CARVIEW |
Peter Snyder Principal Privacy Researcher at Brave Software
I am the principal privacy researcher at Brave Software, where I work on new ways to improve privacy and security on the Web, and to fix new threats to Brave browser users. I work under Hamed Haddadi and Brendan Eich, and alongside a great team of researchers, engineers, and privacy experts.
I also co-chair PrivacyWG (previously, PING), the group in the W3C that reviews proposed new Web standards for privacy risks and concerns.
I also advise and support privacy groups and projects. Currently I am an advisor for the TIMBY project, a start up building private and secure reporting software for workers, journalists, and activists.
Before joining Brave, I worked on my PhD in the Computer Science department at the University of Illinois at Chicago in the BITS Lab, working under the kind and knowledgeable guidance of Chris Kanich.
Publications
-
Local Frames: Exploiting Inherited Origins to Bypass Content Blockers
- Alisha Ukani
- Hamed Haddadi
- Alex C. Snoeren
- Peter Snyder
-
Nebula: Efficient, Private and Accurate Histogram Estimation
- Ali Shahin Shamsabadi
- Peter Snyder
- Ralph Giles
- Aurélien Bellet
- Hamed Haddadi
-
Measuring the Accuracy and Effectiveness of PII Removal Services
- Jiahui HE
- Peter Snyder
- Hamed Haddadi
- Fabian E. Bustamante
- Gareth Tyson
-
Web Execution Bundles: Reproducible, Accurate, and Archivable Web Measurements
- Florian Hantke
- Peter Snyder
- Hamed Haddadi
- Ben Stock
-
A First Look at Related Website Sets
- Stephen McQuistin
- Peter Snyder
- Hamed Haddadi
- Gareth Tyson
-
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
- Mir Masood Ali
- Peter Snyder
- Chris Kanich
- Hamed Haddadi
-
Understanding the Privacy Risks of Popular Search Engine Advertising Systems
- Salim Chouaki
- Oana Goga
- Hamed Haddadi
- Peter Snyder
-
A First Look at the Privacy Harms of the Public Suffix List
- Stephen McQuistin
- Peter Snyder
- Colin Perkins
- Hamed Haddadi
- Gareth Tyson
-
Pool-Party: Exploiting Browser Resource Pools for Web Tracking
- Peter Snyder
- Soroush Karami
- Arthur Edelstein
- Ben Livshits
- Hamed Haddadi
-
Measuring UID Smuggling in the Wild
- Audrey Randall
- Peter Snyder
- Alisha Ukani
- Alex C. Snoeren
- Geoffrey M. Voelker
- Stefan Savage
- Aaron Schulman
-
STAR: Secret Sharing for Private Threshold Aggregation Reporting
- Alex Davidson
- Peter Snyder
- E. B. Quirk
- Joseph Genereux
- Ben Livshits
- Hamed Haddadi
-
Blocked or Broken? Automatically Detecting When Privacy Interventions Break Websites
- Michael Smith
- Peter Snyder
- Moritz Haller
- Ben Livshits
- Hamed Haddadi
- Deian Stefan
-
Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful Tracking
- Jordan Jueckstock
- Peter Snyder
- Shaown Sarker
- Alexandros Kapravelos
- Ben Livshits
-
SugarCoat: Programmatically Generating Privacy-Preserving, Web-Compatible Resource Replacements for Content Blocking
- Michael Smith
- Peter Snyder
- Ben Livshits
- Deian Stefan
-
Towards Realistic and Reproducible Web Crawl Measurements
- Jordan Jueckstock
- Shaown Sarker
- Peter Snyder
- Aidan Beggs
- Panagiotis Papadopoulos
- Matteo Varvello
- Ben Livshits
- Alexandros Kapravelos
-
Detecting Filter List Evasion With Event-Loop-Turn Granularity JavaScript Signatures
- Quan Chen
- Peter Snyder
- Ben Livshits
- Alexandros Kapravelos
