You should be aware that a new ‘exploit’ has been written that allows any of your cookies to be read by any site.
Why this is relevant: most SDMB’ers use cookies for login
and convenience of posting
Info:
Details (as they emerge) and ‘why you should care’ is available at:
http://www.peacefire.org/security/iecookies/
Affected:
Internet Explorer (all known versions) for Windows 95, 98 and NT. IE for the Macintosh and IE for UNIX do not appear to be affected, and *no version of Netscape Navigator or any other browser is vulnerable. *
Workaround:
Until MS releases a patch, disable JavaScript. Apparently when the browser loads one of these “funny” URL’s and makes the cookie available only to JavaScript code on the page; it is not available to the host site. However, a javascript routine can send it to a host site
Irony:
This is yet another of the many ‘joys’ of having an application ‘deeply integrated’ into an Operating system.
I don’t hate MS. I use their stuff almost every day. I also use several other operating systems, open and closed source.