Guess What: Ad Blockers Don't Block Ads That Well

Ad blockers and tracking-cookie blockers don't work as well as you might think, researchers at Belgium's Catholic University of Leuven have determined.

Credit: Pinone Pantone/Shutterstock

(Image credit: Pinone Pantone/Shutterstock)

"Virtually every browser or extension-enforced policy can be bypassed," reads the academic paper written by computer-science grad students Gertjan Franken and Tom Van Goethem along with their supervising professor Wouter Joosen. "We find that even built-in protection mechanisms can be circumvented by multiple novel techniques we discover."

MORE: Best Ad Blockers

The researchers tried to find various ways around each browser, tracker-blocking extension and ad-blocker extension, sometimes using new methods that haven't been implemented widely online. Not a single product stood up to every attack.

"We found that for every analyzed browser extension there exists at least one technique that can be used to circumvent the extension to send an authenticated third-party request," the paper says.

Browsers generally let tracking cookies operate if they come from the site being visited, although Apple Safari blocked a couple of kinds of these, but try to block cookies coming from third-party websites. In other words, if you visit the New York Times website, that site's cookies will be enabled, but cookies that come from WeLuvScamz.com but appear on the Times website shouldn't be.

The browsers' own protections were a mixed bag. Not so good were the PDF-display features in Google Chrome and Opera, which ignored JavaScript-based tracking cookies in PDFs, and Apple Safari and Microsoft Edge, which couldn't block many third-party cookies. (Safari 11 was better than Safari 10 in this respect, however.)

"For the Chromium-based browsers (Google Chrome and Opera), we found that because of the built-in PDF reader, an adversary or tracker can still initiate authenticated requests to third-parties," the paper said.

"Surprisingly, we found that the blocking of third-party cookies feature in Edge had no effect," it also said. "We believe that this is due to an oversight from the browser developers or a regression bug introduced when new functionality was added."

Edge did manage to block third-party cookies in PDFs, even though it displays them in the browser like the Chromium-based browsers do.

Firefox did well, but it failed to block cookies based on browser redirects (i.e., via links embedded in other pages), and its optional tracking protection largely failed. The best performer overall was the Firefox-based Tor browser.

The ad-blocking and tracking-blocking browser extensions didn't do so well either. The only ad blocker that came close to doing a thorough job on all browsers was Adblock Plus, although the performance of each extension differed from brower to browser. The Blur tracking blocker failed in all categories, while the Ghostery extension on Firefox did the best among tracking blockers.

The paper was presented yesterday (Aug. 15) at the USENIX Security Symposium in Baltimore, and there's a companion website called "Who Left Open the Cookie Jar?" that sums it all up.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Internet
Russian flag with padlock smashing through glass
47 VPNs could be axed from Google Play Store following Russian demands
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Obscura VPN website landing page
Obscura VPN wants to be the "best darn VPN out there" – can it?
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Large group of protesters in Turkey following Instanbul mayor's arrest
Turkey sees huge VPN usage spike amid reports of social media crackdown
Latest in News
half-life alyx
Latest Half-Life 3 rumors point to a 2025 release — and maybe pigs will fly
NFL Sunday Ticket logo for YouTube
NFL Sunday Ticket 2025 pricing revealed — and it's bad news
Ben Mendelsohn in Andor season 2
'Welcome to the Rebellion' — new ‘Andor’ season 2 trailer teases a darker edge
Russian flag with padlock smashing through glass
47 VPNs could be axed from Google Play Store following Russian demands
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window