-
Who Filters the Filters: Understanding the Growth, Usefulness and Efficiency of Crowdsourced Ad Blocking
- Peter Snyder
- Antoine Vastel
- Ben Livshits
-
Filter List Generation for Underserved Regions
- Alexander Sjosten
- Peter Snyder
- Antonio Pastor
- Panagiotis Papadopoulos
- Ben Livshits
-
Keeping Out the Masses: Understanding the Popularity and Implications of Internet Paywalls
- Panagiotis Papadopoulos
- Peter Snyder
- Dimitrios Athanasakis
- Ben Livshits
-
AdGraph: A Machine Learning Approach to Automatic and Effective Adblocking
- Umar Iqbal
- Peter Snyder
- Shitong Zhu
- Ben Livshits
- Zhiyun Qian
- Zubair Shafiq
-
SpeedReader: Reader Mode Made Fast and Private
- Mohammad Ghasemisharif
- Peter Snyder
- Andrius Aucinas
- Ben Livshits
-
Most Websites Don’t Need to Vibrate: A Cost–Benefit Approach to Improving Browser Security
- Peter Snyder
- Cynthia Taylor
- Chris Kanich
-
Fifteen Minutes of Unwanted Fame: Detecting and Characterizing Doxing
- Peter Snyder
- Periwinkle Doerfler
- Chris Kanich
- Damon McCoy
-
CDF: Predictably Secure Web Documents
- Peter Snyder
- Laura Watiker
- Cynthia Taylor
- Chris Kanich
-
Browser Feature Usage on the Modern Web
- Peter Snyder
- Lara Ansari
- Cynthia Taylor
- Chris Kanich
-
Characterizing Fraud and Its Ramifications in Affiliate Marketing Networks
- Peter Snyder
- Chris Kanich
-
The Effect of Repeated Login Prompts on Phishing Susceptibility
- Peter Snyder
- Michael K. Reiter
- Chris Kanich
-
No Please, After You: Detecting Fraud in Affiliate Marketing Networks
- Peter Snyder
- Chris Kanich
-
"I Saw Images I Didn't Even Know I Had": Understanding User Perceptions of Cloud Storage Privacy
- Jason Clark
- Peter Snyder
- Damon McCoy
- Chris Kanich
-
Cloudsweeper and Data-Centric Security
- Peter Snyder
- Chris Kanich
-
Cloudsweeper: Enabling Data-Centric Document Management for Secure Cloud Archives
- Peter Snyder
- Chris Kanich
Popular Press
- Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks news The Register
- Google's Hotseat Hypocrisy news Open Web Advocacy
- Browser Extensions are DANGEROUS video Naomi Brockwell: NBTV
- Microsoft's playdate in Google's Privacy Sandbox gets messy news The Register
- Harmonizing User Privacy with Web Functionality and Ad-Blocking Technology podcast The Brave Technologist Podcast
- Google Chrome coders really, truly, absolutely ready to cull third-party cookies from 2024 news The Register
- The Dangers of Browser Extensions video Naomi Brockwell: NBTV
- Google postpones Chrome's third-party cookie bonfire yet again news The Register
- How To STOP Tracking Links! video Naomi Brockwell: NBTV
- Privacy-centric search engines DuckDuckGo and Brave are spiking, per new study news The Drum
- Brave, DuckDuckGo to unplug Google's AMP where possible news The Register
- DuckDuckGo's private Mac browser can't replace Chrome or Safari, yet news Fast Company
- Google resumes shoveling stuff into its 'Privacy Sandbox' news The Register
- Brave Takes the Spring Out of Creepy Bounce Tracking news The Register
- Google Will Stop Tracking You Across Android, But Not Any Time Soon news TechRadar
- A Major Chip Deal Collapses podcast BBC Tech Tent
- Should You Share Your Data With Tech Companies? news Consumer Reports
- Google Just Gave You the Best Reason Yet to Finally Quit Using Chrome news Inc.
