The Cookie Monster ( a privacy hole )
Posted by jdavid
Back in 1994 there was a problem with the internet, how could you track state from one page to the next. When the internet was invented privacy and network simplicity were such concerns that browsers were unable to track who you were from page to page, link to link. Everything was stateless and documents were provided for the free to everyone on the internet. It was a free anonymous society.
However, something changed in 1994, an engineer at Netscape needed a way to make e-commerce possible. The idea was to create a virtual shopping cart, but for the site to track one user from page to page, product to product, they had to create a unique token that would stay with you as you browsed the website.
When the cookie was first released on the web, it was done with great caution, and in many cases you need to approve each cookie, and the default was for the cookie to erase itself after you had left the site or closed your browser. People were afraid that they would loose to much of their privacy if sites could just track you anywhere on the web.
Today, however cookies are not just used for e-commerce, they are used to identify us personally on the web. Google uses it to help web site owners understand who is visiting the owner's site. Sites like twitter, myspace, and facebook use cookies to determine if you are logged in, and in some cases auto personalize the visiting site when you arrive. Nice features like these can be great however there is a cost. If the site owner places the facebook javascript on their page, not only does the browser call up the facebook cookie, but it also passed the address of the referring site back to facebook. So, in this case facebook knows which site you visited, and any data in the url. ( lucky for us that if the URL is https, and you click an http link, your referring address is not sent to the new server. )
However, there is a growing problem with this. Javascript files send the cookie, and it can be used to track which sites you visit and to report this back to a central site, even when you are not logged in. Cookies are a way to track logins and shopping carts, but they can be used at anytime, and most browsers auto accept cookies these days. On many sites, there will be a persistent cookie, and a logged in cookie, and those sites can then track you even when you are not logged in. In fact they can correlate the data between the two cookies pretty easily.
Having these remote login site was great when politics were to ignorant to use it, but recently the US government has become more sophisticated and has subpoenaed twitter for their access logs, which might carry with it every other site you have visited in the last year. The worst part is that this data, which once was private is now being subpoenaed without your permission or notification. Our government feels that average citizens do not have the right to know when they are being watched online.
If you don't believe that governments should not be allowed to track every web search you do or every behavior you perform on the web, for this reason that I am asking you all to turn off cookies. This will be hard, but it's an act of protest. Turning off cookies will effect the revenue of Google and Facebook as they seed to profit off this data to provide ever more targeted ads. And for the most part I really do prefer more targeted ads. I however do not agree with privacy being eroded by our government. Our government fundamentally should not be able to act on this data.
If you can't bring yourself to completely disable cookies, you can set up your browser to dispose of them more often, however sites could still correlate this data over time; and our government can still subpoena this data without your permission or knowledge. I strongly feel like this is a gross challenge to the principles of the 4th amendment.
We need a free society so that everyone's views are valued and discussed in the open. Support freedom, disable cookies.
#NUD National UnFriend Day
Posted by jdavid
I have been using Jimmy Kimmel's announcement of #NUD or National Unfriend Day as a reason to clean up my social connections.
So far I have been clearing myself off of old Meetup Groups, Google Groups, Yahoo Groups. I have also been removing old apps from my Facebook, Twitter, and MySpace apps. It's good to to do a bit of social fall cleaning. Not only have I been removing my self from these email lists, groups and other things, but I have been unsubscribing form newsletters that I don't read any more. It's great. I think I now get about 20 less emails a day that were otherwise not spam, but I had no continued interest in, and it was blocking my communication with the people and topics I care about.
I recommend for you to take action and to pair down who you spend your attention on. ( in a few cases, I actually friended a few new people, when I discovered they were now married )
My blog here is no exception and I found that I have 444 subscribers, and most of them are some form of bots ( an interesting number in Asian cultures http://en.wikipedia.org/wiki/Tetraphobia ) I would like to apologize if I am deleting a valued reader, but if you are real and have something to tell me, please tweet me @jdavid, or just re-register. ( I think there are only a handful of humans that have registered here on my blog. maybe everyone else was afraid of the bot-apocolypse, so like a good John Conner I am clearing out the junk. )
I have added a few tools to make it harder for bots to register, and to track user activity on my blog. I am hoping that I can start fresh with users that are per-capita more human.
Pages
Categories
Blogroll
Archive
- October 2012
- September 2012
- June 2012
- May 2012
- January 2012
- November 2011
- September 2011
- July 2011
- June 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- November 2009
- October 2009
- September 2009
- August 2009
- June 2009