|
Where's my cookie?
|
|
Dec. 18, 2008, 05:33 PM
Post: #30
|
|||
|
|||
RE: Where's my cookie?
(Dec. 18, 2008 03:54 AM)Oddysey Wrote: The way I read RFC2965 is that session cookies may be non-cached (as you say, in memory only), but that's not a requirement. Indeed, the spec does recommend that the UserAgent cache all state-tracking mechanisms (IOW, cookies), unless there is a security issue (multiple users of a machine, for instance).RFC2965 describes the Set-Cookie2: header, different than the more commonly used Set-Cookie: without the '2'. A browser storing long-term values from Set-Cookie: is dictated by the "expires=" date attribute. A browser storing long-term values from Set-Cookie2: is dictated by the "Max-Age=" attribute, and it might optionally also contain "expires=". See section 3.3 of that RFC2965. It specifically states that if there is no Max-Age specified in the Set-Cookie2: header then "The default behavior is to discard the cookie when the user agent exits." I don't know what Proxo does or doesn't do for those headers to avoid long-term tracking via cookies. What my proxy normally does for those headers is: 1) Strip out the "expires=" attribute when its specified date is in the future (setting an old expires date is the method by a server telling a browser to delete a cookie, as commonly happens when logging Out of a site). 2) Strip out the "Max-Age=" attribute when its specified value is not zero (setting zero is the method by a server telling a browser to delete a cookie). Beyond those headers, there's also javascript methods that can assign & manipulate browser cookies. (Dec. 18, 2008 03:54 AM)Oddysey Wrote: And to put the final nail in the coffin, if session cookies were held only in memory, then ProxRocks' faked cookies would never be read at all.Those faked cookies are being added by Proxo, they are not coming from a browser's storage. |
|||
|
« Next Oldest | Next Newest »
|
| Messages In This Thread |
|
Where's my cookie? - Oddysey - Oct. 08, 2008, 07:47 AM
RE: Where's my cookie? - Ralph - Oct. 08, 2008, 11:40 PM
RE: Where's my cookie? - Oddysey - Oct. 28, 2008, 04:10 AM
RE: Where's my cookie? - ProxRocks - Oct. 28, 2008, 09:47 AM
RE: Where's my cookie? - z12 - Oct. 28, 2008, 11:56 AM
RE: Where's my cookie? - lnminente - Oct. 28, 2008, 01:23 PM
RE: Where's my cookie? - Oddysey - Oct. 28, 2008, 04:59 PM
RE: Where's my cookie? - ProxRocks - Oct. 28, 2008, 06:05 PM
RE: Where's my cookie? - lnminente - Oct. 28, 2008, 06:47 PM
RE: Where's my cookie? - Oddysey - Oct. 29, 2008, 05:01 AM
RE: Where's my cookie? - ProxRocks - Oct. 29, 2008, 11:55 AM
RE: Where's my cookie? - lnminente - Oct. 29, 2008, 01:12 PM
RE: Where's my cookie? - Oddysey - Oct. 30, 2008, 04:30 AM
RE: Where's my cookie? - ProxRocks - Oct. 30, 2008, 01:52 PM
RE: Where's my cookie? - Oddysey - Oct. 31, 2008, 08:16 AM
RE: Where's my cookie? - ProxRocks - Nov. 01, 2008, 04:15 PM
RE: Where's my cookie? - Oddysey - Nov. 01, 2008, 05:01 PM
RE: Where's my cookie? - ProxRocks - Nov. 01, 2008, 06:59 PM
RE: Where's my cookie? - Oddysey - Dec. 14, 2008, 08:05 PM
RE: Where's my cookie? - lnminente - Dec. 14, 2008, 08:48 PM
RE: Where's my cookie? - ProxRocks - Dec. 14, 2008, 09:01 PM
RE: Where's my cookie? - Oddysey - Dec. 15, 2008, 06:05 AM
RE: Where's my cookie? - lnminente - Dec. 18, 2008, 01:10 PM
RE: Where's my cookie? - ProxRocks - Dec. 15, 2008, 11:10 AM
RE: Where's my cookie? - Graycode - Dec. 15, 2008, 04:22 PM
RE: Where's my cookie? - ProxRocks - Dec. 15, 2008, 05:20 PM
RE: Where's my cookie? - Oddysey - Dec. 18, 2008, 03:54 AM
RE: Where's my cookie? - Graycode - Dec. 18, 2008 05:33 PM
RE: Where's my cookie? - ProxRocks - Dec. 18, 2008, 12:39 PM
RE: Where's my cookie? - ProxRocks - Dec. 18, 2008, 02:14 PM
RE: Where's my cookie? - Oddysey - Dec. 19, 2008, 01:16 AM
RE: Where's my cookie? - Graycode - Dec. 19, 2008, 05:42 PM
RE: Where's my cookie? - Mele20 - Dec. 19, 2008, 02:10 AM
RE: Where's my cookie? - Siamesecat - Dec. 19, 2008, 06:35 AM
RE: Where's my cookie? - Oddysey - Dec. 20, 2008, 05:39 AM
RE: Where's my cookie? - Siamesecat - Dec. 20, 2008, 06:38 AM
RE: Where's my cookie? - Mele20 - Dec. 20, 2008, 07:43 AM
RE: Where's my cookie? - Kye-U - Dec. 20, 2008, 06:57 PM
RE: Where's my cookie? - Oddysey - Dec. 21, 2008, 05:47 AM
RE: Where's my cookie? - Siamesecat - Dec. 23, 2008, 06:05 AM
RE: Where's my cookie? - ProxRocks - Dec. 21, 2008, 01:05 PM
RE: Where's my cookie? - Oddysey - Dec. 22, 2008, 04:15 AM
RE: Where's my cookie? - lnminente - Dec. 22, 2008, 05:57 PM
I FOUND MY COOKIE..... sorta - Oddysey - Dec. 23, 2008, 10:12 PM
RE: Where's my cookie? - whenever - Jan. 05, 2009, 02:13 AM
RE: Where's my cookie? - Oddysey - Jan. 05, 2009, 05:49 AM
|

Search
Member List
Calendar
Help





![[-]](images/ONi/collapse.gif)