How do CNAME Cloacking track you

Can CNAME Cloaking used to serve ads and tracks you?

Yes.

Example

they hide google-analytics domain via their own CNAME

Image

Ads block tracker

Who is currently doing this?

Below are the 6 tracking companies that are currently using CNAME cloaking:

Image for post
From top left to bottom right: EulerianAT Internet (formerly XiTi), KeyadeAdobe Marketing Cloud (formerly Omniture), CriteoCommanders Act

Solution?

  1. Use Firefox , Firefox for desktop does allow extensions to make DNS queries themselves, and extensions like uBlock Origin already apply their blocking rules to intermediary CNAMEs as well.
  2. Dont use Chromemium based brwoser, such as Opera, Brave, Mirosoft Edge.

References