A security consultant from the United Kingdom has demonstrated how a feature of the secure HTTPS Web protocol can be turned into a tracking feature in some browsers.
HTTP Strict Transport Security (HSTS), described in RFC 6797, is a mechanism that helps websites redirect users from the insecure version of HTTP to the encrypted version of HTTPS. If a user types https://www.google.com into their browser, HSTS will automatically send them to https://www.google.com.
The problem is, someone thought it might be annoying if the User Agent – that is, your browser – had to go through a redirect every time a user types in http instead of https. So the authors of HSTS created a mechanism for browsers to remember the HSTS policy of the websites you've visited.
This is what Sam Greenhalgh calls a super-cookie. His idea is that an HSTS “pin” is set for every HTTPS redirect to the site you use, is unique to the user and the site, and is readable by your browser settings from any location.
“Once the number is stored, it could be read by other websites in the future. Reading the number only requires testing whether requests for the same web addresses redirect or not,” Greenhalgh says.
Greenhalgh notes that some browsers allow HSTS flags to be cleared, so in Chrome, Firefox, and Opera the issue is somewhat mitigated (IE does not support HSTS).
For Apple's Safari, there doesn't seem to be any way for the user to delete HSTS flags. HSTS flags continue to be synced to iCloud and will be restored immediately on a device that has been updated to new firmware. "In this case, the device can effectively be 'branded', with indelible tracking value that you have no way to delete."
