nsane.forums Posted September 22, 2010 Share Posted September 22, 2010 The war against persistent zombie cookies—cookies that never seem to lose your data, even when you delete them—rages on, as users learn more about the technology. While awareness is rising thanks to widespread coverage of Flash cookies and, more recently, HTML5's storage capabilities, we have a long way to go before Internet users can avoid persistent tracking. Like all zombie wars, this one will take some time to win; and if you thought things were bad now, they're about to get worse. Case in point: evercookie, an open source JavaScript API by developer Samy Kamkar. When implemented by a website, evercookie stores a user ID and cookie data in not two, not three, but eight different places—with more on the way. Among them are your standard HTTP cookies, Flash cookies, RGB values of force-cached PNGs, your Web history, and a smattering of HTML5 storage features. In addition, Silverlight Storage and Java are apparently on the way. So, when you delete the cookie in one, three, or five places, evercookie can dip into one of its many other repositories to poll your user ID and restore the data tracking cookies. It works cross-browser, too—if the Local Shared Object cookie is intact, evercookie can spread to whatever other browsers you choose to use on the same machine. Since most users are barely aware of these storage methods, it's unlikely that users will ever delete all of them. "Simply think of it as cookies that just won't go away," reads the evercookie FAQ. Sound evil? It is. But Kamkar—whose motto is "think bad, do good"—doesn't seem all that evil. In fact, Kamkar told Ars that he wrote evercookie to raise user awareness about the ways in which companies can track them. "I hope evercookie simply demonstrates to people what types of methods are being employed to track them and to decide whether or not they want to prevent those methods," he said. "evercookie took less than a day to create for me as a security hobbyist, so I can only imagine the technology that funded developers are producing." Kamkar says he doesn't actually use evercookie to track people—it exists largely as a proof of concept, and he's not using technologies that are particularly bleeding edge in the developer world. "None of these are new techniques," he told Ars, "but an API like this is awesome at raising awareness." Of course, the mere fact that evercookie exists (and exists as an open source project that anyone can use) means that there will be some evil Web developers who make use of it, but that's almost the point. We're supposed to be scared. Kamkar sees his project as a kind of litmus test to see whether people really are up to protecting themselves from being tracked by persistent cookies that anyone could implement, but he also understands that the "average" Internet user is hardly aware of traditional cookies, much less Flash cookies and beyond. Deleting the data from all eight (or more) storage mechanisms can be a pretty daunting task even for the relatively experienced surfer. "I hope to produce software that allows deleting data from any and all of these storage mechanisms for the average user to make use of," Kamkar said. "I also hope evercookie stems others to develop similar software." Kamkar's API comes just days after a lawsuit was filed against a company for making use of the HTML5 Web SQL database storage capabilities that come with Safari, Chrome, and Opera. First exposed by Ars Technica, this particular company (Ringleader Digital) made an effort to keep a persistent user ID even when the user deleted cookies and their HTML5 databases, telling Ars that the only way to opt out of the tracking was to use the company's opt-out link (which gives the user no confirmation that they are, in fact, opted out.) Then there are a number of previous lawsuits over zombie Flash cookies, which have the same goal when it comes to user tracking. They don't want you to delete their info, so they work around it by storing the data in multiple places and restoring it once you delete. While Internet users wait for software to protect against such extensive tracking, Kamkar did point out that the safe browsing mode in many browsers will probably help for now. "I found that using 'Private Browsing' in Safari stops all evercookie methods," he said. View: Original Article Link to comment Share on other sites More sharing options...
Ambrocious Posted September 23, 2010 Share Posted September 23, 2010 So basically he is going to violate us until we learn to protect ourselves? Maybe if this was like cyber warfare this would be a good idea in order to learn how to defend yourself but this would warrant that you actually have knowledge of this or at least warning, but this effects everyone so by far this is slightly insidious to start with. Link to comment Share on other sites More sharing options...
CODYQX4 Posted September 24, 2010 Share Posted September 24, 2010 Anyone know if CCleaner + CCEnhancer misses any of this crap? Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted September 24, 2010 Administrator Share Posted September 24, 2010 In order to stay safe from Zoobie cookies, you have to right click on a flash item and select settings, it will lead you to a webpage where you'll have to disable them storing something like cookies on your computer. Link to comment Share on other sites More sharing options...
HX1 Posted September 24, 2010 Share Posted September 24, 2010 Oh search for and use BetterPrivacy extension for your Firefox..Yes check your plugin settings.. and your Java. as well...:think: I always went that far... thought everyone else did too...HTML5 may bring something new to change.. but developers are always right there with it.. Link to comment Share on other sites More sharing options...
HX1 Posted September 24, 2010 Share Posted September 24, 2010 Thing is that some forms of flash and resources in websites and applications rely on them.. so end point being that people need to be able to clean them out just like everything else... or be able to decide rather they should even enter into your system or not.. I don't want them and I have no use for it.. I do have a right to protect that privacy.. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.