
The CNAME of the Game: Large-scale Analysis of DNS-based Tracking Evasion 18
[16] Disconnect. 2020. Privacy Solutions. https://disconnect.
me/.
[17] duckduckgo. 2020. tracker-radar-collector. https://github.
com/duckduckgo/tracker-radar-collector [Online; accessed
10. Jun. 2020].
[18] EasyPrivacy. 2020. Filter List That Completely Removes All
Forms Of Tracking From The Internet. https://easylist.to/
index.html.
[19] Peter Eckersley. 2010. How unique is your web browser?. In
International Symposium on Privacy Enhancing Technologies
Symposium. Springer, 1–18.
[20] Steven Englehardt and Arvind Narayanan. 2016. Online
tracking: A 1-million-site measurement and analysis. In Pro-
ceedings of the 2016 ACM SIGSAC conference on computer
and communications security. 1388–1401.
[21] Steven Englehardt, Dillon Reisman, Christian Eubank, Pe-
ter Zimmerman, Jonathan Mayer, Arvind Narayanan, and
Edward W Felten. 2015. Cookies that give you away: The
surveillance implications of web tracking. In Proceedings
of the 24th International Conference on World Wide Web.
289–299.
[22] Brent Fulgham. 2018. Protecting Against HSTS Abuse.
https://webkit.org/blog/8146/protecting-against-hsts-
abuse.
[23] Raymond Hill. 2020. uBlock Origin - 1.25.0. https://github.
com/gorhill/uBlock/releases/tag/1.25.0.
[24] Umar Iqbal, Steven Englehardt, and Zubair Shafiq.
2020. Fingerprinting the Fingerprinters: Learning to De-
tect Browser Fingerprinting Behaviors. arXiv preprint
arXiv:2008.04480 (2020).
[25] Samy Kamkar. 2010. Evercookie-virtually irrevocable persis-
tent cookies. His Blog 9 (2010).
[26] Arjaldo Karaj, Sam Macbeth, Rémi Berson, and Josep M
Pujol. 2018. WhoTracks. Me: Shedding light on the opaque
world of online tracking. arXiv preprint arXiv:1804.08959
(2018).
[27] Mitja Kolšek. 2002. Session fixation vulnerability in web-
based applications. Acros Security 7 (2002).
[28] Balachander Krishnamurthy and Craig Wills. 2009. Privacy
diffusion on the web: a longitudinal perspective. In Proceed-
ings of the 18th international conference on World wide
web. ACM, 541–550.
[29] Adam Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno,
and Franziska Roesner. 2016. Internet jones and the raiders
of the lost trackers: An archaeological study of web tracking
from 1996 to 2016. In 25th {USENIX}Security Symposium
({USENIX}Security 16).
[30] Scott Low and Joe Martin. 2020. Tracking Prevention in
Microsoft Edge (Chromium). https://docs.microsoft.com/
en-us/microsoft- edge/web-platform/tracking-prevention.
[31] Andrea Marchesini. 2019. Enable sameSite=lax by default
on Nightly. https://bugzilla.mozilla.org/show_bug.cgi?id=
1604212.
[32] Vasilios Mavroudis, Shuang Hao, Yanick Fratantonio, Fed-
erico Maggi, Christopher Kruegel, and Giovanni Vigna.
2017. On the privacy and security of the ultrasound ecosys-
tem. Proceedings on Privacy Enhancing Technologies 2017,
2 (2017), 95–112.
[33] Jonathan R Mayer and John C Mitchell. 2012. Third-party
web tracking: Policy and technology. In 2012 IEEE Sympo-
sium on Security and Privacy. IEEE, 413–427.
[34] McAfee. 2020. Customer URL Ticketing System. https:
//trustedsource.org/.
[35] Keaton Mowery and Hovav Shacham. 2012. Pixel perfect:
Fingerprinting canvas in HTML5. Proceedings of W2SP
(2012), 1–12.
[36] NextDNS. 2020. CNAME Cloaking Blocklist. https://
github.com/nextdns/cname-cloaking- blocklist.
[37] NextDNS. 2020. NextDNS CNAME Cloaking Blocklist.
https://github.com/nextdns/cname-cloaking- blocklist.
[38] Nick Nikiforakis, Alexandros Kapravelos, Wouter Joosen,
Christopher Kruegel, Frank Piessens, and Giovanni Vigna.
2013. Cookieless monster: Exploring the ecosystem of web-
based device fingerprinting. In 2013 IEEE Symposium on
Security and Privacy. IEEE, 541–555.
[39] Lukasz Olejnik and Claude Castelluccia. 2014. Analysis of
openx-publishers cooperation. In In 7th Workshop on Hot
Topics in Privacy Enhancing Technologies (HotPETs 2014).
[40] Lukasz Olejnik, Tran Minh-Dung, and Claude Castelluccia.
2014. Selling off privacy at auction. In In Proceedings of
the 2014 Symposium on Network and Distributed System
Security.
[41] Mike O’Neill. 2015. Discovered In The Wild: A New Method
Bypassing Safari’s Third-Party Cookie Blocking. https:
//baycloud.com/blog/PostDetail?slug=discovered-in-the-
wild-a-new-method-bypassing-safaris-third-party-cookie-
blocking.
[42] Olivier Poitrey. 2019. NextDNS first to support blocking
of ALL third-party trackers disguised as first-party. https:
//medium.com/nextdns/nextdns-added- cname-uncloaking-
support-becomes- the-first-cross-platform-solution-to-the-
problem-e3f437f84342.
[43] Chrome DevTools Protocol. 2020. Instrument, Inspect,
Debug And Profile Chromium. https://chromedevtools.
github.io/devtools-protocol/.
[44] Rapid7. 2020. DNS ’ANY’, ’A’, ’AAAA’, ’TXT’, ’MX’,
and ’CNAME’ responses for known forward DNS names.
https://opendata.rapid7.com/sonar.fdns_v2/.
[45] Rapid7. 2020. DNS IPv4 PTR responses. https://opendata.
rapid7.com/sonar.rdns_v2/.
[46] Michael Schrank, Bastian Braun, Martin Johns, and
Joachim Posegga. 2010. Session fixation–the forgotten
vulnerability? Sicherheit 2010. Sicherheit, Schutz und Zuver-
lässigkeit (2010).
[47] SourcePoint. 2020. Consent Management Platform. https:
//help.sourcepoint.com/en/collections/1255107-consent-
management-platform.
[48] Alan Toner. 2017. Safari in Arms Race Against Trackers -
Criteo Feels the Heat. https://www.eff.org/deeplinks/2017/
12/arms-race-against-trackers-safari-leads-criteo-30.
[49] Security Trails. 2020. Robust APIs & Data Services for
Security Teams. https://securitytrails.com/.
[50] Adam Warner. 2020. Pi-hole v5.0 is here! https://pi-hole.
net/2020/05/10/pi-hole- v5-0- is-here/.
[51] Mike West. 2020. Incrementally Better Cookies. https:
//tools.ietf.org/html/draft-west-cookie-incrementalism- 01.
[52] WhoTracks.me. 2018. GDPR - What happened? https:
//whotracks.me/blog/gdpr-what-happened.html.
[53] Whoxy. 2020. WHOIS Lookup API for Domain Names.
https://www.whoxy.com/.