTT: Privacy Networks<\/h2>\n<p>This means that not only can websites track your sessions across all known IPs, but that large networks that you frequently hit (think Google Analytics, Google AMP, CloudFlare, Facebook, Twitter, JS libraries, Amazon Web Services, Microsoft Azure etc) can follow you all over the internet and link all of your activity across many sessions.<\/p>\n<h2>What This Looks Like \u2013 Identifying a VPN user using 0-RTT<\/h2>\n<p>For a real world example that demonstrates this issue, I visited a TLS 1.3 enabled site with a default build of the latest Firefox. I then closed the browser, signed on to a VPN service, and then visited the same website. While everything on the surface looks the same when you do this, and your IP address is functionally different, under the hood we have a problem. Here\u2019s a WireShark of that second visit:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-8952\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/tls-early-data-cloudflare-1024x659.png\" alt=\"\" width=\"840\" height=\"541\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/tls-early-data-cloudflare-1024x659.png 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/tls-early-data-cloudflare-300x193.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/tls-early-data-cloudflare-768x494.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/tls-early-data-cloudflare.png 1132w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>To be clear, this pre_shared_key identity is uniquely linked to you. Using privacy services with this feature enabled is like putting on a disguise to get into a bar you were kicked out of, and then handing the bouncer your photo ID.<\/p>\n<h2>The Problem is Worse in TLS 1.2<\/h2>\n<p>0-RTT is an \u201cimprovement\u201d over a prior implementation of early_data that applies similar principles. 0-RTT is better in that it doesn\u2019t continuously re-use the same static key, and at least changes it from session to session, making it harder for a man in middle to learn the shared secret. However, to gain the performance edge in 0-RTT, session resumption has to be carried out without replay protection.<\/p>\n<p>In essence, the TLS 1.2 version of session resumption is less safe because the standard has no defined mechanism for changing keys like TLS 1.3s 0-RTT, and both the TLS 1.2 and TLS 1.3 versions of session resumption ignore the principal of ephemeral data and allow services to track users with very high accuracy.<\/p>\n<h2>Session IDs, Session Tickets, and 0-RTT are enabled by default in \u201cPrivate Mode\u201d on Firefox<\/h2>\n<p>This means that even while in private mode, and with privacy extensions installed in Firefox, this problem persists and can out you.<\/p>\n<h2>Mitigation in Firefox<\/h2>\n<p>To mitigate this, you need to be able to disable both TLS 1.2 and TLS 1.3 session resumption. There are four settings related to this scenario that we have to change to fully address the problem.<\/p>\n<pre id=\"ct-0\" class=\"comment-text \">security.ssl.disable_session_identifiers (hidden feature)\nsecurity.ssl.enable_false_start\nsecurity.tls.enable_0rtt_data\nprivacy.firstparty.isolate<\/pre>\n<h3>security.tls.enable_0rtt_data<\/h3>\n<p>This is the 0-RTT feature itself. Disabling this feature disables the ability for the server and browser to negotiate a 0-RTT connection using related keys and no replay protection.<\/p>\n<p>To disable 0-RTT: Type about:config into your navigation bar in Firefox. In the screen that pops up, enter security.tls.enable_0rtt_data into the search bar, and make sure that the setting is set to FALSE.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8620\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-0rtt.png\" alt=\"\" width=\"597\" height=\"169\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-0rtt.png 597w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-0rtt-300x85.png 300w\" sizes=\"auto, (max-width: 597px) 85vw, 597px\" \/><\/p>\n<p>Next, we have to disable the TLS 1.2 session resumption mechanisms. This prevents Firefox from being able negotiate session resumption using static session IDs or session tickets.<\/p>\n<h3>security.ssl.disable_session_identifiers (HIDDEN FEATURE)<\/h3>\n<p>To disable session identifiers: Type about:config into your navigation bar in Firefox, in the screen that pops up, you must right click on a blank area of the page and select new -&gt; boolean.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-9049\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-1024x278.png\" alt=\"\" width=\"840\" height=\"228\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-1024x278.png 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-300x81.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-768x209.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature.png 1123w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>In the window that pops up, we have to enter the exact name of the hidden feature: security.ssl.disable_session_identifiers and hit OK.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9050\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2.png\" alt=\"\" width=\"973\" height=\"547\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2.png 973w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2-300x169.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2-768x432.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Then we have to search for the feature that we added and make sure that it is set to TRUE.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9051\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3.png\" alt=\"\" width=\"797\" height=\"146\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3.png 797w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3-300x55.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3-768x141.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>The next two features help to isolate the problem, and explicitly prevent 3rd party services from tracking you by using session IDs, session tickets, and related keys.