Live data from Hacker News

Evercookie: A cookie that undeletes itself from 8 different storages

samy.pl

91–100 of 114 posts

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#92
post #31

Seems like this will be pretty effective even if widely known, since clearing one of these 'cookies' will require deleting a lot of info, including some you were probably using. You'll be simultaneously clearing history and cache, logging yourself out of every site you're logged into, clearing all offline state in every web app you use, etc. Most people won't want to do that often.

It's not a big deal.

I have Firefox purge everything except saved passwords every time I quit. I also use better privacy to purge LSOs and DOM storage. It really doesn't effect my quality of life when browsing the web. That being said I don't use a lot of sophisticated web applications that require complex preferences to be set and kept in local storage.

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#93
post #33

What's truly disturbing is that this absolutely meets a need for a paid gig I'm working on now, where the client wants persistent identity tracking for the purposes of marketing and analytics. (I'm part of the problem, aren't I?)

You're not the only one, the SEO people in my company got onto this surprisingly quickly. I sometimes feel black (hat) has become the new white: for whatever reasons companies seem to be more willing to accept the less ethical sides of doing business on the web. Anyone else notice this or is it just me?

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#94

Earlier quoted context omitted.

rm -rf ~/.macromedia works pretty well.

...followed by ln -s /dev/null ~/.macromedia

That breaks some things.

i.e. the escapist thinks you're a scraping bot and bans you from viewing their videos for a week.

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#98
post #15

Earlier quoted context omitted.

Also now that it's packed up so tidily, we'll probably get some better tools for blocking/removing all of those tricks. Think of it like an Acid3 test for browser security.

That's a good perspective. It's my fervent hope someone names their tool everenema.

I humbly suggest "Everclear"

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#99
post #77
post #2

Once again I am forced to golf clap for a horrifying idea brilliantly executed.

Of course though it's fairly unnecessary. If all you want to do is track users, it's far easier to use UserAgent/screensize/plugins/etc to uniquely identify users. https://panopticlick.eff.org/ You can then store anything heavier server side.

It seems to work remarkably well. And they do not even use all the tricks imaginable. E.g. you could add lots of more volatile information to the fingerprint, if you also added some statistical intelligence.

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#100
post #86

Earlier quoted context omitted.

I also have Firefox clearing all cookies and all history on exit so that probably helped during my testing. BetterPrivacy dealt with the lso stuff though. I don't know why people allow cookies to persist between browser sessions. I've been clearing them on exit for years now and it really doesn't make it more difficult to use the Web.

I only restart Firefox 1 or 2 times a month. Keeping all those tabs open really is far more useful than having the same sites bookmarked.

You can ask Firefox to restore the tabs from the last session. So restarting becomes cheap. (You can also do this to Chrome and Opera, and probably other browsers.)
Post reply on HN