- Google Slammed Over Ad-cookie Replacement Flip-Flop news BBC
- Google Introduces a New System for Tracking Chrome Browser Users news The New York Times
- Google Reveals Latest Attempt at Cookies Replacement news AdAge
- Global Privacy Control Popularity Grows as Legal Status Up in Air news Bloomberg Law
- Tool protects users' private data while they browse news National Science Foundation
- Internet Advertising Is About to Change. Here's What Consumers Need to Know. news Consumer Reports
- Google’s vague privacy cure-all is showing up in new proposals, but some say it could break the internet news DigiDay
- The incredibly sneaky way websites sidestep privacy tools to spy on you news Fast Company
- Concern trolls and power grabs: Inside Big Tech’s angry, geeky, often petty war for your privacy news Protocol
- Ad Blockers with Pete Snyder podcast Technical Marketing Handbook
- Google pledges not to build backdoors in FLoC but not everyone's convinced news AndroidCentral
- We Checked 250 iPhone Apps—This Is How They’re Tracking You news The WireCutter (NYT)
- Google and the Age of Privacy Theater news Wired
- What's Up with the Apple App Store's Privacy Changes? news TheMarkup
- How Apple, Google, and other browser makers are quietly duking it out over the future of the web news Business Insider
- Google Chrome's crackdown on ad blockers and browser extensions, Manifest v3, is now available in beta news The Register
- The digital switch that blocks all websites from selling your personal data news DigitalTrends
- I Scanned the Websites I Visit with Blacklight, and It’s Horrifying. Now What? news TheMarkup
- Google Is Working On A New Web Standard Called WebBundles Which Is Dangerous To The Privacy Of Internet Users, Security Researchers Warned news Digital Information World
- Brave Takes Brave Stand Against Google's Plan to Turn Websites into Ad-Blocker-Thwarting Web Bundles news The Register
- Google’s New Web Standard Could Disable Your Ad-Blocker news TechRadar
- The Battle for Your Privacy on the Web With Pete Snyder podcast Software Sessions
- Google's Plan for Chrome Capability has a Big Security Risk news C|Net
- Aggrieved Ad Tech Types Decry Google Dominance in W3C Standards – Who Writes the Rules and for Whom? news The Register
- FYI: Your Browser can pick up Ultrasonic Signals You Can't Hear, and That Sounds Like a Privacy Nightmare to Some news The Register
- What the FLoC? Browser makers queue up to decry Google's latest ad-targeting initiative as invasive tracking news The Register
- Google Chrome 80 Released With Controversial Deep Linking Upgrade news Forbes
- Chrome Deploys Deep-Linking Tech in Latest Browser Build Despite Privacy Concerns news The Register
- Google's Second Stab at Preserving Both Privacy and Ad Revenue Draws Fire news The Register
- If You Want an Example of How User Concerns do not Drive Software Development, Check Out This Google-backed API news The Register
- Protecting Your Online Privacy radio Science Friday
- Why People Ruin Others’ Lives by Exposing All Their Data Online news NewScientist
- First Large-Scale Doxing Study Reveals Motivations and Targets for Cyber Bullying news ScienceDaily
- Gotta Have Standards? Security Boffins not API about Bloated Browsers news The Register
- Privacy on the Modern Web podcast The Provocateur
Other Technical Work
-
Global Privacy Control (GPC)
- Robin Berjon
- Sebastian Zimmeck
- Ashkan Soltani
- David Harbage
- Peter Snyder
- Privacy Principals W3C Guidance document for specification authors, on how to protect and improve privacy in Web standards.
-
The Off-The-Record Response Header Field
- Mark Pilgrim
- Sofía Celi
- Peter Snyder
- Shivan Kaul Sahib
-
STAR: Distributed Secret Sharing for Private Threshold Aggregation Reporting
- Alex Davidson
- Shivan Kaul Sahib
- Peter Snyder
-
W3C Security and Privacy Questionnaire
- Theresa O’Connor
- Peter Snyder
-
Reader Mode-Optimized Attention Application
- Ben Livshits
- Peter Snyder
- Andrius Aucinas
- Improving Web Privacy And Security with a Cost-Benefit Analysis of the Web API slides: pdf source: latex My thesis, presenting a thorough measurement of WebAPI use, and ways those findings can be used to better protect the privacy and security of web users. Written for the completion of my PhD.
- Yao's Garbled Circuits: Recent Directions and Implementations slides: pdf source: latex Literature review of performance and security developments in using Yao's Protocol for secure function evaluation. Written for my degree's "Written Critique and Presentation" requirement.
