IdeaConnection.com 
Access Teams of Expert Solvers led by World-Class Facilitators
Login | Register
Search Solutions:

Insecure cookies

Post a Problem
The recording of information about specific Internet activities has become one of the biggest emerging threats to Internet privacy. Every time a user accesses a web page, the server holding the page logs the user's Internet address along with the time and date. Some sites place "cookies" on a users machine to help track people's activities at a much more detailed level. Others ask for the users name, address and other personal details before allowing access. Internet purchases are similarly recorded. On-line stores value such data very highly, not least for the potential to sell the data on to marketers and other organizations. Some technical solutions have been devised to counter such activities. "Anonymizing" software allows users to browse the Web without revealing their Internet address. "Cookie cutter" programs stop sites from putting cookies on a users machine, and are now built into most browsers. Anonymous digital cash lets consumers make payments without revealing their identity

The US Environmental Protection Agency (EPA), having made efforts to put a large amount of information on its web site, asserts in its online privacy notice that "Cookies are not enabled on this site and no information is collected to personally identify you." However, EPA's Environmental Data Registry web site was designed to set cookies on users' hard drives. Of greater concern is EPA's Terminology Reference System. Currently, this site will not only set cookies but its data download option requires users to provide their name, organization, email address, and phone number. If a user does not fill in a blank, it will not download the information. EPA's policy is clear. Other than collecting an email address to respond to a direct request, no personally-identifiable information is collected

A cookie should be an "opaque token"; an apparently meaningless string of characters, which only has meaning to the entity which created it. Instead many companies are they storing customer names and private email addresses from an e-commerce transaction, as "plain text" in cookies and sending it out without any security whatsoever

"Cookies" are small pieces of software that identify a computer to another computer, typically an Internet server. A cookie is sent by the server at the time of first contact and subsequently enables the server to recognize that computer on each return visit. Cookies are a matter of convenience, but some people do not like them on privacy grounds

Digital certificates are like smart cookies. They have to be signed up for. They do more than identify a computer -- they verify the person's identity and thus his/her credit rating, address, etc. They are intended to be a secure proof of identity, saving you time and possibly trouble. Credit card information may be required for verification


[JOIN] a group of volunteers working collaboratively on developing innovative solutions to this problem. The team's solution(s) will be published here.
23 38
Vote UpVote Down

Known Solutions

for Insecure cookies



Removing Cookies

Create a Windows Service that runs a delete *.* on the cookie folder at specified time intervals as required. Put the windows service on your standard build when rolling machines out. If specific ...

Delete your cookies out of the computer every week

Many web pages will load cookies into your browser. Pending on your internet activitity alot of personal information can be stored in those cookies. It's a good idea to clear out your browser and cook...

Encrypt the complete session by routing though VPN Tunnel

There are various methods to insure your private information isn’t attacked because of insecure cookies, but the only way to have full protection is to encrypt the complete session while on-line. If...

Innovative Solutions

for Insecure cookies




Comments

on Insecure cookies

Post Comment
A digital certificate is not like a cookie, they come from an entirely different aspect of computer science. A cookie is just a little tag (id, value pair) stored on your computer from a web server....
- Doug Cowie

[READ ALL COMMENTS]

Notify me of New Entries on this Page

Receive an email whenever a new solution or comment is added to this problem.
You can unsubscribe at any time.
Enter your Email:

Become a Problem Solver

Help solve problems for pay or for the Common Good. Use your expertise to help companies solve problems and get paid for every accepted solution. Or volunteer to work on solving problems for the Common Good. [REGISTER]

Volunteer to be a Moderator

If you are a regular contributor and are passionate about one or more topics, IdeaConnection is interested in talking to you about becoming a moderator. Please [REGISTER] as a member and [EMAIL US] your interest.

Solution Seekers: Risk-Free Problem Solving

IdeaConnection.com has thousands of expert, experienced Problem Solvers who can work collaboratively on new and innovative solutions to this problem. Risk-free: you pay only for satisfactory results. Hire a [TEAM OF EXPERTS]



Become a
Paid Problem Solver

Sign up for
our free weekly
Innovation Newsletter

© 2007-2012 IdeaConnection Ltd. All rights reserved.