12 ms·
Undeletable Cookies
- icode 15y agoNot undeletable. Just not deleted via the browsers "delete cookies" function.
- davidu 15y agoI would not advise that argument as a legal defense strategy.
- wingo 15y agoVery interesting, and evil: abusing the ETag mechanism for user tracking. (If a user requests some sort of unchanging resource without an etag, you give them a fresh one; and if they request a resource with an etag, you give it to them, with the supplied etag, and record the user.) Even if Hulu turned off cookie respawning via etags, you can still track users this way, on the server side. I guess the tricky thing is to correlate the etag of the tracker resource with the rest of the requests that a user makes on a site.
- apgwoz 15y ago> Even if Hulu turned off cookie respawning via etags, you can still track users this way, on the server side. I guess the tricky thing is to correlate the etag of the tracker resource with the rest of the requests that a user makes on a site. The important distinction is that the ETag is literally no different than a cookie, when used this way. Turning off caching is the new turning off cookies.
- wingo 15y agoThere is a difference: cookies get sent on requests to any resource in a domain, whereas etags get sent only to specific resources.
- rjbond3rd 15y ago> ...the tricky thing is to correlate the etag of the tracker resource with the rest of the requests that a user makes... Not tricky though. Just put 1-pixel Etagged gif on every page. It gets requested on each page. Or just associate (server-side or client-side) the user's session cookie with the Etag.
- nbpoole 15y agoSee also: http://news.ycombinator.com/item?id=2844321 http://news.ycombinator.com/item?id=2844321
- ynniv 15y agoETag and cache based cookies are old news. I assume that Schneier didn't notice these components last time he reported on evercookie. [ http://google.com/search?q=evercookie http://google.com/search?q=evercookie ]
- nikcub 15y agoIt is a lot older than evercookie. I remember porn affiliate scripts that were using ETag back in 01-02. It is a well known method, as is using Last-Modified.
- gmac 15y agoI wonder how this will be treated under the EU's Directive on cookies... Edit: sorry, not found an answer yet, but the top Google result for 'EU cookies' is rather fun: http://www.davidnaylor.co.uk/eu-cookies-directive-interactive-guide-to-25th-may-and-what-it-means-for-you.html http://www.davidnaylor.co.uk/eu-cookies-directive-interactiv...
- route66 15y agoSchneier does not tell so much here, instead he links to this article giving more details: http://ashkansoltani.org/docs/respawn_redux.html http://ashkansoltani.org/docs/respawn_redux.html
- nirvana 15y agoI believe Google is doing this with its google voice product. We're unable to access our google voice accounts outside the USA, despite disabling flash, deleting all cookies, etc. The ironic thing is, of course, that this is when we need it the most, as we miss more calls being in a radically different time zone.
- dchest 15y agoI'd say they disable access by IP, but I can access my account from two countries that are far outside the US.
- nirvana 15y agoWell, I'm using different IPs than the "home" IP we used when we signed up. Any attempts to get into google voice for me, though, say that it is not allowed outside the USA.
- kahawe 15y agoYep, so they just filter by whatever IP you are connecting from from outside the US and that's it. Countless websites and services have been doing that for a looong time - just as evil but should not have anything to do with cookies because then you should be able to sign in just fine on a different machine and use voice.
- randomdata 15y agoI sometimes run into a problem with Google that when I try to log out, I remain logged in. Even after deleting my cookies, I find myself logged in still. This may explain why.
- abraham 15y agoThat should never happen. You should email security@google.com.
- drivebyacct2 15y ago
- ck2 15y agoReminds me to write a firefox plugin to strip etags and "if-none-match" - pretty sure most pages can function just fine without them and use last-modified, etc instead. Kind of surprised to not find anything yet on addons.mozilla.org
- CGamesPlay 15y agoYou do that, and I'll just assign a unique UNIX timestamp to each visitor.
- ck2 15y agoThat's a good point and this would not be practical in a regular browser session but if someone chooses private browsing, an extension could be sure to strip "last-modified" as well as "if-none-match". Would hurt the server a little and reduce speed because there would not be any caching but still helps guarantee no tracking.
- ars 15y agoOn a properly written server you could "fuzz" the date of "if-none-match". Then it would still work for caching, but would not uniquely identify you. The trouble is that most servers are not written properly, the date is not parsed, rather it's string compared with the file date. For example if the server sends the timezone as EST vs +0400 the browser will send it back exactly as it gets it, when normally you would think that should not matter.
