Ever Cookie - HTML5 Gecko 1.9
Posted by: ndebord
Date: October 12, 2010 03:32AM

HTML5 in KM 1.6.xxx brings up this interesting and scary threat. EverCookie.

http://samy.pl/evercookie/

N



Edited 1 time(s). Last edit at 10/12/2010 06:13AM by ndebord.

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: guenter
Date: October 12, 2010 10:37PM

http://kmeleon.sourceforge.net/forum/read.php?1,110695,110695#msg-110695



Edited 1 time(s). Last edit at 10/12/2010 10:39PM by guenter.

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: ndebord
Date: October 13, 2010 12:18AM

Guenter,

Perhaps you can delete my post then or combine them. There is also a New York Times article about this.*

It pains me because we here at KM have managed to do so well with stopping persistent cookies with tools like FlashBlock and only using the flash DLL in plugins instead of the full install. This looks much harder to control or kill.

SIGH

* http://news.google.com/news/url?sa=t&ct2=us%2F0_0_s_2_0_t&usg=AFQjCNGJKRj8QpOgpxUxdXlhjxmI1ge5KQ&cid=8797598916424&ei=W5i0TOn-AsiPgwfblbrtAQ&rt=SEARCH&vm=STANDARD&url=http%3A%2F%2Ffreakonomics.blogs.nytimes.com%2F2010%2F09%2F27%2Falready-afraid-to-open-your-web-browser-meet-the-evercookie%2F

N

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: panzer
Date: October 13, 2010 01:47AM

Just use old versions of Km and you'll be safe. grinning smiley

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: ndebord
Date: October 13, 2010 06:07AM

Quote
panzer
Just use old versions of Km and you'll be safe. grinning smiley

Panzer,

Would love to IF they do bug fixes for Gecko 1.8 that is. <sob>

N

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: mhf
Date: October 13, 2010 05:49PM

I'm sure someone will find a way round this.

There was a long discussion about this Broadbandreports



Edited 1 time(s). Last edit at 10/13/2010 05:50PM by mhf.

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: ndebord
Date: October 13, 2010 10:01PM

Quote
mhf
I'm sure someone will find a way round this.

There was a long discussion about this Broadbandreports

mhf,

Thanks for the URL. Looks like an early beta attempt has been made that works with some, but not all browsers.


http://bleachbit.sourceforge.net/news/test-bleachbit-081-beta




N

N

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: vincent
Date: October 14, 2010 09:56PM

Just disable javascript and enable it only when it's absolutely necessary.

Re: Ever Cookie - HTML5 Gecko 1.9
Posted by: ndebord
Date: October 15, 2010 09:25AM

Quote
vincent
Just disable javascript and enable it only when it's absolutely necessary.

Vincent,

Except that one of those times when you think it is absolutely necessary is when you'll be hit.

Have read in FF MozillaZine forum that enabling the master password eliminates this threat? Any idea if that also applies to either KM 1.5.4 or KM 1.6.xx??

Tks.

N

K-Meleon forum is powered by Phorum.