Browser History Sniffing Is Back
An anonymous reader writes "Remember CSS history sniffing? The leak is plugged in all major browsers today, but there is some bad news: in a post to the Full Disclosure mailing list, security researchers have showcased a brand new tool to quickly extract your history by probing the cache, instead. The theory isn't new, but a convincing implementation is."
I use Firefox with NoScript, instructing the browser to clear everything when it closes. I made a NoScript exception and tried the tool, and it failed to detect anything except Lowe's! I have never visited the Lowe's website, and I have never shopped there*!
* Home Depot is where it's at, especially for cheap Mexicans!
I just looked at the Home Depot sale paper, and they've got Mexicans on sale. Buy 1, get 18 free.
You are welcome on my lawn.