LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-10-2013, 06:01 PM   #16
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174

Thanks Z038 and welcome to the thread. The behavior you describe is exactly what I experienced on the XP test PC without Flash installed. I guess I need to install Flash and see if the "Flash backup if you delete browser cookies" also works as advertised. I can monitor Flash cookies with the BetterPrivacy addon to Firefox.

Ken
 
Old 06-10-2013, 07:12 PM   #17
Z038
Member
 
Registered: Jan 2006
Location: Dallas
Distribution: Slackware
Posts: 910

Rep: Reputation: 174Reputation: 174
Just throwing some things out in case you haven't tried them.

There is a program called BleachBit that might do a more thorough job of clearing cache and cookies.

The Firefox add-on BetterPrivacy detects and clears LSOs (Flash cookies).

Another Firefox add-on called Collusion shows you how all the web sites you visit are tracking you via third-party cookies. If you leave your browser up and let Collusion collect data for a few days, the resulting graph will shock you. Here is what Collusion says:

Quote:
Collusion is an experimental add-on for Firefox that allows you to see which sites are using third-party cookies to track your movements across the Web. It shows, in real time, how that data creates a spider-web of interaction between companies and other trackers.
This one sounds really plausible... Maybe they are using "fingerprint" data. See this article: Race Is On to 'Fingerprint' Phones, PCs.
 
Old 06-11-2013, 05:07 AM   #18
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Thanks again Z038. I will look at BleachBit for regular use. I have BetterPrivacy and Collusion installed although I do not leave the browser running long enough for it accumulate any data. I will give the article a read.

Ken
 
Old 06-12-2013, 08:36 AM   #19
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Thanks Z038 for the link to the WSJ article.

It appears that some sort of fingerprinting is at the root of this issue. I suspect that if browser cookies and Flash cookies fail the sites are falling back on some sort of fingerprinting. Based on the fact that I am challenged when the Firefox version is updated on my CentOS machine I conclude that there is some incorporation of software related data in the fingerprint.

However, at two of the 3 sites of interest, once they have fingerprinted the computer on the Ubuntu Live CD they still recognize it when running knoppix. This leads me to believe that their fingerprint is strictly hardware based. The third site barfed when accessed with knoppix. I need to go back to Ubuntu and see if it is still recognized. Booting now...

The machine is still recognized when booted to Ubuntu. I have changed the CPU speed to "compatible" in BIOS. Rebooting Ubuntu. Well, perhaps not. It looks like Ubuntu is not compatible with compatible speed on an old Dell Pentium 4.

To summarize...

I have a snail mail letter in to the CIO at the large financial institution asking if their computer identification process is hosed or what data they are collecting but not disclosing in their privacy statement. I have enough $ invested there that I will have an answer from someone if they want my business.

I have an on-line contact message in to the major bank/credit card issuer again quoting their documents and asking WTF?

As to my local (small) bank... I am waiting for a return call from an "on-line banking support supervisor". Hopefully I will get someone who can at least spell PC I will update this post with any interesting findings.

Ken
 
Old 06-12-2013, 11:18 AM   #20
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Quote:
Originally Posted by taylorkh View Post
However, at two of the 3 sites of interest, once they have fingerprinted the computer on the Ubuntu Live CD they still recognize it when running knoppix.
I'm sorry but you cannot rope them together like that. Each site must be treated individually as they all use different rules.
There's no "magic cookie" going on here just rules based upon a few pieces of information and your inability to distinguish between how they are all used.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
lost computer login password for computer model d250-1958, S.O.S.teenager Linux - Newbie 5 01-05-2010 07:55 PM
redirect printer output on computer 1(Win2000) to Computer 2(Ubuntu)via parallel port dmarkd Linux - Hardware 2 12-01-2008 03:51 AM
How to move open office doc from Linux computer to Windows computer Phoenixink Linux - Software 6 02-15-2007 07:09 AM
Why Scourge (2nd computer) isn't getting ip address from Misery (1st computer) dhcp? pslave Linux - Networking 2 04-09-2006 05:58 AM
How can i portage Linux from computer with Celeron proc to computer with Pentium 166? gdi Linux - General 4 05-31-2003 01:11 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration