Earlier quoted context omitted.
That's a good perspective. It's my fervent hope someone names their tool everenema.
I humbly suggest "Everclear"
Evercookie: A cookie that undeletes itself from 8 different storages
101–110 of 114 posts
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#102Re: Evercookie: A cookie that undeletes itself from 8 different storages
#103Firefox's BetterPrivacy addon defeats all of these techniques. I just tested and confirmed this myself.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#104Re: Evercookie: A cookie that undeletes itself from 8 different storages
#105Earlier quoted context omitted.
It's not evil. It just shows that "Clear cookies" button is no longer an effective privacy tool. Browser vendors are aware of this already and working to make evercookie no worse than regular cookie, e.g. Mozilla blocked reading of visited link history, Chrome privacy window has link to Flash LSO controls. All vendors are working towards making it better integrated and more effective against all "evercookies".
> It just shows that "Clear cookies" button is no longer an effective privacy tool. It has never been. the vast majority (90%+) of browsers are uniquely identifiable simply from useragent, plugins, capabilities etc. https://panopticlick.eff.org/browser-uniqueness.pdf
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#106Earlier quoted context omitted.
the essential reason of this kind of persistence is that it has to survive the explicit deletion of the cookie by the user. Browser offer the user the possibility to remove cookies (manually or delete all), and this is because users want privacy. This clever library manages to exploit browser features to go around this and store some identification information persistently against the will of the user If the user doe…
Your exploiting a security hole in my browser and overriding my explicit wishes to benefit your company is no more ethical than my exploiting a security hole in your website and "fixing" your database.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#107What are the privacy laws surrounding conciously cirumventing user intent like is? Is it legal to use this in the USA? In Europe?
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#108Earlier quoted context omitted.
the essential reason of this kind of persistence is that it has to survive the explicit deletion of the cookie by the user. Browser offer the user the possibility to remove cookies (manually or delete all), and this is because users want privacy. This clever library manages to exploit browser features to go around this and store some identification information persistently against the will of the user If the user doe…
Your exploiting a security hole in my browser and overriding my explicit wishes to benefit your company is no more ethical than my exploiting a security hole in your website and "fixing" your database.
Of course they want to run e.g. skype, who doesn't, right?! I know that there is something arbitrary in all that, that's the point.
I didn't say it was ethical to circumvent the user wishes. I said that some people might reason in such a way that it makes them feel morally excused for exploiting something which is perceived as an unethical technique in order to perform a licit goal.
The main points behind this mind setting are:
(here "you" are the application devel, not the evil guy, of course)
* point out the user de facto doesn't have control on his privacy settings by disabling the cookies, since the Bad Guys (TM) already have a hack to go around it.
* point out that the user is not even conscious of what privacy and security risks are, and often run a browser preconfigured by the sysadmin, nephew, whatever, which might decide to conservatively block cookies "because they are bad".
* you are not exploiting the cookies with the purpose to invade user privacy. You are just building an application X (see grand parent question) which exploits the same hack to get around the 'default paranoid settings'.
* you feel stupid to limit your application functionality just to obey some obviously bugged rule. It would be like skype saying "oh, there is a firewall, I know how to get around it, but I won't because it's unethical since people have the right to setup a firewall according to their wishes".
(of course these points are valid once this technique becomes mainstream, and all tracking sites employ it)
I'm not saying that behaving this way is ethical or not or less unethical. I'm just supposing that there might be some uses of this technique which are not directly intended to trace the identity of a user for malicious reasons (marketing etc) but for providing some functionality to the average user of a particular product (who asks for it).
People might be pissed out because some features don't work. They don't care why. Application providers are also pissed off when half of their users cannot use a given feature because some sysadmin/security software/nephew hacker decided to impose some restriction (settings, firewall rules etc), even if there are valid reasons for the restriction (settings, firewall, etc) to be be there.
Re: Evercookie: A cookie that undeletes itself from 8 different storages
#109Earlier quoted context omitted.
Your exploiting a security hole in my browser and overriding my explicit wishes to benefit your company is no more ethical than my exploiting a security hole in your website and "fixing" your database.
What about combatting trolls?