Blogging
- Privacy Feature Updates in Brave (Blog Series) Brave Blog Blog series of updates on new privacy features in Brave, and new privacy concerns Brave targets.
- First-Party Sets: Tearing Down Privacy Defenses Just as They're Being Built WebStandards@Brave
- Google's Topics API: Rebranding FLoC Without Addressing Key Privacy Issues WebStandards@Brave
- Privacy And Competition Concerns with Google's Privacy Sandbox WebStandards@Brave
-
Why Brave Disables FLoC
Written with:Brave Blog Description of the privacy harms and categorical errors in Google's FLoC proposal
- Brendan Eich
-
Global Privacy Control, a new Privacy Standard Proposal, now Available in Brave’s Desktop and Android Testing Versions
Written with:WebStandards@Brave Brave authors and implements a new proposal for opting users out of online tracking.
- Anton Lazarev
- WebBundles Harmful to Content Blocking, Security Tools, and the Open Web WebStandards@Brave WebBundles are extremely bad for researchers, blocking tools, and folks hoping to preserve a user-editable web.
-
Brave, Fingerprinting, and Privacy Budgets
Written with:WebStandards@Brave Discussion of why Google's Privacy Budget proposal for combating browser fingerprinting would not be effective, and what alternatives Brave is pursuing.
- Ben Livshits
- Privacy Anti-Patterns In Standards W3C Blog Description of several privacy-harming patterns observed as part of PING, the W3C's privacy review group, how these anti-patterns make it difficult to protect user privacy on the web.
-
Brave's Concerns with the Client-Hints Proposal
Written with:WebStandards@Brave Discussion of concerns with the proposed Client Hints standard, and why it would be harmful for web privacy.
- Pranjal Jumde
- Tom Lowenthal
- Brian Clifton
-
Understanding Redirection-Based Tracking
Written with:Brave Blog Blog post description research lead at Brave regarding the frequency and parties involved in bounce-tracking. Conducted as part of designing Brave's improvements to Safari's Intelligent Tracking Prevention 2.0.
- Ben Livshits
-
The Mounting Cost of Stale Ad Blocking Rules
Written with:Brave Blog Blog post describing research lead at Brave regarding the number and cost of the accumulation of stale rules in EasyList.
- Antoine Vastel
- Ben Livshits
Teaching
Selected Talks
- Testimony in Favor of Required Browser Opt-Out Signals: AB 3048 other California Senate Judiciary Committee bill: pdf video
- Web Tracking In Practice and Product invited talk ECE 598 - Digital Identity @ University of Illinois at Champaign Urbana slides: keynote video
-
Designing Cryptography for Small Organizations and Projects
- Sofia Celi
- Alex Davidson
- Peter Snyder
- SugarCoat: Programmatically Generating Privacy-Preserving, Web-Compatible Resource Replacements for Content Blocking invited talk NGN Webinar: Imperial College London announcement slides: pdf video: youtube
- Online Tracking, What Can Be Done About it, and Who's Doing it invited talk CS253 - Web Security @ Stanford slides: keynote slides: pdf
- Improving the Coverage and Compatibility of Web Content Blocking in Brave Browsers invited talk Stanford Security Lunch
- Best-of-Breed Content Blocking in Brave: Three Projects to Improve the Depth, Breath, and Usefulness of Blocking at Scale invited talk MADWeb slides: pdf
- Brave, Fingerprinting, and Privacy on the Web invited talk CS253 - Web Security @ Stanford slides: pdf video
- Privacy, Standards and Anti-Patterns invited talk PEARG slides: pdf
- Brave, Privacy and Standards invited talk WWW slides: pdf
- Web Privacy Beyond Extensions: New Browsers Are Pursuing Deep Privacy Protections conference presentation USENIX Enigma slides: pdf
- No Please, After You: Detecting Fraud in Affiliate Marketing Networks invited talk Department of Information Engineering at Chinese University of Hong Kong slides: pdf
Significant Programs and Code
- Brave Browser PRs Features and bugfixes I've added to the Brave browser while working at Brave.
- University of Illinois at Chicago Computer Science Thesis Template source (Oddly!) I still maintain the thesis template for my university's PhD thesis.
