TechRepublic : A ZDNet Tech Community

IT Security

Host: Chad Perrin
Contact

Flash cookies: What's new with online privacy

If you thought refusing HTTP cookies prevented tracking, think again. Web site developers have found a way.

——————————————————————————————————————-

Web site hosts and advertisers do not like relying on HTTP cookies. Users have figured out how to avoid them. According to Bruce Schneier, Web site developers now have a better way. It’s still considered a cookie, yet it’s different.

LSO, a bigger better cookie

Local Shared Object (LSO) or Flash cookie, like the HTTP cookie, is a way of storing information about us and tracking our movement around the Internet. Some other things I learned:

  • Flash cookies can hold a lot more data, up to 100 Kilobytes. A standard HTTP cookie is only 4 Kilobytes.
  • Flash cookies have no expiration date by default.
  • Flash cookies are stored in different locations, making them difficult to find.

YouTube test

LSOs are also hard to get rid of. Here is a test proving that. Go to YouTube, open a video, and change the volume. Delete all cookies and close the Web browser. Reopen the Web browser and play the same video. Notice that the volume did not return to the default setting. Thank a Flash cookie for that.

Not many know about Flash cookies and that is a problem. It puts people who configure their Web browser to control cookies under a false sense of security. As shown earlier, privacy controls have no effect on Flash cookies.

Where are they stored

Flash cookies use the extension .sol. Knowing that, I still wasn’t able to find any on my computer. Thanks to Google (uses Flash cookies), I determined the only way you can access information about resident Flash cookies is by going to Flash Player’s Web site.

The following slide is from the Flash Player Web site and shows my storage settings. The visited Web sites (total of 200) shown in this tab all have deposited Flash cookies on my computer. This tab is also where the Flash cookies can be deleted, if so desired.

Flash cookies are rampant

Another Google search brought me to a report by University of California, Berkeley researchers. Flash Cookies and Privacy describes what the researchers found after capturing Flash cookie data from the top 100 Web sites. Here are the results:

  • Encountered Flash cookies on 54 of the top 100 sites.
  • These 54 sites set a total of 157 Flash shared objects files yielding a total of 281 individual Flash cookies.
  • Ninety-eight of the top 100 sites set HTTP cookies. These 98 sites set a total of 3,602 HTTP cookies.
  • Thirty-one of these sites carried a TRUSTe Privacy Seal. Of these 31, 14 were employing Flash cookies.
  • Of the top 100 Web sites only four mentioned the use of Flash as a tracking mechanism.

It appears many Web sites use both HTTP and Flash cookies. That surprised/confused the researchers. After more digging they found the answer, respawning.

Flash cookie respawning

UC Berkeley researchers determined that HTTP cookies deleted by closing the browser session were rewritten (respawned) using information from the Flash cookie:

“We found HTTP cookie respawning on several sites. On About.com, a SpecificClick Flash cookie respawned a deleted SpecificClick HTTP cookie. Similarly, on Hulu.com, a QuantCast Flash cookie respawned a deleted QuantCast HTTP cookie.”

The researchers also found Flash cookies were able to restore HTTP cookies for more than one Web-site domain:

“We also found HTTP cookie respawning across domains. For instance, a third-party ClearSpring Flash cookie respawned a matching Answers.com HTTP cookie. ClearSpring also respawned HTTP cookies served directly by Aol.com and Mapquest.com.”

It gets better

Awhile ago, I wrote a piece about how Google started using behavioral targeting (BT) after originally saying they wouldn’t. In that article, I mentioned the Network Advertising Initiative (NAI). A consortium of approximately 30 companies that use BT technology. Bowing to pressure, the group created an opt-out page making it simple to prevent tracking.

The researchers found that setting the opt-out cookie wasn’t enough. Web sites belonging to the NAI created Flash cookies anyway. The report refers to one specific incident:

“We found that persistent Flash cookies were still used when the NAI opt-out cookie for QuantCast was set. Upon deletion of cookies, the Flash cookie still allowed a respawn of the QuantCast HTML cookie. It did not respawn the opt-out cookie. Thus, user tracking is still present after individuals opt out.”

Some solutions

To prevent Flash cookies from being stored, switch to the Global Storage Settings tab in the Setting Manager and remove the check for “Allow third-party Flash content to store data on your computer” as shown in the following slide:

That is supposed to prevent Flash cookies from being installed. Ironically, we have to take the word of the Flash Web site.

