Focus Areas:
Security Operations & Defense
,
Penetration Testing
This Tool Demo covers following tools where the speaker has contributed or authored
LOCAL SHERIFF
LOCAL SHERIFF
Abstract
URL is the most commonly tracked piece of information, the innocent choice to structure a URL based on page content can make it easier to learn a users’ browsing history, address, health information or more sensitive details. While you as a user normally browse the internet Local Sheriff works in the background and helps you identify what sensitive information(PII—Name, Date Of Birth, Email, Passwords, Passport number, Auth tokens.) is being shared/leaked to which all third-parties and by which all websites. The issues that Local Sheriff helps identify:
- What sensitive information is being shared with whom?
- Which companies are own these third parties?
- What can they doing with this information? EG: de-anonymize users on the internet, create shadow profiles.
- Data points that can be used for tracking a user across the web.
- Insights into which companies know what about you on the internet.
Local Sheriff can also be used by organizations to audit:
- Which all the third-parties that are being used on their websites.
- The third-parties on the websites are implemented in a way that respect user’s privacy and sensitive data is not being leaked to them.
Local Sheriff is a browser extension that can used with Chrome, Opera, Firefox, Brave, Cliqz.