Home / Software & Gaming / The end of private browsing: Evercookie – unkillable ?

The end of private browsing: Evercookie – unkillable ?

Terrible news has reached us today that security researcher Samy Kamkar has created a horrific tool designed to create browser cookies that can not be deleted, The EverCookie API.

Kamkar is coming under flak from many organisations due to his coding which is able to generate a series of cookies that can survive multiple removal purges and can even track a user between browsers.

The Evercookie is a frightening little bugger as it can create a series of linked cookies using various storage methods. Local shared objects via Flash which operate only when a Flash plug in is installed but require a seperate clean up and which can be detected from any Flash enabled browser. Standard HTTP Cookies which can be cleared from any browser. HTML 5's session storage, global storage, local storage and database storage through SQLite. To make matters even worse it appears that it can work into page titles that store cookie information in all the browsers history and it can even create a cookie in the shape of a RGB value based PNG file. This is forced into the cache and then read back using the HTML 5's Canvas tag.

Kamkar hasn't decided to stop here as he has said he is going to look at improving it further and as it only needs one area to remain alive, it is going to prove hard to remove. Especially when it can regenerate itself after re-visiting an Evercookie enabled site.

Kamkar has released the source code for thie project which is going to put it into the hands of a wide array of crackers, hackers and malicious coders. In six months time we could have a serious situation on our hands.

KitGuru says: This has tremendous ramifications for security down the line and we can't understand why someone would create this in the first place.

Become a Patron!

Check Also

Call of Duty COD

KitGuru Games: Predicting the Next Half a Decade of Call of Duty Releases

Benjamin Franklin (1706-1790) famously once said: “The three absolutes in life are death, taxes and a new Call of Duty coming out every single year”. Sure enough, the US founding father has yet to be proven wrong, with Activision and a dozen studios having ensured that come the tail-end of any given year, there will be a new COD ready to release. And so, what can we expect from the franchise later this year? What about 2027, 2028 or even 2030? By looking back at the past two decades of Call of Duty games, their trends, progression and regression, I believe I can predict the next 5 years worth of annual COD entries.

4 comments

  1. very nasty indeed. some people need other hobbies 🙁

  2. This is a potential nightmare in the waiting.

  3. Samuel L Jackson ain’t gonna like this…

  4. If there was ever a case for the death penalty…

    Hopefully browser and plugin writers will be on top of this, creating the tools to delete these cookies safely.