[LINK] Another Form of Super-Cookie Exposed

Martin Barry marty at supine.com
Sun Jul 31 05:08:47 AEST 2011


$quoted_author = "Roger Clarke" ;
> 
> "The stuff works even if you have all cookies blocked and 
> private-browsing mode enabled," Soltani said. "The code itself is 
> pretty damning."

I'm off to read the article because my understanding was that the various
"private browsing" modes turned off caching.¹ Hence it's not clear to me how
the KISSmetrics method works in that scenario unless the period tracked is
during the same "private browsing" session.

 
> t.js is the same for all people who visit a specific site. (t.js is 
> unique to each KISSmetrics customer)  [I appears that the second 
> 't.js' should be 'i.js'.]

I think that they are supposed to be both t.js as the bit in brackets is
just clarifying that KISSmetrics uses one per customer but all visitors to
that customer's site receive the same t.js
 
cheers
Marty

¹ http://crypto.stanford.edu/~dabo/pubs/abstracts/privatebrowsing.html
  Page 7 of the PDF 



More information about the Link mailing list