Skip to main content
QUICK REVIEW

[Paper Review] Web Tracking: Mechanisms, Implications, and Defenses

Tomasz Bujlow, Valentín Carela-Español|arXiv (Cornell University)|Jul 28, 2015
Privacy, Security, and Data Protection47 references21 citations
TL;DR

This paper provides a comprehensive survey of web tracking mechanisms (e.g., cookies, fingerprinting, device identifiers), their implications for privacy (including price discrimination and surveillance), and defense strategies such as ad blockers and tracking discovery tools. It identifies a shift toward more invasive tracking techniques and highlights emerging privacy-preserving identifiers like Google AdID and Microsoft Device Identifier as potential alternatives to third-party cookies.

ABSTRACT

This articles surveys the existing literature on the methods currently used by web services to track the user online as well as their purposes, implications, and possible user's defenses. A significant majority of reviewed articles and web resources are from years 2012-2014. Privacy seems to be the Achilles' heel of today's web. Web services make continuous efforts to obtain as much information as they can about the things we search, the sites we visit, the people with who we contact, and the products we buy. Tracking is usually performed for commercial purposes. We present 5 main groups of methods used for user tracking, which are based on sessions, client storage, client cache, fingerprinting, or yet other approaches. A special focus is placed on mechanisms that use web caches, operational caches, and fingerprinting, as they are usually very rich in terms of using various creative methodologies. We also show how the users can be identified on the web and associated with their real names, e-mail addresses, phone numbers, or even street addresses. We show why tracking is being used and its possible implications for the users (price discrimination, assessing financial credibility, determining insurance coverage, government surveillance, and identity theft). For each of the tracking methods, we present possible defenses. Apart from describing the methods and tools used for keeping the personal data away from being tracked, we also present several tools that were used for research purposes - their main goal is to discover how and by which entity the users are being tracked on their desktop computers or smartphones, provide this information to the users, and visualize it in an accessible and easy to follow way. Finally, we present the currently proposed future approaches to track the user and show that they can potentially pose significant threats to the users' privacy.

Motivation & Objective

  • To systematically survey and categorize existing web tracking mechanisms used by online services.
  • To analyze the privacy implications of tracking, including price discrimination, identity theft, and government surveillance.
  • To evaluate existing and proposed defenses against tracking, including technical tools and user-awareness mechanisms.
  • To examine emerging tracking technologies such as network-inserted and cloud-synchronized identifiers.
  • To promote transparency and inform policy development by documenting tracking practices and their impacts on users.

Proposed method

  • Categorized tracking mechanisms into five main groups: session-based, client storage, client cache, fingerprinting, and other approaches.
  • Analyzed tracking techniques based on device, browser, OS, and network characteristics for fingerprinting and device identification.
  • Evaluated defense mechanisms tailored to specific tracking methods, including ad blockers and privacy-preserving identifiers.
  • Reviewed tools for tracking discovery and visualization, such as those used to detect third-party tracking on desktop and mobile devices.
  • Examined proposed future tracking systems, including device-inferred, client-generated, network-inserted, server-issued, and cloud-synchronized identifiers.
  • Synthesized findings from peer-reviewed literature and web resources (2012–2014) to provide a holistic view of tracking ecosystems.

Experimental results

Research questions

  • RQ1What are the primary technical mechanisms used for tracking users on the web, and how do they differ in invasiveness and persistence?
  • RQ2How do tracking techniques enable user identification using device, browser, and network attributes?
  • RQ3What are the real-world implications of web tracking, including financial, social, and governmental consequences?
  • RQ4How effective are current defense mechanisms in mitigating various tracking methods?
  • RQ5What future tracking technologies are being proposed, and what privacy risks do they pose?

Key findings

  • Fingerprinting techniques, which use device and browser attributes, can uniquely identify users with high accuracy, even without cookies.
  • Third-party cookies are being phased out, but fingerprinting and device identifiers are emerging as dominant tracking methods.
  • Google AdID and Microsoft Device Identifier are proposed as privacy-preserving alternatives to third-party cookies, with user control and annual reset capabilities.
  • Network-inserted identifiers, such as those from ISPs or CDNs, can track users across devices and networks if coordinated.
  • Tracking discovery tools can visualize and inform users about which entities are collecting their data, increasing transparency.
  • The shift toward more invasive tracking methods threatens user privacy and may lead to widespread adoption of ad blockers unless regulated.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.