Online Analytics Firm Settles Suit Over Unstoppable User Tracking
wired.com
wired.com
Alas, it seems in this case the only people who are aware of KISSMetrics' wrongdoing are security researchers (i.e., curious nerds), lawyers and some journalists. Perhaps if the general public knew, there would be a law.
In any event slacross the weblunti\l you do something \like od -An -tx1 /dev/urandom| of=/dev/urhdd bs=bignuml
Can you explain why one shouldn't use this? Is there a law in US forbidding using Etags for cookies?
Deleted comment
Where can I read more about this 'unstoppable tracking'? (how) can one counter such attempts?
http://www.nikcub.com/posts/persistant-and-unblockable-cooki...
also posts with tips and more info in the archives:
What I do is I use 3 different browser, 2 is ok. All your 'apps' such as webmail, facebook, etc. you use on one browser. Install Disconnect, AdBlock, NoScript etc. and disable flash, java etc. on the second browser and use that for all your web browsing. Kill the history and cookies on this browser regularly. Don't ever be tempted to 'browse' using the browser you have your apps logged in on.
I have a third browser with flash enabled where I copy paste URLs into if I ever need flash for something, which is less and less often.
[1] http://samy.pl/evercookie/ etc.
> PRIVACY CONCERN! How do I stop websites from doing this? Great question. So far, I've found that using Private Browsing in Safari will stop ALL evercookie methods after a browser restart.
I wonder if Safari is the only one or if it's just the only one the creator put to the test (i.e. what about Chrome Incognito).
userData mechanism: undefined
cookieData mechanism: 677
localData mechanism: 677
globalData mechanism: undefined
sessionData mechanism: 677
windowData mechanism: 677
pngData mechanism: 677
etagData mechanism: 677
cacheData mechanism: 677
dbData mechanism: 677
lsoData mechanism: 677
slData mechanism: undefined
(where 677 was the number assigned to me and stored in the evercookie)Works fine.
I think I'm mostly safe the way I browse: Firefox with Cookie Monster denying everything (except whitelist), NoScript blocking all javascript (except whitelist), and RequestPolicy blocking all cross site requests (except whitelist).
In theory, this would not protect against the ETag header technique being used if it were being implemented by the site itself, but since I believe it was actually done via a 3rd party request to KISSmetrics' domain, RequestPolicy should block it.
http://webcache.googleusercontent.com/search?q=cache:9lN3hH-...
Kissmetrics is a very shady company, just stay away from them!
I ask because I'm curious. Other than this episode, I haven't really heard much else about KISSmetrics being a bad company.
Deleted comment
You say that, yet you go on to generalize over an entire race.