<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>255450</bug_id>
          
          <creation_ts>2023-04-14 05:29:08 -0700</creation_ts>
          <short_desc>ITP Bounce tracking defense not efficient enough</short_desc>
          <delta_ts>2023-04-14 16:52:51 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>Safari 16</version>
          <rep_platform>Mac (Apple Silicon)</rep_platform>
          <op_sys>macOS 13</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="webkit.gently881@simplelogin.fr">webkit.gently881</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>sihui_liu</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>wilander</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1948763</commentid>
    <comment_count>0</comment_count>
    <who name="webkit.gently881@simplelogin.fr">webkit.gently881</who>
    <bug_when>2023-04-14 05:29:08 -0700</bug_when>
    <thetext>Hello,

I contact you because I noticed adtech companies selling their Safari deterministic cross-domain tracking capabilities. From Taboola some time ago (cf. this thread https://twitter.com/WolfieChristl/status/1356547088692240386) to First.id (cf. this thread https://twitter.com/pixeldetracking/status/1645123172671389696). When I noticed Taboola tracking and read John Wilander answer https://twitter.com/johnwilander/status/1356638414880215040, I assumed I was protected (and I remembered Criteo tried this a long time ago, without success).

But then, I noticed that Safari didn&apos;t flag first-id bounce tracking if the user only consulted one, two or three different websites using first-id.fr tracking. It wasn&apos;t until the fourth website that first-id.fr was flagged by ITP (cf. this thread https://twitter.com/pixeldetracking/status/1646816439486099463). And in some circumstances, Safari might even not flag the website after 4+ domains (first-id made this video to &quot;prove&quot; their tracking was efficient: https://www.youtube.com/watch?v=cDKc7xALi1w).

Here are a few of the websites with first-id tracking. If you click on one of the website links (for the bounce tracker to be triggered, you have to consult 2 pages), and accepting cookies if you see the consent pop-up (but this pop-up might be dependant on you being in European Union):
- allocine.fr
- marmiton.org
- liberation.fr
- aufeminin.com
- doctissimo.fr
- marieclaire.fr
- capital.fr
- jeuxvideo.com

Their website: https://www.first-id.fr/
As they are not the only one, Taboola is using the same mechanism, I am afraid a few other adtech companies might also rely on this &quot;ITP limitation&quot;.

ITP bounce tracking defense is working well if the user consult enough websites with first-id.fr tracker included, but I would have assumed ITP was protecting me from their tracking even if I only consulted 2 different domains, hence this bug filling.

Thanks in advance</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1948909</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2023-04-14 16:46:36 -0700</bug_when>
    <thetext>&lt;rdar://problem/108071412&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1948912</commentid>
    <comment_count>2</comment_count>
    <who name="John Wilander">wilander</who>
    <bug_when>2023-04-14 16:52:51 -0700</bug_when>
    <thetext>Thanks for filing! Yes, there is a fan-out threshold for classification of a domain. We&apos;ll take your feedback into consideration.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>