Risk
2/1/2011
07:22 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Usage Of Flash To Recreate Deleted Cookies Minimal

But research suggests regulation may be needed to deal with that companies that track Internet users in contravention of privacy controls.

The good news is that zombie cookies -- deleted HTTP cookies that have been resurrected through Adobe Flash Local Shared Objects (LSOs) -- are rare.

The bad news is that lack of visibility into Internet marketers' tracking practices makes self-regulation a dubious strategy for averting potential privacy problems.

A study published on Monday by Carnegie Mellon researchers Aleecia M. McDonald and Lorrie Faith Cranor, "A Survey of the Use of Adobe Flash Local Shared Objects to Respawn HTTP Cookies," has found that misuse of Adobe's Flash technology to rebuild deleted HTTP cookies isn't as widespread as some have feared.

LSOs are Flash's version of HTTP cookies. Few computer users are familiar with them but they present even greater potential for privacy problems because they can be read from any browser, because they're don't expire, and because they can store more data and more complex data types than HTTP cookies.

Because they can be uniquely identified, LSOs present similar privacy problems to cookies while being less affected by user choice. As the study explains, marketers turned to LSOs to address the data quality problems created by the deletion of cookies by Internet users. But doing so flouts users' expressed desire for privacy.

The researchers found no evidence of cookie respawning at 500 randomly selected Web sites and only two instances of resurrected cookies at the 100 most popular Web sites. They also found that LSOs were being used as unique identifiers at 9% of the most popular 100 Web sites and at 3.4% of the 500 randomly selected Web sites.

"We found respawning is currently rare but sites still use LSOs as persistent identifiers..., which may or may not have privacy implications...," the study states.

The researchers suggest that Adobe should take a more proactive role in making it clear that LSOs should not be used to uniquely identify computers and in providing developers with strong privacy guidance and tools. The researchers claim that just over 40% of sites save LSO data, which they interpret as a sign that Flash developers may not understand the privacy implications of LSOs.

They also express skepticism about the ongoing viability of self-regulation. "It is difficult to find calls for a purely industry self-regulation approach to Internet privacy credible when industry demonstrates willingness to violate user intent and privacy as demonstrated by using LSOs to respawn HTTP cookies or individually identify computers," they state.

With the Federal Trade Commission mulling privacy rules after years of hands-off policy, not to mention a slew of recent lawsuits over alleged privacy violations related to tracking, the era of lightly regulated online marketing may be coming to an end.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5312
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

CVE-2012-6662
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

CVE-2014-1424
Published: 2014-11-24
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

CVE-2014-7817
Published: 2014-11-24
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

CVE-2014-7821
Published: 2014-11-24
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?