For the tests, researchers used Mozilla Firefox. In the report, they mentioned BetterPrivacy, a Firefox add-on that removes all flash cookies when the Web browser is closed. Another Firefox add-on Ghostery raises alerts about any hidden scripts that track Web presence.

Final thoughts

I thought we were past unannounced tracking of our movements on the Internet. If the technology is so innocent, make tracking an opt-in feature.


Michael KassnerMichael Kassner has been involved with with IT for over 30 years. Currently a systems administrator for an international corporation and security consultant with MKassner Net. Read his profile or Twitter at MKassnerNet.

Print/View all Posts Comments on this blog

Tracking your Internet experience is alive and well Michael Kassner | 09/08/09
Thank You cliff@... | 09/08/09
You are welcome, Cliff Michael Kassner | 09/08/09
Not really browser behavior - but web page behavior cliff@... | 09/08/09
You may Michael Kassner | 09/08/09
True story thamadgreek@... | 09/08/09
Those are Michael Kassner | 09/08/09
I have the gun, I make the rules... JasonKB | 09/08/09
Who's worse... ultimitloozer@... | 09/09/09
At least you know what the criminals want... JasonKB | 09/09/09
I have the gun, I make the rules JasonKB | 09/08/09
The nebulous part Michael Kassner | 09/08/09
Consent and the hidden third parties JasonKB | 09/09/09
Exactly, Jason Michael Kassner | 09/09/09
No, How? JasonKB | 09/10/09
Two opt-out links Michael Kassner | 09/10/09
Wow, cool - Michael!!!... JCitizen | 09/10/09
Michael has a magic box santeewelding | 09/10/09
santeewelding just think of all the tools... JCitizen | 09/10/09
I wish Michael Kassner | 09/11/09
You mean boxfiddler | 09/11/09
Nope Michael Kassner | 09/12/09
Snooze button santeewelding | 09/12/09
Ouch, Rich Michael Kassner | 09/12/09
Pending Legislation (1) ocie3@... | 09/09/09
Pending legislation (2) ocie3@... | 09/09/09
Thank you ocie3!... JCitizen | 09/10/09
There is an exceptional group Michael Kassner | 09/11/09
For sure!!!....(nt) JCitizen | 09/12/09
Thanks Michael scott.ager@... | 09/09/09
Not sure Michael Kassner | 09/09/09
You said it best... Timbo Zimbabwe | 09/09/09
Sandboxie protection ocie3@... | 09/09/09
You may be retired santeewelding | 09/09/09
I so agree Michael Kassner | 09/09/09
Lay off the Scotch santeewelding | 09/09/09
It is hard to learn ocie3@... | 09/09/09
Here, and elswhere santeewelding | 09/09/09
As I yours Michael Kassner | 09/12/09
I'm glad you raised this one Tony Hopkinson | 09/11/09
What browser, Tony? Michael Kassner | 09/11/09
FF and I'll give it a try Tony Hopkinson | 09/11/09
And gasoline santeewelding | 09/11/09
Tony, Do you Michael Kassner | 09/12/09
Don't use it so not a problem Tony Hopkinson | 09/13/09
Where I found my .sol files MartyL | 09/12/09
Good article Michael Kassner | 09/12/09
Did your Windows Search ocie3@... | 09/13/09
Thanks for the tip - now for Linux? danielh_7777@... | 09/12/09
You are very welcome Michael Kassner | 09/12/09
They would have been Jacky Howe | 09/12/09
Thought so Michael Kassner | 09/12/09
Your welcome Jacky Howe | 09/12/09
RE: Flash cookies: What's new with on-line privacy Emil Hugo | 09/08/09
You are welcome, Emil Michael Kassner | 09/08/09
RE: Flash cookies: What's new with on-line privacy rbees | 09/08/09
That is my take Michael Kassner | 09/08/09
Get C-Cleaner to kill Flash cookies? rickclark9@... | 09/08/09
its been suggested already ---TK--- | 09/08/09
Good idea Sensei Humor | 09/08/09
Using Akamai is sensible rather than suspicious GyroGearloose@... | 09/08/09
Need help Michael Kassner | 09/08/09
suspicions against Akamai unwarranted GyroGearloose@... | 09/10/09
Not necessarily suspicious, seanferd | 09/10/09
Need explanation Michael Kassner | 09/11/09
@Michael... JCitizen | 09/12/09
It has for some time, AFAIK. seanferd | 09/08/09
