(Bloomberg) — Google engineers said a tool Apple Inc. developed to help users avoid web tracking is fundamentally flawed and creates more problems than it solves.
The Intelligent Tracking Prevention feature on Apple’s Safari web browser, which is meant to block tracking software used by digital advertisers, can be abused to do the exact opposite, according to a paper released Wednesday by Google researchers. Google told Apple about the problem in August, and in December the iPhone maker published a blog post saying it had fixed the issues and thanking Google for its help.
But Wednesday’s paper concluded that the problems go beyond the issues that Apple addressed. Instead of making a big list of cookies to block, Apple’s ITP continuously learns what websites users visit and which kinds of cookies try to hitch a ride. Over time, this creates unique cookie-blocking algorithms for each web surfer that can be used to identify and track them, according to the paper.
“I can assure you that they still haven’t fixed these issues,” Justin Schuh, engineering director for Google’s Chrome browser, said on Twitter. Apple’s December blog post “didn’t disclose the vulnerabilities or appropriately credit the researchers,” he added. Apple said the bugs mentioned in the report were patched in December, but declined to comment further. “Our core security research team has worked closely and collaboratively with Apple on this issue,” a spokesman for Google said.
This isn’t the first time the two tech giants have clashed over privacy. Apple Chief Executive Officer Tim Cook has criticized internet companies for collecting too much personal information, and last year Google researchers reported a two-year long vulnerability in the iPhone maker’s software.
Google’s Chrome and Apple’s Safari are two of the most popular web browsers, with Chrome used by more people overall but Safari dominating on iPhones. Apple has been touting Safari privacy features to persuade more consumers to use it. Apple first introduced Intelligent Tracking Prevention in 2017. The tool targets cookies, bits of code that let marketers follow people around the web and send them targeted ads.
Google refused to block cookies for years, arguing that targeted ads help publishers and keep the internet free. But last week, the internet giant said it would eventually phase them out, setting off a race among advertisers to adapt.
Privacy advocates have lauded Apple’s approach to tracking, and criticized Google for taking so long to do the same. But the paper suggests Apple may have to go back to the drawing board to find a new way to block tracking.
“This bug is quite counter-intuitive, but rather very serious,” said Lukasz Olejnik, an independent cybersecurity researcher.
(Updates with Google statement in fourth paragraph.)
To contact the reporter on this story: Gerrit De Vynck in New York at firstname.lastname@example.org
To contact the editors responsible for this story: Alistair Barr at email@example.com, Jillian Ward
For more articles like this, please visit us at bloomberg.com
©2020 Bloomberg L.P.