<\/p>\n<h3>privacy.firstparty.isolate<\/h3>\n<p>This feature prevents the browser from making requests to sites outside of the primary domain from the site. This prevents large ubiquitous services from following your keys around the web like a supercookie.<\/p>\n<p>To enable first party isolation: Type about:config into your navigation bar in Firefox. In the screen that pops up, enter privacy.firstparty.isolate into the search bar, and make sure that the setting is set to TRUE. (This setting can break websites that rely heavily on 3rd party libraries and scripts.)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9053\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate.png\" alt=\"\" width=\"994\" height=\"168\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate.png 994w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate-300x51.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate-768x130.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Lastly, we have to disable False Start. This is because it does not allow the client to fully complete its handshake before starting the actual session. There is more info here from the IETF:\u00a0<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7918\">https:\/\/tools.ietf.org\/html\/rfc7918#section-4<\/a> (See section 5. Security Considerations)<\/p>\n<p>To disable TLS false start: Type about:config into your navigation bar in Firefox. In the screen that pops up, enter security.ssl.enable_false_start into the search bar, and make sure that the setting is set to FALSE.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9054\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start.png\" alt=\"\" width=\"847\" height=\"142\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start.png 847w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start-300x50.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start-768x129.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start-846x142.png 846w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p><em><strong>The combination of these 4 changes restricts the browser to only using real ephemeral cryptography as the TLS 1.3 specification intends throughout the entirety of the rest of the standards. 0-RTT, Session Tickets, Session IDs, and other shortcuts undermine the progress that internet standards are making toward ubiquitous strong security and privacy on the web. In this case, a few milliseconds while loading a web page are saved by sacrificing fundamental privacy and security gains made over the last twelve years.<\/strong><\/em><\/p>\n<p>I am currently researching mitigations for this problem in Chrome, but full mitigation does not seem possible at this time. Contact me if you believe you know how to fully disable session IDs, session tickets, and 0-RTT in Chrome\/Chromium or other browsers, and I will edit in the mitigation here.<\/p>\n<p>Stay safe and private out there!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In doing my research around the impact of TLS 1.3 for Private Internet Access, I came across some peculiar items in the new standards. TLS 1.3 represents a relatively large shift in cryptography, so much so that it was debated whether it should be called TLS 2.0 rather than 1.3. It throws away a lot &hellip; <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SuperCooKey &#8211; A SuperCookie Built Into TLS 1.2 and 1.3&#8221;<\/span><\/a><\/p>\n","protected":false},"author":32,"featured_media":8944,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_stopmodifiedupdate":false,"_modified_date":"","footnotes":""},"categories":[12,1,1941],"tags":[85,141,132,857],"class_list":["post-8760","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-news","category-surveillance","tag-security-2","tag-tls","tag-tor","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SuperCooKey - A SuperCookie Built Into TLS 1.2 and 1.3<\/title>\n<meta name=\"description\" content=\"A privacy flaw in TLS encryption standards can out private users by exploiting related keys and associating them with identities, even with a new IP address.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SuperCooKey - A SuperCookie Built Into TLS 1.2 and 1.3\" \/>\n<meta property=\"og:description\" content=\"A privacy flaw in TLS encryption standards can out private users by exploiting related keys and associating them with identities, even with a new IP address.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\" \/>\n<meta property=\"og:site_name\" content=\"PIA\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/privateinternetaccess\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-14T17:00:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-28T10:14:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Derek Zimmer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@http:\/\/www.twitter.com\/ostifofficial\" \/>\n<meta name=\"twitter:site\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Derek Zimmer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\"},\"author\":{\"name\":\"Derek Zimmer\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1\"},\"headline\":\"SuperCooKey &#8211; A SuperCookie Built Into TLS 1.2 and 1.3\",\"datePublished\":\"2018-11-14T17:00:11+00:00\",\"dateModified\":\"2024-01-28T10:14:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\"},\"wordCount\":1502,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png\",\"keywords\":[\"security\",\"tls\",\"tor\",\"Vulnerability\"],\"articleSection\":[\"Cybersecurity\",\"General Privacy News\",\"Surveillance\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\",\"name\":\"SuperCooKey - A SuperCookie Built Into TLS 1.2 and 1.3\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png\",\"datePublished\":\"2018-11-14T17:00:11+00:00\",\"dateModified\":\"2024-01-28T10:14:58+00:00\",\"description\":\"A privacy flaw in TLS encryption standards can out private users by exploiting related keys and associating them with identities, even with a new IP address.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.privateinternetaccess.