Was that Michael Kassner | 09/08/09
I'm not sure if it was default. seanferd | 09/08/09
Interesting Michael Kassner | 09/08/09
I see Adobe Flash Player ocie3@... | 09/09/09
A favor please Michael Kassner | 09/09/09
RE: Flash cookies: What's new with on-line privacy rhuston@... | 09/08/09
Strange Michael Kassner | 09/08/09
File Location bryantwalley | 09/08/09
You will Michael Kassner | 09/08/09
BetterPrivacy Firefox addon is excellent scott38w@... | 09/08/09
Thanks Scott Michael Kassner | 09/08/09
I just use MBAM... JCitizen | 09/10/09
Why do you think that, Jay Michael Kassner | 09/11/09
MBAM is more thorough... JCitizen | 09/12/09
They all appear to be in roughly the same place... Jessie | 09/08/09
And no... Jessie | 09/08/09
Are you Michael Kassner | 09/08/09
.SOL locations ocie3@... | 09/09/09
Flash Cookies in PCLOS 07 running FF 2.0.0 Betelgeuse58 | 09/09/09
Thanks for sharing the info. ocie3@... | 09/09/09
I recommend it Michael Kassner | 09/09/09
You are quite welcome. Betelgeuse58 | 09/10/09
Looks like that is the way to go... JCitizen | 09/10/09
If you do Michael Kassner | 09/11/09
Why do vendors continue to do this? Craig_B | 09/08/09
Exactly Michael Kassner | 09/08/09
"We're from the Gov't, we're here to help you" Sensei Humor | 09/08/09
Stalking is stalking hlhowell@... | 09/08/09
Except a few... Jessie | 09/08/09
Have to prove intent Michael Kassner | 09/08/09
Not just advertisers ultimitloozer@... | 09/09/09
The problem Michael Kassner | 09/08/09
First time for everything... ultimitloozer@... | 09/09/09
Surely you jest.... mudpuppy1 | 09/11/09
Me? Michael Kassner | 09/11/09
Vous... mudpuppy1 | 09/14/09
Great Michael Kassner | 09/14/09
Thanks mudpuppy1 | 09/15/09
Two reasons shardeth | 09/09/09
Good grasp Michael Kassner | 09/10/09
Solution: No Flash dlevine@... | 09/08/09
So you have flash cookies Michael Kassner | 09/08/09
I can't wait till my x64 IE8 browser gets flash... JCitizen | 09/10/09
My. How effusive tonight. santeewelding | 09/10/09
HA! Only the direct method!... JCitizen | 09/10/09
Why?, Jay Michael Kassner | 09/11/09
Oh I love FF too!... JCitizen | 09/12/09
NoScript Firefox Plugin Sensei Humor | 09/08/09
It is good Michael Kassner | 09/08/09
Clarification ocie3@... | 09/09/09
Wow that's a surprise.... Tony Hopkinson | 09/08/09
Hey, Tony Michael Kassner | 09/08/09
2nd that.... ---TK--- | 09/09/09
Web 2.0 equivalent of spook? shardeth | 09/09/09
RE: Bad idea dhs13@... | 09/08/09
That is odd Michael Kassner | 09/08/09
I'd just ignore that... JCitizen | 09/10/09
Good point, Jay Michael Kassner | 09/11/09
Have you used IE Tab? ocie3@... | 09/11/09
Didn't know about that Michael Kassner | 09/12/09
IE tab - works great JasonKB | 09/12/09
Question Michael Kassner | 09/12/09
I thought that was for pages that didn't load?!.. JCitizen | 09/12/09
The embedded IE engine ocie3@... | 09/13/09
Okay, thanks!.. JCitizen | 09/13/09
CCleaner removes them seanferd | 09/08/09
You are welcome, Sean Michael Kassner | 09/08/09
All over hlhowell@... | 09/08/09
I've seen multiple (browser & user dependent) locations. seanferd | 09/08/09
That's with Michael Kassner | 09/08/09
Re: CC & BP seanferd | 09/08/09
Thanks, Sean Michael Kassner | 09/08/09
I just like it, is all. seanferd | 09/09/09
CCleaner cliffcoy@... | 09/08/09
For those found in "alternate locations" seanferd | 09/08/09
Well done Michael Kassner | 09/08/09
I had to look to make sure! seanferd | 09/08/09
Here I go santeewelding | 09/08/09
You may wish to scream some more. seanferd | 09/08/09
I'm late santeewelding | 09/08/09
GMER? seanferd | 09/09/09
GMER rocks! JCitizen | 09/12/09
A lazy IT persones two cents... JCitizen | 09/09/09
All right Michael Kassner | 09/10/09
It was Jaqui... JCitizen | 09/10/09
Where is Jaqui? Michael Kassner | 09/11/09
I don't know!.. JCitizen | 09/12/09
