Live data from Hacker News

Evercookie: A cookie that undeletes itself from 8 different storages

samy.pl

101–110 of 114 posts

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#102
post #59
post #47

Earlier quoted context omitted.

Nope, just tried it. Incognito, cookies there. Clear cache, incognito mode again and 3 types still captured. Really quite fascinating.

So we need a stateless browser and don't have one.

wget or curl come to my mind

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#105
post #79
post #74

Earlier quoted context omitted.

It's not evil. It just shows that "Clear cookies" button is no longer an effective privacy tool. Browser vendors are aware of this already and working to make evercookie no worse than regular cookie, e.g. Mozilla blocked reading of visited link history, Chrome privacy window has link to Flash LSO controls. All vendors are working towards making it better integrated and more effective against all "evercookies".

> It just shows that "Clear cookies" button is no longer an effective privacy tool. It has never been. the vast majority (90%+) of browsers are uniquely identifiable simply from useragent, plugins, capabilities etc. https://panopticlick.eff.org/browser-uniqueness.pdf

If privacy is dead as has been asserted there are no longer any effective countermeasures.

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#106
post #89
post #72

Earlier quoted context omitted.

the essential reason of this kind of persistence is that it has to survive the explicit deletion of the cookie by the user. Browser offer the user the possibility to remove cookies (manually or delete all), and this is because users want privacy. This clever library manages to exploit browser features to go around this and store some identification information persistently against the will of the user If the user doe…

Your exploiting a security hole in my browser and overriding my explicit wishes to benefit your company is no more ethical than my exploiting a security hole in your website and "fixing" your database.

What about combatting trolls?

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#107
post #67

What are the privacy laws surrounding conciously cirumventing user intent like is? Is it legal to use this in the USA? In Europe?

for me that the major question here. what are the legal implications since using this sort of cookie involves a set of hacks that derive the normal use of various systems for a purpose they were not intended for in the first place, and since it is intended to defeat some of the privacy protections of browsers. I am not condemning this clever system but I am curious of the privacy and other legal issues here...

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#108
post #89
post #72

Earlier quoted context omitted.

the essential reason of this kind of persistence is that it has to survive the explicit deletion of the cookie by the user. Browser offer the user the possibility to remove cookies (manually or delete all), and this is because users want privacy. This clever library manages to exploit browser features to go around this and store some identification information persistently against the will of the user If the user doe…

Your exploiting a security hole in my browser and overriding my explicit wishes to benefit your company is no more ethical than my exploiting a security hole in your website and "fixing" your database.

How many software include tricks to get around firewalls by punching holes (http://www.h-online.com/security/features/How-Skype-Co-get-r...). Is this unethical because it circumvents an explicit user wish? Do people even know that they have a firewall, or know what a firewall is, or do people even have control on the firewall settings (at work for example)?

Of course they want to run e.g. skype, who doesn't, right?! I know that there is something arbitrary in all that, that's the point.

I didn't say it was ethical to circumvent the user wishes. I said that some people might reason in such a way that it makes them feel morally excused for exploiting something which is perceived as an unethical technique in order to perform a licit goal.

The main points behind this mind setting are:

(here "you" are the application devel, not the evil guy, of course)

* point out the user de facto doesn't have control on his privacy settings by disabling the cookies, since the Bad Guys (TM) already have a hack to go around it.

* point out that the user is not even conscious of what privacy and security risks are, and often run a browser preconfigured by the sysadmin, nephew, whatever, which might decide to conservatively block cookies "because they are bad".

* you are not exploiting the cookies with the purpose to invade user privacy. You are just building an application X (see grand parent question) which exploits the same hack to get around the 'default paranoid settings'.

* you feel stupid to limit your application functionality just to obey some obviously bugged rule. It would be like skype saying "oh, there is a firewall, I know how to get around it, but I won't because it's unethical since people have the right to setup a firewall according to their wishes".

(of course these points are valid once this technique becomes mainstream, and all tracking sites employ it)

I'm not saying that behaving this way is ethical or not or less unethical. I'm just supposing that there might be some uses of this technique which are not directly intended to trace the identity of a user for malicious reasons (marketing etc) but for providing some functionality to the average user of a particular product (who asks for it).

People might be pissed out because some features don't work. They don't care why. Application providers are also pissed off when half of their users cannot use a given feature because some sysadmin/security software/nephew hacker decided to impose some restriction (settings, firewall rules etc), even if there are valid reasons for the restriction (settings, firewall, etc) to be be there.

Re: Evercookie: A cookie that undeletes itself from 8 different storages

#109
post #89

Earlier quoted context omitted.

Your exploiting a security hole in my browser and overriding my explicit wishes to benefit your company is no more ethical than my exploiting a security hole in your website and "fixing" your database.

What about combatting trolls?

what about free speech?
Post reply on HN