public marks

PUBLIC MARKS with search cookies

This month

January 2012

November 2011

Why Johnny Can’t Opt Out: A Usability Evaluation of Tools to Limit Online Behavioral Advertising

by karlcow

We present results of a 45-participant laboratory study investigating the usability of tools to limit online behavioral advertising (OBA).We tested nine tools, including tools that block access to advertising websites, tools that set cookies indicating a user’s preference to opt out of OBA, and privacy tools that are built directly into web browsers. We interviewed participants about OBA, observed their behavior as they installed and used a privacy tool, and recorded their perceptions and attitudes about that tool. We found serious usability flaws in all nine tools we examined. The online opt-out tools were challenging for users to understand and configure. Users tend to be unfamiliar with most advertising companies, and therefore are unable to make meaningful choices. Users liked the fact that the browsers we tested had built-in Do Not Track features, but were wary of whether advertising companies would respect this preference. Users struggled to install and configure blocking lists to make effective use of blocking tools. They often erroneously concluded the tool they were using was blocking OBA when they had not properly configured it to do so.

September 2011

jCookies - Gérez les cookies de vos visiteurs avec jQuery:

by eledo34 (via)
jCookies - Gérez les cookies de vos visiteurs avec jQuery: J is for jCookies - HTTP Cookie Handling for jQuery | Codrops

July 2011

Tracking users that block cookies with a HTTP redirect | From Information to Intelligence

by karlcow

When the redirection occurs the browser will cache the redirect information so the next time the user connect to the tracking page the user will be redirected to the tracking page with his unique id.

June 2011

Charles Web Debugging Proxy • HTTP Monitor / HTTP Proxy / HTTPS & SSL Proxy / Reverse Proxy

by karlcow & 8 others

Charles is an HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP and SSL / HTTPS traffic between their machine and the Internet. This includes requests, responses and the HTTP headers (which contain the cookies and caching information).

daniel.haxx.se » The cookie RFC 6265

by karlcow

We don’t fix any of the many known problems with cookies, but we describe how you write your protocol implementation if you want to interact fine with existing infrastructure.

May 2011

BBC - BBC Internet Blog: How BBC Online will meet changes to UK cookie laws

by karlcow

we're publishing an updated list of the main cookies in use across BBC Online and what each is used for.

April 2011

March 2011

BBC News - New net rules set to make cookies crumble

by karlcow

From 25 May, European laws dictate that "explicit consent" must be gathered from web users who are being tracked via text files called "cookies".

January 2011

PrivacyChoice Opt-out :: Modules pour Firefox

by shadoko
Opt-out of behavioral tracking by 100+ companies, including Google, Microsoft and AOL. Preserve your preferences even when you clear cookies from your browser. Choose individual networks, all networks or networks with policy questions.

Top 5 WordPress Security Tips You Most Likely Don’t Follow

by mozkart (via)
1. Don’t use the admin account – The default user account that is created with every installation of WordPress is the admin account. Unfortunately the entire world knows this, including hackers, and can easily launch a dictionary attack on your website to try and guess your password. If a hacker already knows your username that’s half the battle. It’s highly recommended to delete or change the admin account username. 2. Move your wp-config.php file – Did you know since WordPress 2.6 you can move your wp-config.php file outside of your root WordPress directory? Most users don’t know this and the ones that do don’t do it. To do this simply move your wp-config.php file up one directory from your WordPress root. WordPress will automatically look for your config file there if it can’t find it in your root directory. 3. Change the WordPress table prefix – The WordPress table prefix is wp_ by default. You can change this prior to installing WordPress by changing the $table_prefix value in your wp-config.php file. If a hacker is able to exploit your website using SQL Injection, this will make it harder for them to guess your table names and quite possibly keep them from doing SQL Injection at all. If you want to change the table prefix after you have installed WordPress you can use the WP Security Scan plugin to do so. Make sure you take a good backup before doing this though. 4. Use Secret Keys – This is probably the most followed security tip on the list, but still I’m amazed at how many people don’t do this. A secret key is a hashing salt that is used against your password to make it even stronger. Secret keys are set in your wp-config.php file. Simply visit https://api.wordpress.org/secret-key/1.1 to have a set of randomly generated secret keys created for you. Copy the 4 secret keys to your wp-config.php file and save. You can add/change these keys at any time, the only thing that will happen is all current WordPress cookies will be invalidated and your users will have to log in again. 5. htaccess lockdown – This is actually my favorite tip from my presentation. Using a .htaccess file you can lockdown your wp-admin directory by IP address. This means only IP addresses you specify can access your admin dashboard URLs. This makes it impossible for anyone else to try and hack your WordPress backend. To do this simply create a file called .htaccess and add the following code to your file, replacing xxx.xxx.xxx.xxx with your IP address:

December 2010

Why the Nexus S has NFC – Google Places window stickers are NFC enabled

by karlcow

because the window stickers that come with them feature near field communications (NFC) built right in that includes information about the business on its Places pages (and we’re guessing will allow users to do things such as rate the venue as well).

NFC is the cookies of the physical world.

November 2010

Firecookie :: Add-ons for Firefox

by srcmax

Cookie manager for Firebug. Firebug has to be installed in order to use this extension. Use this extension to create a new cookie, delete existing cookies, see list of cookies for current site, manage cookies permissions and a lot more.

lcamtuf's blog: HTTP cookies, or how not to design protocols

by karlcow & 1 other

All these moves led to a very interesting situation: there is simply no accurate, offcial account of cookie behavior in modern browsers; the two relevant RFCs, often cited by people arguing on the Internet, are completely out of touch with reality.

October 2010

evercookie - virtually irrevocable persistent cookies

by srcmax & 2 others (via)

evercookie is a javascript API available that produces extremely persistent cookies in a browser. Its goal is to identify a client even after they've removed standard cookies, Flash cookies (Local Shared Objects or LSOs), and others.

September 2010

July 2010

Privacy Lawsuit Targets Net Giants Over ‘Zombie’ Cookies | Threat Level | Wired.com

by karlcow

At issue is technology from Quantcast, also targeted in the lawsuit. Quantcast created Flash cookies that track users across the web, and used them to re-create traditional browser cookies that users deleted from their computers.

Active users

gregg
last mark : 05/02/2012 19:20

blackgoldfish
last mark : 30/01/2012 06:16

marco
last mark : 18/01/2012 09:05

karlcow
last mark : 06/11/2011 23:31

eledo34
last mark : 16/09/2011 11:33

groucho
last mark : 22/03/2011 19:30

shadoko
last mark : 29/01/2011 09:27

mozkart
last mark : 19/01/2011 08:19

srcmax
last mark : 23/11/2010 09:13

François Hodierne
last mark : 23/09/2010 09:50

piouPiouM
last mark : 22/09/2010 13:18