Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Third party tracker obfuscation #20533

Closed
kaytwo opened this issue Jan 17, 2022 · 5 comments
Closed

Third party tracker obfuscation #20533

kaytwo opened this issue Jan 17, 2022 · 5 comments
Assignees
Labels
closed/fixed-by-component-update OS/Android Fixes related to Android browser functionality OS/Desktop

Comments

@kaytwo
Copy link

kaytwo commented Jan 17, 2022

Description

Cloudflare acquired Zaraz, which purports to increase privacy and performance for third party tracking, and have integrated it into their main whole-site CDN product. A significant side effect of their architecture is that these third party (largely tracking-related) requests appear to the browser to be first party requests to https://YOURDOMAIN/cdn-cgi/zaraz/**. In Brave Nightly on Windows, these requests are not blocked by aggressive shields in incognito mode (or any weaker setting).

Steps to Reproduce

  1. Activate Zaraz on a Cloudflare-proxied website
  2. Load the site in Brave
  3. Observe in the Network tab that tracking via Facebook Pixel, Google Analytics, etc. is successfully sent.

Actual result:

Status: 200

Expected result:

Status: Blocked

Reproduces how often:

Easily reproduced

Desktop Brave version:

Brave 1.35.77 Chromium: 97.0.4692.71 (Official Build) beta (64-bit)
Revision adefa7837d02a07a604c1e6eff0b3a09422ab88d-refs/branch-heads/4692@{#1247}
OS Windows 11 Version 21H2 (Build 22000.434)

Version/Channel Information:

  • Can you reproduce this issue with the current release?
    Did not attempt
  • Can you reproduce this issue with the beta channel?
    Yes
  • Can you reproduce this issue with the nightly channel?
    Yes
@kaytwo kaytwo added OS/Android Fixes related to Android browser functionality OS/Desktop labels Jan 17, 2022
@diracdeltas
Copy link
Member

cc @ryanbr , should be easy to add a filter for this

@ryanbr
Copy link

ryanbr commented Jan 20, 2022

Example website of this in action @kaytwo ?

@kaytwo
Copy link
Author

kaytwo commented Jan 20, 2022 via email

@ryanbr
Copy link

ryanbr commented Jan 21, 2022

kaytwo.org unable to find domain from NZ/US/UK ips. Standard Cloudflare error message @kaytwo

@kaytwo
Copy link
Author

kaytwo commented Jan 21, 2022 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
closed/fixed-by-component-update OS/Android Fixes related to Android browser functionality OS/Desktop
Projects
None yet
Development

No branches or pull requests

3 participants