Collected research
The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private Information
Sites that still serve some pages over HTTP leak their non-session cookies to any network eavesdropper. An audit of 25 major services shows those stolen cookies expose search history, home and work addresses, purchase history and contact lists, and can even send mail from the account; a month of campus traffic found 282,000 exposed accounts, and Tor users are deanonymisable the same way.
Record
- Researcher
- Suphannee Sivakorn, Iasonas Polakis and Angelos D. Keromytis
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Suphannee Sivakorn, Iasonas Polakis and Angelos D. Keromytis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .