[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: Flash Cookies and Tor.
- To: or-talk@xxxxxxxxxxxxx
- Subject: Re: Flash Cookies and Tor.
- From: coderman <coderman@xxxxxxxxx>
- Date: Thu, 29 Jul 2010 17:34:05 -0700
- Delivered-to: archiver@xxxxxxxx
- Delivered-to: or-talk-outgoing@xxxxxxxx
- Delivered-to: or-talk@xxxxxxxx
- Delivery-date: Thu, 29 Jul 2010 20:34:13 -0400
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:in-reply-to :references:date:message-id:subject:from:to:content-type; bh=xWVMEOxmmLVOpHr2deYAcdT0X8E481zmkkTbmKijDbw=; b=Jn5li6pq2pfY8MxsvMpAUVVNI6UiAdwpTrLfEyrZz+5T3LH4P3wLE/8SMwg82pdz4R PdB1KI9zOHW//gOhAPToX23ByFH0GiKo+EghowtsdmZ134uVmzYhjjNe3cti3ynScuSy hKyRFvn/nFox8yJIWdiU9I8oJz/Vpo4nkuZRk=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; b=nHAfCivjRYWjkBAQT6wwkMVmCs7K4v8fjaoyEAbQYoa8f53qJlWgD7lbXH85jfC7Uj r3wLz4O3iO+2YLjxsjujduLczHE/3WVvxcMbHx/49TaK5v67z0tEfpc0x2m26+RwRpZH uSHSHCZ6zt4KHy/Ee8jNMytZ8bK5a+BQHQMko=
- In-reply-to: <4C51EFED.3030001@xxxxxxxxx>
- References: <4C51EFED.3030001@xxxxxxxxx>
- Reply-to: or-talk@xxxxxxxxxxxxx
- Sender: owner-or-talk@xxxxxxxxxxxxx
On Thu, Jul 29, 2010 at 2:17 PM, Matthew <pumpkin@xxxxxxxxx> wrote:
> ...
> When I use Tor, I disable Flash.
good!
> However, when not using Tor, sometimes I do use Flash.
we all have our vices...
> I was surprised today to discover in my .macromedia folder on Ubuntu dozens
> of flash cookies.
this will quit surprising you as you begin paying attention.
> Can these cookies have connected my static non-Tor IP and the various Tor
> IPs... can the flash cookie connect to the website even when flash is turned
> off?
nope, as long as you NEVER, EVER, NOT EVEN ONCE have Flash enabled
while using Tor. or anything with privs (extensions, other plug-ins)
that have access to the local store, or other situations where remote
disclosure of local file content may occur.
an easier consideration, are you consistent about always using a
recent and signature verified release of the browser bundle?
best regards,
***********************************************************************
To unsubscribe, send an e-mail to majordomo@xxxxxxxxxxxxxx with
unsubscribe or-talk in the body. http://archives.seul.org/or/talk/