For users of Win9x and Internet Explorer

You should be aware that a new ‘exploit’ has been written that allows any of your cookies to be read by any site.

Why this is relevant: most SDMB’ers use cookies for login
and convenience of posting

Info:
Details (as they emerge) and ‘why you should care’ is available at:
http://www.peacefire.org/security/iecookies/

Affected:
Internet Explorer (all known versions) for Windows 95, 98 and NT. IE for the Macintosh and IE for UNIX do not appear to be affected, and *no version of Netscape Navigator or any other browser is vulnerable. *

Workaround:
Until MS releases a patch, disable JavaScript. Apparently when the browser loads one of these “funny” URL’s and makes the cookie available only to JavaScript code on the page; it is not available to the host site. However, a javascript routine can send it to a host site

Irony:
This is yet another of the many ‘joys’ of having an application ‘deeply integrated’ into an Operating system.

I don’t hate MS. I use their stuff almost every day. I also use several other operating systems, open and closed source.

On the subject of internet privacy and blocking those that are trying to track you: I have found a nifty free program that will effectively block tracking networks and lets you know who is trying to track you.

It’s called Idecide, and can be found at www.idcide.com if anyone is interested. It is a plug-in to your browser, just adds a little icon up in the right-hand corner.

A site tracker is a cookie placed in your browser that follows you around the site you are on, to track your interests. For those that care, the SDMB is showing as having a site-tracker on my new little program. I don’t mind that so much as I mind the tracking networks.

Tracking networks (like doubleclick) cooperate with many sites and profile you invisibly as you cruise sites on the net. This data about you is compiled and sold as a marketing tool. FYI, there is a tracking network being blocked by my nifty new program right now on the SDMB as I type this. So now I can cruise the net, and not be followed by info gatherers.