Skip to content

Comment on Evercookie: A cookie that undeletes itself from 8 different storagesparent

Comments

All of the methods he uses have been known to the web-app security community for a while. He's simply raising awareness of what's already broken.

Keeping these things quiet helps nobody. We need more privacy and security issues to be publicly demonstrated so that they'll get fixed instead of ignored.

As an example, his work exploiting wireless routers to get location is genius. Who would have thought that having your router's wireless MAC available to your internal network allows a website to determine your location to within a few hundred feet? It uses well known and oft ignored attack methods to produce a sensational result with which everyone can immediately identify.

See: http://samy.pl/mapxss/

Important point. Better to let everyone see the truth of evercookie than let the bad guys enjoy it in the dark.

Still, with it all packed up so tidily, a few rascals will do something interesting with it.

Also now that it's packed up so tidily, we'll probably get some better tools for blocking/removing all of those tricks. Think of it like an Acid3 test for browser security.

That's a good perspective. It's my fervent hope someone names their tool everenema.

I humbly suggest "Everclear"

"Milk"?

Isn't it trivial to change his script to remove the cookies? I should have a look into that.

Putting IE in private browsing mode defeats it btw, so it's definitely doable.

Oh wow, putting Firefox in private browsing mode did not defeat it. That'll probably get fixed pretty quickly, I hope.

/me tries router xss

>400 Bad Request

Cross Site Action detected!

Sweet :) Though that's vs the vanilla script. Anyone know if there's one that works against DD-WRT?

That MAX thing is not precise at all. Around 600 miles away from my real location.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.