Understanding cookies and cookie pools

Post on 22-Feb-2017

186 views 1 download

Transcript of Understanding cookies and cookie pools

aka your web identity

VIJAY SANKAR

• A piece of information generated by a web server and stored in the user's computer, ready for future access

• Usage

Shopping carts

Login sessions

Online advertising

User experience

VS

Just a sample…

VS

VS

based on purpose

VS

https://spring.io/blog/2014/01/20/exploiting-encrypted-cookies-for-fun-and-profit

Persistent &

Plain Text

Session &

Plain Text

Persistent &

Encrypted

Session &

Encrypted

VS

VS

First Party

Third Party

VS

Super Cookies

Zombies

VS

Video - https://www.youtube.com/watch?v=I01XMRo2ESg

VS

VS

aka your true web identity

Web Beacons

1 X 1 Pixels

Invisible GIFs

Clear GIFs

VS

COOKIES – THE FUTURE

VS

Device Inference

Client IDs Network IDs

Server IDsSynchronized

IDs

VS

VS

VS