| − | Servers sometimes use HTTP Strict Transport Security (HSTS) to ensure that uses connect using an encrypted connection for security. If a user tries to connect using an unencrypted protocol (usually HTTP) then HSTS will instruct the browser to connect using a secure connection, instead (HTTPS). This website is then added to the web browser's director of secure websites, so it connects properly in the future. There is nothing specifically wrong with this system--it is a very useful and convenient feature. However, some developers have found a way to abuse this system. They send an HSTS message to the connecting browser, then allow the visitor to connect. The browser, meanwhile, automatically stores an entry for that website as specified by the site itself. From this point on, the browser can be identified by how it connects based on the HSTS entry.<ref>http://www.pcworld.com/article/2865297/super-cookies-can-track-you-even-in-private-browsing-mode-researcher-says.html</ref> This is not a cookie in the strictest sense, but it offers the same functionality--to uniquely identify the user to the website. Removing these "super cookies" is not easy, but can be done. Many browsers offer the option to clear this record of secure websites, so this can be used. However, some other browsers such as [[Safari (web browser)|Safari]] do not. There are also software solutions to help clear these cookies.<ref>http://www.pcworld.com/article/238895/how_to_protect_yourself_from_supercookies.html</ref> | + | Servers sometimes use HTTP Strict Transport Security (HSTS) to ensure that uses connect using an encrypted connection for security. If a user tries to connect using an unencrypted protocol (usually HTTP) then HSTS will instruct the browser to connect using a secure connection, instead (HTTPS). This website is then added to the web browser's director of secure websites, so it connects properly in the future. There is nothing specifically wrong with this system—it is a very useful and convenient feature. However, some developers have found a way to abuse this system. They send an HSTS message to the connecting browser, then allow the visitor to connect. The browser, meanwhile, automatically stores an entry for that website as specified by the site itself. From this point on, the browser can be identified by how it connects based on the HSTS entry.<ref>http://www.pcworld.com/article/2865297/super-cookies-can-track-you-even-in-private-browsing-mode-researcher-says.html</ref> This is not a cookie in the strictest sense, but it offers the same functionality—to uniquely identify the user to the website. Removing these "super cookies" is not easy, but can be done. Many browsers offer the option to clear this record of secure websites, so this can be used. However, some other browsers such as [[Safari (web browser)|Safari]] do not. There are also software solutions to help clear these cookies.<ref>http://www.pcworld.com/article/238895/how_to_protect_yourself_from_supercookies.html</ref> |
| − | Super cookies are considered a risk by many since they are difficult to clear. This enables websites to track many users with impunity, even if they think they are remaining safe by clearing their traditional cookies. A great number of websites also use these without mentioning them, even in their extensive privacy policies. Even the U.S. federal government uses these in many of their websites, since the use of traditional cookies on their websites is banned.<ref name="fightidentitytheft.com">http://www.fightidentitytheft.com/blog/new-breed-super-cookie-defies-removal-almost</ref> This not only violates the spirit of the law, but also gives the government another method by which violate citizens' [[Right to Privacy]]. | + | Super cookies are considered a risk by many since they are difficult to clear. This enables websites to track many users with impunity, even if they think they are remaining safe by clearing their traditional cookies. A great number of websites also use these without mentioning them, even in their extensive privacy policies. Even the U.S. federal government uses these in many of their websites, since the use of traditional cookies on their websites is banned.<ref name="fightidentitytheft.com"/> This not only violates the spirit of the law, but also gives the government another method by which violate citizens' [[Right to Privacy]]. |