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SuperCooKey &#8211; A SuperCookie Built Into TLS 1.2 and 1.3\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"name\":\"PIA\",\"description\":\"Online privacy news from around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\",\"name\":\"Private Internet Access\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"width\":1200,\"height\":1200,\"caption\":\"Private Internet Access\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/privateinternetaccess\/\",\"https:\/\/x.com\/buyvpnservice\",\"https:\/\/www.instagram.com\/piavpn\/\",\"https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1\",\"name\":\"Derek Zimmer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g\",\"caption\":\"Derek Zimmer\"},\"description\":\"Derek is a cryptographer, security expert and privacy activist. He has twelve years of security experience and six years of experience designing and implementing privacy systems. He founded the Open Source Technology Improvement Fund (OSTIF) which focuses on creating and improving open-source security solutions through auditing, bug bounties, and resource gathering and management.\",\"sameAs\":[\"https:\/\/ostif.org\/\",\"https:\/\/www.linkedin.com\/in\/derek-zimmer-2164a441\/\",\"https:\/\/x.com\/http:\/\/www.twitter.com\/ostifofficial\"],\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/author\/derek-zimmer\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SuperCooKey - A SuperCookie Built Into TLS 1.2 and 1.3","description":"A privacy flaw in TLS encryption standards can out private users by exploiting related keys and associating them with identities, even with a new IP address.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/","og_locale":"en_US","og_type":"article","og_title":"SuperCooKey - A SuperCookie Built Into TLS 1.2 and 1.3","og_description":"A privacy flaw in TLS encryption standards can out private users by exploiting related keys and associating them with identities, even with a new IP address.","og_url":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/","og_site_name":"PIA","article_publisher":"https:\/\/www.facebook.com\/privateinternetaccess\/","article_published_time":"2018-11-14T17:00:11+00:00","article_modified_time":"2024-01-28T10:14:58+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png","type":"image\/png"}],"author":"Derek Zimmer","twitter_card":"summary_large_image","twitter_creator":"@http:\/\/www.twitter.com\/ostifofficial","twitter_site":"@buyvpnservice","twitter_misc":{"Written by":"Derek Zimmer","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#article","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/"},"author":{"name":"Derek Zimmer","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1"},"headline":"SuperCooKey &#8211; A SuperCookie Built Into TLS 1.2 and 1.3","datePublished":"2018-11-14T17:00:11+00:00","dateModified":"2024-01-28T10:14:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/"},"wordCount":1502,"commentCount":0,"publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png","keywords":["security","tls","tor","Vulnerability"],"articleSection":["Cybersecurity","General Privacy News","Surveillance"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/","name":"SuperCooKey - A SuperCookie Built Into TLS 1.2 and 1.3","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png","datePublished":"2018-11-14T17:00:11+00:00","dateModified":"2024-01-28T10:14:58+00:00","description":"A privacy flaw in TLS encryption standards can out private users by exploiting related keys and associating them with identities, even with a new IP address.","breadcrumb":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#primaryimage","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/10\/supercookeys-article.png","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.privateinternetaccess.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SuperCooKey &#8211; A SuperCookie Built Into TLS 1.2 and 1.3"}]},{"@type":"WebSite","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website","url":"https:\/\/www.privateinternetaccess.com\/blog\/","name":"PIA","description":"Online privacy news from around the world.","publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization","name":"Private Internet Access","url":"https:\/\/www.privateinternetaccess.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","width":1200,"height":1200,"caption":"Private Internet Access"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/privateinternetaccess\/","https:\/\/x.com\/buyvpnservice","https:\/\/www.instagram.com\/piavpn\/","https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w"]},{"@type":"Person","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1","name":"Derek Zimmer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g","caption":"Derek Zimmer"},"description":"Derek is a cryptographer, security expert and privacy activist. He has twelve years of security experience and six years of experience designing and implementing privacy systems. He founded the Open Source Technology Improvement Fund (OSTIF) which focuses on creating and improving open-source security solutions through auditing, bug bounties, and resource gathering and management.","sameAs":["https:\/\/ostif.org\/","https:\/\/www.linkedin.com\/in\/derek-zimmer-2164a441\/","https:\/\/x.com\/http:\/\/www.twitter.com\/ostifofficial"],"url":"https:\/\/www.privateinternetaccess.com\/blog\/author\/derek-zimmer\/"}]}},"_links":{"self":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/8760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/comments?post=8760"}],"version-history":[{"count":13,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/8760\/revisions"}],"predecessor-version":[{"id":17325,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/8760\/revisions\/17325"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media\/8944"}],"wp:attachment":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media?parent=8760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/categories?post=8760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/tags?post=8760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}