Flash Cookies
James Firth
ukcrypto at chiark.greenend.org.uk
Mon, 9 Jun 2008 19:25:47 +0100
I've not seen much posted recently on this topic:
How Flash Cookies Threaten Your Privacy
http://tips.webdesign10.com/flash-cookies-privacy
It's a little known fact that Flash has cookie-like "terminal equipment"
storage. Obviously this falls under PECR but how many website owners are
aware of how their flash developers work, or indeed what third-party content
(i.e. adverts) embedded in their site work. I'm not sure what the public
knowledge of this is likely to be, or how security software currently
handles this.
It's worth noting that this is not just limited to Flash. Any third-party
browser plug-in could and often does implement storage that could be used to
facilitate cross-domain transfer of information.
James Firth