6.3.4 Ensure Prevent Cross-site Tracking in Safari Is Enabled

Information

There is a vast network of groups that collect, use and sell user data. One method used to collect user data is pay and provide contented and services for website owners, along with that 'assistance' the site owners push tracking cookies on visitors. In many cases the help allows a content owner to keep the site up. The tracking cookies allow information brokers to track web users across visited sites. For better privacy and to provide some resistance to data brokers prevent cross-tracking.

Rationale:

Cross-tracking allows data-brokers to follow you across the Internet to enable their business model of selling personal data. Users should protect their data and not volunteer it to marketing companies.

Impact:

Marketing companies will be unable to target you as effectively.

Solution

Profile Method:
Create or edit a configuration profile with the following information:

The PayloadType string is com.apple.Safari

The key to include is BlockStoragePolicy

The key must be set to: 2

The key to also include is WebKitPreferences.storageBlockingPolicy

The key must be set to: 1

The key to also include is WebKitStorageBlockingPolicy

The key must be set to: 1

See Also

https://workbench.cisecurity.org/benchmarks/14561

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|SC-18, CSCv7|7.1

Plugin: Unix

Control ID: 12bfecbb783f904823516f1d3358a68e21675379896f36f0e33f1337d64683d2