- bwag 15y agoInteresting. Wikipedia references two add-ons written back in 2007 for this purpose. No idea if they still work on more recent versions of FF. http://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags http://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags
- ck2 15y agoThe writeup about the two extensions for firefox is wrong, those two were meant to block the trick where you can determine if a user has visited a specific site/page by looking at the link color/state.
- hammock 15y agoFrom wikipedia: ETags may be flushable by clearing the browser cache (but browser implementations may vary). In 2007, two Mozilla Firefox add-ons were made to prevent the usage of ETags for tracking.[5][6] [5]https://addons.mozilla.org/en-US/firefox/addon/safecache/ https://addons.mozilla.org/en-US/firefox/addon/safecache/ [6]https://addons.mozilla.org/en-US/firefox/addon/safehistory/ https://addons.mozilla.org/en-US/firefox/addon/safehistory/
- jim_h 15y agoThe safehistory plugin doesn't seem to work for the newer versions based on the comments on their page.
- yaix 15y agoEven better is the paper (written 2003) linked in the comments of the article: http://www.arctic.org/~dean/tracking-without-cookies.html http://www.arctic.org/~dean/tracking-without-cookies.html
- youngtaff 15y agoThe potential of etags as a way of tracking has been known about for a while... To put the other side of this argument Kiss Metrics put up a pretty strong denial that they were using etags for tracking http://bit.ly/r5lPbx http://bit.ly/r5lPbx Guess it might need a bit more research
- RyanGWU82 15y agoWell, they said that they "made the following changes" -- one of which is not using eTags. So I guess they stopped that. (That said, they never aggregated this data across multiple websites, so I really don't get what the whole fuss was about.)
- mtogo 15y agoThey tried to make their cookies undeletable. Why would they do something like that? The fuss is that it's a bad, dishonest, skeezy thing to do. Kissmetrics has shown that they are not an honest company, they're a dishonest one that will disregard the privacy concerns of their user's visitors.
- coderdude 15y agoRyanGWU82 makes a good point though. People only whined about the "evercookie" method of tracking because of the potential for abuse (across multiple Web properties). Why on Earth would you care if someblog.com knows for sure that you've been to their site five times? I don't think the problem here is that you can be tracked using multiple methods that were not originally intended for use in tracking. I think the problem is that people always had a false sense of privacy (i.e., there was ignorance about what can and cannot be used to track your client). You're accessing a remote server. There will always be a way for sites to track your visits. There is a necessity for those sites to track your visits. Don't care about their necessity to track you? Stop going to those sites.
- RyanGWU82 15y agoSee, I still don't understand how this is dishonest. They didn't try to make "undeletable cookies," they're not using cookies! I understand that to a layperson "cookie" means "anything that identifies me to a web site," but they're wrong, and what's dishonest about using an analytics mechanism that's not a cookie?
- driverdan 15y agoI don't understand why this keeps getting press. It's nothing new, this method has been around for at least 4 years. Schneier should be well aware of it.
- woodall 15y agoYou blog to make OTHERS aware.
- mtogo 15y agoThis is not news. Evercookie has been doing this for years, and it's just as easy to defeat as it was years ago. http://samy.pl/evercookie/ http://samy.pl/evercookie/
- nodata 15y agoObligatory link to Panopticlick: http://panopticlick.eff.org/ http://panopticlick.eff.org/
- praptak 15y agoWhat it really boils down to is this: you cannot have both caching and privacy. For the cache to work your browser must reveal to the server what it has already downloaded, this way or another. And the browser cannot really tell which of the downloaded pieces of data were specially generated to track this particular user. A possible workaround is to create an intermediate cache to share it with multiple other people, but this creates other privacy concerns.
- NiekvdMaas 15y agoWe created a PoC a while ago showing ETag + browser fingerprinting to replace cookies/client-side storage: http://www.adperium.com/tracking http://www.adperium.com/tracking It works in all major (desktop) browsers, but not in some mobile browsers. I think the cookie debate (in the EU) is not in the best interest of users: with cookies, the user has full control of the data stored, can easily purge cookies, etc. With user-tagging technology moving server-side, this gets a lot more complicated.