You have the latest version(edited).. JCitizen | 09/10/09
Have you Michael Kassner | 09/11/09
Okay, after running CCleaner they are all empty... JCitizen | 09/12/09
Note santeewelding | 09/12/09
For sure!!.. JCitizen | 09/12/09
RE: Flash cookies: What's new with on-line privacy mgnl@... | 09/08/09
Not sure Michael Kassner | 09/08/09
It's Not just Flash PhilippeV | 09/08/09
Thanks, Philippe Michael Kassner | 09/08/09
RE: Flash cookies: What's new with on-line privacy woodtech1@... | 09/08/09
Favor please Michael Kassner | 09/08/09
Flash Web site vs. CCleaner Patient angler | 09/08/09
Thanks for sharing Michael Kassner | 09/10/09
RE: Flash cookies: Jacky Howe | 09/08/09
Thanks for the test. seanferd | 09/09/09
Your welcome Jacky Howe | 09/09/09
Found Flash cookie with very private data lars.staurset@... | 09/09/09
Wow, thanks Lars Michael Kassner | 09/09/09
Thanks, Lars santeewelding | 09/09/09
I wonder who owns Jacky Howe | 09/09/09
Forgive me, Jacky Michael Kassner | 09/11/09
I was just wondering Jacky Howe | 09/12/09
Yes that looks like some of the same file paths... JCitizen | 09/10/09
Thanks - do updates change the settings? bus66vw@... | 09/09/09
In my experience ocie3@... | 09/09/09
That is Michael Kassner | 09/10/09
Mr. Kassner you've done it again! pgit | 09/09/09
Thank you Pgit Michael Kassner | 09/10/09
Same to yourself... JCitizen | 09/10/09
back at ya... pgit | 09/11/09
Uh... isn't it supposed to be... pandu@... | 09/09/09
If you want Michael Kassner | 09/09/09
According to Adobe... pandu@... | 09/09/09
You are right, ocie3@... | 09/09/09
Did they tell you? Michael Kassner | 09/09/09
The Pandora Privacy Policy ocie3@... | 09/09/09
There was mention though Michael Kassner | 09/10/09
Zero-sized LSO? pandu@... | 09/10/09
Interesting!... JCitizen | 09/10/09
mail.google.com? Michael Kassner | 09/11/09
You need a better File Manager JackOfAllTech | 09/09/09
I guess so Michael Kassner | 09/10/09
EPIC article Craig_B | 09/10/09
Great article, Craig Michael Kassner | 09/10/09
Yeah! Thanks Craig_B!... JCitizen | 09/10/09
Need your help Michael Kassner | 09/11/09
I don't have an answer Jacky Howe | 09/11/09
Great information Michael Kassner | 09/12/09
I have Firefox withOUT Flash and MSIE with mdhealy@... | 09/11/09
You should have flash cookies Michael Kassner | 09/12/09
Getting folders but no *.sol files MartyL | 09/12/09
Me too... JCitizen | 09/12/09
What bothers me the most... NickNielsen | 09/13/09
I'm still in the dark.. JCitizen | 09/13/09
Sort of NickNielsen | 09/13/09
I guess I don't mind... JCitizen | 09/13/09
A lot depends on the type of cookie and what it's set to do Deadly Ernest | 10/10/09
Anything that puts itself there is an exploit Deadly Ernest | 10/10/09
Flash user have full control GyroGearloose@... | 10/11/09
Then why is it the default installation of Flash Player has Deadly Ernest | 10/11/09
Player cookies: where is the risk? GyroGearloose@... | 10/12/09
RE: Flash cookies: What's new with on-line privacy Deadly Ernest | 10/10/09
MAXA Cookie Manager finds them all maxatwo | 01/12/10

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



Quick Reference: Linux Commands
Reduce stress and speed up resolutions with the easiest command references right at your fingertips. You'll receive a PDF file covering Linux, packed with the most common commands you'll need and use daily.
Buy Now
500 Things Every Technology Professional Needs to Know
Did you know Microsoft's RegClean does not work with XP but you can use shareware to clean your registry? Did you know most wireless access points don't have encryption enabled by default? Did you know there are 500 tidbits of information contained in TechRepublic's 500 Things Every Technology Professional Needs to Know that will help you become a successful IT professional.
Buy Now

SmartPlanet

Click Here