That uses mostly data collected clientside using javascript and flash. HTTP headers alone are no way enough.
82 karma · joined August 27, 2010
[1] http://msdn.microsoft.com/en-us/library/ms533007%28v=vs.85%2...
[1] http://src.chromium.org/chrome/trunk/src/net/cookies/cookie_... search for kMaxCookies
Wouldn't this just make dictionary attacks easier? Now the hacker doesn't have to find one exact password but has the option to match any of his dictionary passwords to any of the password hashes.
I know that there are hardly any collisions and that in practise this wouldn't really change a thing. But in theory the dictionary attack would be faster this way.
.someIcon {
padding: 0 0 0 20px;
background: url(someIcon.png) left center no-repeat;
}1: http://googleblog.blogspot.com/2010/05/android-froyo-with-so...