Ontvanger toegeschreven op een spoofbare header
Een bevinding wijst de veroorzakende pagina aan op basis van een header die iedereen kan zetten.
- Familie
- Methode
- Status
- actief
- Geldt voor
- web, mobile-app
Wat er gebeurt
A capture is turned into a claim about which page sent data to which recipient. The link between page and request is taken from the referring header in the request, or from the order in which requests appear. Both are unreliable: the header can be set by whatever issued the request, measurement instrumentation routinely rewrites it, and ordering breaks as soon as a capture spans more than one page.
Waarom het ertoe doet
The party named as a recipient may never have received anything from that page, and the party that did receive something disappears from the finding. A published measurement that cannot survive this objection damages the case it was meant to support and, worse, the next one by the same researcher.
Veelvoorkomende oorzaken
- traffic attributed by referring header because it is the field that is always present
- one capture spanning several pages, with requests from a later page counted against an earlier one
- navigation to another site during the capture, whose traffic is then counted against the target
- a redirect chain collapsed to its final host, so the intermediate recipients vanish
Dit is het níet
A recipient that is genuinely present but not named in the privacy statement is Undisclosed recipient, a fault in the system. This entry is about the finding: the recipient may not belong to the page at all.
Hoe je het vaststelt
Indicator
Re-attributing the same capture through the page reference recorded in it, or through the initiator chain, produces a different set of recipients per page than attribution by referring header. The difference between the two sets is the fault.
Methode
differential
Kwaliteit van de detectie
95 van 100
De grenzen van deze bevinding
Wat dit patroon zou weerleggen
- Attribution was already done through the page reference or the initiator chain.machinaal te toetsende bevinding vervalt
- The capture contains exactly one page load and no navigation, so there is nothing to confuse.machinaal te toetsende bevinding vervalt
- Both routes yield the same recipient set for the page in question.machinaal te toetsende bevinding vervaltThe finding then stands on the stronger route, and saying so is worth a sentence in the publication.
- The raw capture no longer exists and the attribution cannot be redone.niet uit de meting af te leidende bevinding wordt zwakkerThe finding cannot be repaired, only repeated. Report it as unverifiable rather than as sound.
Wat dit patroon níet vaststelt
- harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
- severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
- unlawfulness; that is for a supervisory authority or a court
- intent; a fault is usually a build decision, not a plan
- absence: not finding it in one capture is not evidence that it is not there
Reproduceren
- manual
METHOD.mdno dedicated reproduction exists yet; follow the general method and the indicator above
Juridisch kader
Veelgehoorde tegenwerpingen
The header is what the browser sends, so it is authoritative.
It is what the issuing party chose to send. Instrumentation rewrites it as a matter of routine, and a field that anything may set cannot establish who caused a request.
The finding was correct anyway.
Then it survives re-attribution, which costs one pass over the capture you already have. Doing it is cheaper than defending it later.
Nobody checks this.
The party you named will, and it is the first thing their technical people will look at.
Geldt wanneer
to-a-finding