In the real world of Internet security push and shove, it seems everything has a “season” – a space in the spotlight. For example – each day we are bombarded with the latest, subjectively “most dangerous” – malware threat, cyber criminal operational techniques, application vulnerabilities, or irresponsible enterprise behavior – the latest being the negligent Epsilon data breach. All destined to become “old news” and seemingly irrelevant, within days
Just wait a few days and the Epsilon data breach will no longer be news worthy; it will simple fade away (just as if it never happened) – as have the other 20+ serious data breaches which have occurred in the last 30 days. Data breaches that have impacted governments, educational facilities, major enterprises ……
Test yourself – can you name one other security breach, application vulnerability, or dangerous malware threat, or technique, reported on in the last thirty days?
Internet privacy is a perfect example of this; in favor – out of favor, critical issue – non-critical issue cycle of Internet security push and shove. Lately, Internet privacy has been relegated to the back burner. Sort of like – hey, it’s not a big deal. Besides, there are newer and more exciting issues to report on – Internet privacy is old news!
But here’s the thing – Internet privacy is a substantial issue, and a more critical issue than ever. Developments in tracking technologies and a complete disregard for fundamental privacy rights, should be a major topic of conversation in the security community – until such time as the issue has been resolved in favor of consumers.
In the meantime, we’re on our own. It’s up to us, as individual consumers, to take the appropriate steps to safeguard our privacy (as best we can), while interacting with the Internet.
You can take a step in that direction by increasing your awareness of a significant threat to your privacy – Flash Cookies (also described as (LSO) – Local Shared Objects, and Smart Cookies).
Late last year, I wrote an article “BetterPrivacy Firefox Add-on Kills Flash Cookies”, centered on this stealthy and underhanded privacy threat, which I have now updated. I think you’ll find it’s worth another read.
If you hear something repeated often enough, then that “something” takes on a veneer of truth. It doesn’t necessarily mean that it is true of course – but, it appears to be true. The “truth” regarding Internet site cookies, falls into that category.
Most of us have heard that “truth” – without cookies (and now, Flash cookies), your Web experience would be terrible. You’d be starting from scratch each time you did anything on a given site online. Or, something along that line.
Nonsense! For years, I have deleted cookies at every Browser shut down, and have experienced no perceptible difference in performance when visiting the same 30 or so sites, that I visit every day
Here’s the reality:
Cookies are there for the benefit of advertisers; not the web site visitor – plain and simple. Keep in mind, that it’s critically important to advertisers to generate advertising that is specific to the web site visitor at the time of the visit – not later, but right then. And a cookie is the tool that facilitates this happening.
Luckily, Internet browsers can be set to allow full user control over cookies including accepting, rejecting, or wiping private data which includes wiping cookies. That is, until recently.
It appears that a user’s decision to control cookies, in this way, is simply not acceptable to advertisers and certain web sites, and so, we now have the Flash Cookie (LSO) – Local Shared Objects.
There is a major advantage for an advertiser to employ Flash cookies, not the least of which is; they are virtually unknown to the average user. Equally as important, from an advertisers perspective is; they remain active on a system even after the user has cleared cookies and privacy settings.
This practice of web sites dropping Flash cookies onto your computer, which occurs without your knowledge or permission, according to some in the security community, is akin to hacking. Frankly, I agree.
If you think this practice is restricted to shady web sites, you’d be wrong. Of the top 100 web sites, the majority use Flash Cookies. So, I was not particularly surprised, when I found some of my favorite sites involved in this invasive practice.
I first wrote on the issue of Flash Cookies back in September 2009, and since then, I’ve watched as these obnoxious web trackers and privacy invaders multiply like a virus.
Quick Flash cookie facts:
They never expire
Can store up to 100 KB of information compared to a text cookie’s 4 KB.
Internet browsers are not aware of those cookies.
LSO’s usually cannot be removed by browsers.
Using Flash they can access and store highly specific personal and technical information (system, user name, files,…).
Can send the stored information to the appropriate server, without user’s permission.
Flash applications do not need to be visible.
There is no easy way to tell which flash-cookie sites are tracking you.
Shared folders allow cross-browser tracking – LSO’s work in every flash-enabled application
No user-friendly way to manage LSO’s, in fact it’s incredible cumbersome.
Many domains and tracking companies make extensive use of flash-cookies.
If you value your privacy, then without a doubt you need to control these highly invasive objects, and if you are a Firefox user there is a solution – BetterPrivacy – a free Firefox add-on.
From the BetterPrivacy page:
“Better Privacy serves to protect against not delectable, long-term cookies, a new generation of ‘Super-Cookie’, which silently conquered the internet.
This new cookie generation offers unlimited user tracking to industry and market research. Concerning privacy Flash- and DOM Storage objects are most critical.
This add-on was made to make users aware of those hidden, never expiring objects and to offer an easy way to get rid of them – since browsers are unable to do that for you”.
In the following screen capture (click to expand to original), you’ll notice BetterPrivacy has deleted a cumulative total of 6188 Super Cookies. An amazing number, considering the OS on this machine was freshly installed on March 1, 2011.
The Options and Help tab (shown in the following screen shot), will allow you to choose specific deletion methods. You should consider selecting “Disable Ping Tracking”, which will prohibit sites from following you as you surf the Net.
Download at: Mozilla
Simple HTTP cookies (ordinary cookies), can be subject to attack by cyber criminals, so it won’t be long before flash cookies will be subject to the same manipulation. Better you should learn how to control them now – not later.
Privacy, in all areas of our life is under constant attack, but that shouldn’t mean that we give up. We need to learn to fight back with every tool that’s available.
For a more detailed breakdown on flash cookies, and the danger they represent to personal privacy, checkout The Electronic Privacy Information Center.
If you found this article useful, why not subscribe to this Blog via RSS, or email? It’s easy; just click on this link and you’ll never miss another Tech Thoughts article.