DEF CON 33 - Escaping the Privacy Sandbox with Client Side Deanonymization Attacks - Eugene Lim

DEF CON 33 - Escaping the Privacy Sandbox with Client Side Deanonymization Attacks - Eugene Lim

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 25:58

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Google's Privacy Sandbox contains critical vulnerabilities that undermine its privacy claims, allowing advertisers to deanonymize users and track browsing history despite being designed as a privacy-preserving alternative to third-party cookies.

Key Takeaways:

• The Privacy Sandbox consists of experimental JavaScript APIs added to Chrome that advertisers must apply to access, creating a "walled garden" controlled by Google
• The Attribution Reporting API tracks ad conversions by registering a "source" when a user views an ad, then matching it with a "conversion" when the user visits the advertiser's site
• Debug reports bypass privacy protections like referral headers, leaking information about where conversions were recorded
• A "destination hijacking" vulnerability was found where Google ads inject potentially ownable domains, allowing creation of a boolean oracle to deanonymize users and track browsing history

Privacy-preserving advertising technology remains fundamentally challenging, with the Privacy Sandbox demonstrating how attempts to satisfy both advertisers and privacy needs create new vulnerabilities.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay, so it's 10:00 and I think we're just going to kick it off. So, thank you again everyone. I know it's Sunday morning on DevCon. Um, last day. So, I really appreciate you guys being here and uh I'm hoping this is a useful one for you guys as well. Um, quick um quick introduction. I'm Eugene. Um, I go by Space Raccoon online and this talk is um escaping the privacy sandbox deep dive edition. So uh on Thursday I kind of talked through some of these um findings in the main stage but I thought this was a good opportunity to kind of break it down a bit more deep dive into some of the techniques and the um ideas I had while researching this topic and give you a bit of insight into the privacy sandbox which is Google's um own ad technology that they're trying to use to replace third party coo…