Evercookie: A cookie that undeletes itself from 8 different storages
61–70 of 114 posts
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#62check out http://www.convertro.com/visitor-tracking.html . looks like the analytics guys are already using similar sketchy methods.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#63I know that in Chrome's incognito mode, nothing gets written to the disk at all (including Flash's Shared Objects). So if I open an incognito window, browse, then close Chrome, then open another incognito window and return to the page, does this defeat all this?
Will have to repeat this experiment with the current version.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#64Re: Evercookie: A cookie that undeletes itself from 8 different storages
#65Firefox's BetterPrivacy addon defeats all of these techniques. I just tested and confirmed this myself.
I don't know why people allow cookies to persist between browser sessions. I've been clearing them on exit for years now and it really doesn't make it more difficult to use the Web.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#66In firefox set about:config -> dom.storage.enabled -> false Use flashblock and also block cookies by default. The above causes evercookie to fail for me. No need to block javascript.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#67Re: Evercookie: A cookie that undeletes itself from 8 different storages
#68Earlier quoted context omitted.
Important point. Better to let everyone see the truth of evercookie than let the bad guys enjoy it in the dark. Still, with it all packed up so tidily, a few rascals will do something interesting with it.
Also now that it's packed up so tidily, we'll probably get some better tools for blocking/removing all of those tricks. Think of it like an Acid3 test for browser security.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#69Earlier quoted context omitted.
Also now that it's packed up so tidily, we'll probably get some better tools for blocking/removing all of those tricks. Think of it like an Acid3 test for browser security.
Putting IE in private browsing mode defeats it btw, so it's definitely doable.