- Fingerprinting Protections additional APIs hardening technique change Improved the technique used to block fingerprinting related Web API methods to reduce the impact on non-fingerprinting related code, and expanded the set of blocked Web API methods to cover five more, previously allowed, methods used for fingerprinting users.
- Web API Manager Browser Extension firefox extension source WebExtension, cross-browser extension that allows users to improve their privacy and security online by controlling what browser functionality web hosts have access to. Web API functionality access controls can be defined in general, or on a per host level, and can allow, for example, only trusted hosts to have access to privacy-risky browser functionality like high resolution timers, WebGL and WebRTC.
- CDF: Abstractions for Security Guarantees in Interactive Web Applications paper source Built client and server-side tools for implementing CDF, a document format for building dynamic, interactive web applications that provide increased security and privacy guarantees for users of commodity web browsers.
- FormBug source A Firefox extension to make dealing and developing form based applications easier. I just maintain it now, but wrote it back when I was doing web development work.
- Dijkstra's Algorithm (Objective-C implementation) cocoapods source Library to perform Dijkstra in Objective-C (for iOS and OSX).
- Cloudsweeper paper Web app to measure and mitigate the frequency of plaintext password sharing in Gmail archives. The public tool allows users to redact or encrypt-in-place found passwords. The site has had over 2,500 users and has secured over 38,000 messages
- Machine Learning for Automatic 8bit Song Generation slides: ppt source Library to write original NES chip-style soundtracks using a corpus of 39 classic NES games and machine learning.
Non-Technical Writing
-
In Chicago's Old Town and elsewhere, NIMBY opponents block new housing
Written with:op-ed Chicago SunTimes
- Steven Vance
- Get rid of parking mandates that keep Chicago car-centric letter to the editor Chicago SunTimes
Positions and Accomplishments
- I am Brave's AC member in the W3C.
- I did an Reddit AMA about privacy and Brave.
- I co-chair PING, the group responsible for reviewing the privacy aspects of new web standards.
- Our paper on Web API security and privacy was a finalist in the CSAW’17 Applied Research Competition.
- I was a fellow in UIC's Electronic Security and Privacy IGERT.
- I organized a crypto reading group at UIC.
- I placed first as the Symantec Cyber Challenge Competition, held at UIC.
- I twice served as the president for the UIC computer science graduate student association.
- I advise TIMBY, a community investigating website and project, on web and application security issues.
Misc. Bits
- I was invited to be on the Judge Judy show once.
- I was half of the Chicago chiptune band 🍒🍒💣.
- I sang and played guitar in a Chicago power-pop band called The Pleasure Centers.
- A while back I played in a LOST-themed band called Sonic Weapon Fence.
- Sometimes I record chiptune music solo.
- Before it closed, I volunteered tutoring Chicago high school students as part of the East Village Youth Program.
Community Involvement
Venue | Position |
---|---|
2026 | |
PETS | PC Member |
2025 | |
PEPR | PC Member |
MADWeb | PC Member |
2024 | |
USENIX Security | PC Member |
S&P | PC Member |
PEPR | PC Member |
MADWeb | PC Member |
2023 | |
USENIX Security | PC Member |
S&P | PC Member |
MADWeb | PC Member |
2022 | |
USENIX Security | PC Member |
WWW | PC Member |
PEPR | PC Member |
MADWeb | PC Member |
2021 | |
USENIX Security | PC Member |
CCS | PC Member |
MADWeb | PC Member |
WWW | PC Member |
2020 | |
SIGCOMM CCR | External Reviewer |
MADWeb | PC Member |
WWW | PC Member |
2019 | |
CSAW | PC Member |
Journal of Cybersecurity | External Reviewer |
MADWeb | PC Member |
2018 | |
DTL Grants | Reviewer |
CSAW | PC Member |
CHI Late Breaking | External Reviewer |
2017 | |
USENIX Security | External Reviewer |
NDSS | External Reviewer |
2016 | |
S&P | External Reviewer |
CCS | External Reviewer |
2015 | |
CCS | External Reviewer |
2013 | |
NDSS | External Reviewer |