IE "Persistence" Tracks Without Warning
A reader writes "Never mind if you've shut off cookies. If you are using IE 5+, the browser can still be used to track you, with no warning. An IE 5+ feature, "persistence", allows the browser to remember information, such as search queries. Which of course means that you can be uniquely identified and tracked. And since it is a feature, there is no warning either that this information is being stored or when it is given. Shutting off scripting in theory stops it.
More on the story at www.news.c om ."
it's good that that works and that it's that simple, but the fact remains that the vast majority of computer users never change the defaults on any of their applications. if something doesn't work quite the way the want it to, they don't bother poking around in the preferences to fix it. my father complains about the recent versions of microsoft word because of those "annoying red and green squiggly lines all over the place." i say "dad, you can get rid of those in two steps." he doesn't bother. with respect to something like this, where you can't even tell that it's happening, i would wager that next to no one (outside of those reading this forum) are going to do anything about it.
Mozilla will never take the market from IE, unless someone starts paying folks to use it. Most people don't give a rat's ass about features/loopholes/etc. like the one described in the story. What percentage of web users browse without using cookies? I don't know the answer to this, but I'd put money on it being a relatively small minority.
I use IE 5.1 and there is an option in the advanced tab called "Enable Page Hit Counting". Here is what the Help says about it (emphasis is mine):
Specifies whether you want Internet Explorer to allow Web sites to track your Web page usage. Selecting this check box allows sites to create a log on your computer of which pages you view, even when you are viewing Web pages offline. That log is sent to the site the next time you go to it. By tracking the usage and popularity of specific Web pages, content providers can tailor future content to match your interests.
Looks like this has been around a while as M$ fishes for the most innocuous name possible.
"I will gladly pay you today, sir, and eat up
Sacred cows make the best burgers.
The capability, described as a "feature" by Microsoft, came to light on the BugTraq mailing list three days ago after an angry user revealed that his copy of IE 5.1 had phoned his wife to tell her about his subscription to hotmonkeylovin.com.
"This is a perfectly standard feature of any web browser," said a Microsoft spokesman. "As with all aspects of life on the internet, there is a tradeoff here between a very valuable capability and a vanishingly small, almost theoretical loss of privacy."
Free Software Foundation guru Richard M. Stallman was unavailable for comment. A source close to the programmer said that Stallman was "busy reformatting his Windows partition."
Carousel is a lie!
MSK
From the article
Hint, the link is there to remind you to read it
Not to rant, but I cannot understand how such specious reasoning would find its way out of the mouth of a Microsoft representative. How could they possibly argue that since users are already at much greater risk from other features/exploits, one more "minor" inconvenience shouldn't matter?
Clearly documented explanations of the security features that one can toggle in the Internet Options -> Security tab would be one thing, but the lack of context-specific, right-click help (try it and see) or even the word persistence in the indexed help file (search and see) is somewhat silly.
Why would I have to journey to the developer's corner (link lifted from article) to learn what features are present in my browser? Maybe it's time that end-users insist on better [more immediate] documentation from Microsoft, especially with regards to things categorized under the heading of security
ps - SlashDot still has its woes when dropping in long URLs. God bless the preview button
I tried to buy some porn the other day at the local bookshop. But guess what - people look at you when you pick it up off the shelf - like everyone in the store! It's worse - when you go and pay you actually have to interact with another human! It's even worse - they remember who you are and the next time you go shopping there and your wife comes along it's very embarassing. I think there must be some kind of multinational corporation conspiracy thing going on with the retailers in cahoots with the publishers in order to track me. Scary stuff.
--
-- SIGFPE
I just looked at IE, and under security settings, it gives you the option of disabling "userdata persistence".
And you don't have to turn off javascript. It's just in the IE Preferences dialog, but it's enabled by default.
To turn it off, do the following in IE:
Click Tools->Internet Options.
Choose the 'Security' tab.
Click the 'Custom level' button
Search for 'Userdata persitence' (it's near the bottom, in the 'Miscellaneous' section)
Select the 'disable' option.
That's it!
Every expression is true, for a given value of 'true'