Yet another moment in human history where someone brilliant decided to do something because they could without asking if they should.
Perhaps one day Samy will look back and reflect that he isn't evil man, though he has done evil things.
(The thing is I'm not even sure how serious I am. On the one hand, damn, clever. But on the other hand, I can see some truly miserable privacy issues at play here.)
All of the methods he uses have been known to the web-app security community for a while. He's simply raising awareness of what's already broken.
Keeping these things quiet helps nobody. We need more privacy and security issues to be publicly demonstrated so that they'll get fixed instead of ignored.
As an example, his work exploiting wireless routers to get location is genius. Who would have thought that having your router's wireless MAC available to your internal network allows a website to determine your location to within a few hundred feet? It uses well known and oft ignored attack methods to produce a sensational result with which everyone can immediately identify.
Also now that it's packed up so tidily, we'll probably get some better tools for blocking/removing all of those tricks. Think of it like an Acid3 test for browser security.
It's not evil. It just shows that "Clear cookies" button is no longer an effective privacy tool.
Browser vendors are aware of this already and working to make evercookie no worse than regular cookie, e.g. Mozilla blocked reading of visited link history, Chrome privacy window has link to Flash LSO controls. All vendors are working towards making it better integrated and more effective against all "evercookies".
Comments
Yet another moment in human history where someone brilliant decided to do something because they could without asking if they should.
Perhaps one day Samy will look back and reflect that he isn't evil man, though he has done evil things.
(The thing is I'm not even sure how serious I am. On the one hand, damn, clever. But on the other hand, I can see some truly miserable privacy issues at play here.)
All of the methods he uses have been known to the web-app security community for a while. He's simply raising awareness of what's already broken.
Keeping these things quiet helps nobody. We need more privacy and security issues to be publicly demonstrated so that they'll get fixed instead of ignored.
As an example, his work exploiting wireless routers to get location is genius. Who would have thought that having your router's wireless MAC available to your internal network allows a website to determine your location to within a few hundred feet? It uses well known and oft ignored attack methods to produce a sensational result with which everyone can immediately identify.
See: http://samy.pl/mapxss/
Important point. Better to let everyone see the truth of evercookie than let the bad guys enjoy it in the dark.
Still, with it all packed up so tidily, a few rascals will do something interesting with it.
Also now that it's packed up so tidily, we'll probably get some better tools for blocking/removing all of those tricks. Think of it like an Acid3 test for browser security.
That's a good perspective. It's my fervent hope someone names their tool everenema.
I humbly suggest "Everclear"
"Milk"?
Isn't it trivial to change his script to remove the cookies? I should have a look into that.
Putting IE in private browsing mode defeats it btw, so it's definitely doable.
Oh wow, putting Firefox in private browsing mode did not defeat it. That'll probably get fixed pretty quickly, I hope.
/me tries router xss
>400 Bad Request
Cross Site Action detected!
Sweet :) Though that's vs the vanilla script. Anyone know if there's one that works against DD-WRT?
That MAX thing is not precise at all. Around 600 miles away from my real location.
It's not evil. It just shows that "Clear cookies" button is no longer an effective privacy tool.
Browser vendors are aware of this already and working to make evercookie no worse than regular cookie, e.g. Mozilla blocked reading of visited link history, Chrome privacy window has link to Flash LSO controls. All vendors are working towards making it better integrated and more effective against all "evercookies".
> It just shows that "Clear cookies" button is no longer an effective privacy tool.
It has never been. the vast majority (90%+) of browsers are uniquely identifiable simply from useragent, plugins, capabilities etc.
https://panopticlick.eff.org/browser-uniqueness.pdf
If privacy is dead as has been asserted there are no longer any effective countermeasures.