Imagine I wanted to do this but not be get caught. What would you improve? Clearly the cookies will need to look different pre and post logout, but how different?
Imagine I wanted to do this but not be get caught. What would you improve? Clearly the cookies will need to look different pre and post logout, but how different?
A major faux pas like leaving your uid in the clear in the cookie after logout certainly seems to bother us, but I don't think users (even savvy users) care about leaving some cookies behind. For the record, I've installed various opt-out browser extensions in the past (only to switch computers/browsers and forget to bring them along)--I don't think my views are pro-cookie or even moderate.
In most contexts, that is true. A Slashdot cookie is just a line in a text file until you visit Slashdot. But a Facebook cookie is sent home every time you visit a page with any FB spam on it.
The mysql.com malware is trivial. Hitting Facebook would get most everyone, users and not.