Live data from Hacker News

Code Known as Flash Cookies Raises Privacy Concerns

nytimes.com

1–10 of 13 posts

Re: Code Known as Flash Cookies Raises Privacy Concerns

#5
post #2

Oh so now it's a big deal? These have been around forever people, c'mon!

They've been here forever, but there is still no good (user friendly) way to delete them. No easy way to define a privacy profile (delete cookies when I close my browser...).

I don't understand why flash doesn't hook into browser privacy settings by default. Instead, you have to install custom software like the firefox betterprivacy extension: https://addons.mozilla.org/en-US/firefox/addon/6623/.

Re: Code Known as Flash Cookies Raises Privacy Concerns

#6
post #2

Oh so now it's a big deal? These have been around forever people, c'mon!

They've been here forever, but there is still no good (user friendly) way to delete them. No easy way to define a privacy profile (delete cookies when I close my browser...). I don't understand why flash doesn't hook into browser privacy settings by default. Instead, you have to install custom software like the firefox betterprivacy extension: https://addons.mozilla.org/en-US/firefox/addon/6623/ .

I believe the new flash player versions do respect the private browsing modes of browsers.

Back when I used to use windows, I used to touch two files called "#Security" and "#SharedObjects" in the flash player app data folder, which prevented it from downloading anything at all. In retrospect, it was an overly heavy-handed way of doing things :)

Re: Code Known as Flash Cookies Raises Privacy Concerns

#8
“The core function of the cookie is to link what you do on Web site A to what you do on Web site B,” said Peter Eckersley, a technologist at the Electronic Frontier Foundation. “The Flash cookie makes it harder for people to stop that from happening.”

I think the technologist intends to refer to third-party cookies.

Re: Code Known as Flash Cookies Raises Privacy Concerns

#10
post #8

“The core function of the cookie is to link what you do on Web site A to what you do on Web site B,” said Peter Eckersley, a technologist at the Electronic Frontier Foundation. “The Flash cookie makes it harder for people to stop that from happening.” I think the technologist intends to refer to third-party cookies.

No. Third party cookies do something similar, but don't always work with all browsers/privacy settings. Specifically, Safari won't accept third party cookies from non-blessed domains (one the user didn't navigate to on purpose). Some IE flavors needed the cookie to have a compact privacy policy in the header, something that was never audited or checked...total honor system.

This was a big problem at my last job, trying to get an accurate count of unique visitors to a network of around 50 distinct domains. Nothing nefarious, just trying to get a sense of which visitors on site A were the same (anonymous) visitors on site B.

Flash "cookies" work with more desktop browsers, although they always felt like an ugly hack.

Post reply on HN