The next front in the cookie wars: Fighting the Evercookie


  1. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #1

    The next front in the cookie wars: Fighting the Evercookie


    Read More:

    The next front in the cookie wars: Fighting the Evercookie | IT Security | TechRepublic.com

    “Evercookie is a JavaScript API that produces extremely persistent cookies in a browser. Its goal is to identify a client even after they’ve removed standard cookies, Flash cookies, and others.”

    Here we go again.
    Let’s assume the cookie data we want to store is “bcde”. Evercookie then accesses the following URLs in the background:

    • google.com/evercookie/cache/b
    • google.com/evercookie/cache/bc
    • google.com/evercookie/cache/bcd
    • google.com/evercookie/cache/bcde
    • google.com/evercookie/cache/bcde-

    These URLs are now stored in the browser’s history. When checking for a cookie, Evercookie loops through all the possible characters on google.com/Evercookie/cache/, starting with “a” and moving up, but only for a single character.
    Once it sees a URL that was accessed because it’s in the browser’s history, it attempts to brute force the next letter. This process occurs extremely fast because no requests are made to the server in question. Evercookie knows it has reached the end of the string as soon as it finds a URL that ends in “-”.
    TechRepublic: Can Evercookie be defeated by disabling JavaScript or using an application like NoScript?
    Samy Kamkar: Yes, NoScript or turning off JavaScript will prevent the Evercookie from being created.
      My Computer


  2. Posts : 826
    Windows 7 Professional 64 Bit SP1
       #2

    Yet more marketers trying to profile browsing habits.

    This is really sad, as it's hard enough controlling the flow of your personal data currently, but it seems like things will only get worse in the near future~

    Thanks for the info :)

    Borg 386 said:
    Read More:

    The next front in the cookie wars: Fighting the Evercookie | IT Security | TechRepublic.com

    “Evercookie is a JavaScript API that produces extremely persistent cookies in a browser. Its goal is to identify a client even after they’ve removed standard cookies, Flash cookies, and others.”
      My Computer


  3. Posts : 11,424
    Windows 7 Ultimate 64
       #3

    Someone needs to develop a program and call it warm milk as warm milk dissolves cookies! Or better yet cookie monster to eat up the evercookies.
      My Computer


  4. Posts : 966
    Windows 7 Enterprise
       #4

    "C" is for cookie.

    Thats good enough for me.
      My Computer


  5. Posts : 10,994
    Win 7 Pro 64-bit
       #5

    Still don't understand why we have to resort to plug-ins or add-ons like NoScript to accomplish what should be a standard feature of all browsers.
      My Computer


  6. Posts : 826
    Windows 7 Professional 64 Bit SP1
       #6

    I found this to be a interesting read: In the war of Internet privacy, Internet Explorer 8 limit the default credentials of third-party cookie tracking | My Computers Land

    "Microsoft engineers initially wanted to feature in Internet Explorer 8 to limit the default credentials of third-party cookie tracking, Wall Street Journal reported today. But the leaders, concerned about the implications for online advertisers, has won"

    "Only one – Safari from Apple – is set to deny third-party cookies based on privacy."

    marsmimar said:
    Still don't understand why we have to resort to plug-ins or add-ons like NoScript to accomplish what should be a standard feature of all browsers.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:41.
Find Us