2 ms·
As we have just found out... "cookies" have evolved exactly the same way that malware has. Persistence is maintained without writing to disk, using a variety o
by cnd 8y ago
As we have just found out... "cookies" have evolved exactly the same way that malware has.
Persistence is maintained without writing to disk, using a variety of methods.
Three of those which I now know about include
a) all google pages have javascript which polls or gets an event when cookies change, and this script fires to rejuvenate the cookies using an ID stored inside the page HTML.
b) some google pages store an ID inside the browser URL, so the next page you visit tells google who you were again via the referrer
c) Chrome itself tracks you if you don't switch off that obscure setting mentioned above.
Probably the more-likely method of solving this problem is to poison the cookies, instead of remove them. Google will be tracking billions of devices, so it seems probable that their client side code will not know the difference between a "real" and a "fake" cookie - so long as your code produces cookies that their JS etc thinks is "real", it's not going to trigger the rejuvenation step.
- rasz 8y agoThis isnt a problem,. you can override default cookie method var cookieDesc = Object.getOwnPropertyDescriptor(Document.prototype, 'cookie') || Object.getOwnPropertyDescriptor(HTMLDocument.prototype, 'cookie'); if (cookieDesc && cookieDesc.configurable) { Object.defineProperty(document, 'cookie', { get: function () { return cookieDesc.get.call(document); }, set: function (val) { console.log(val); cookieDesc.set.call(document, val); } }); } and filter what gets stored before it touches the Cookie database.