q2K BHP
Black History Portal
THE BHP WIRE —
HIDDEN TRUTHS
What's New!
THE JOURNEY THROUGH TIME

Explore Black History

Explore the people, places, events, achievements, struggles and stories that shaped our journey.

✊🏾

Civil Rights

Movements, leaders, victories and the continuing fight for equality.

⚙️

Black Inventors

Innovation, patents, science, technology and world-changing contributions.

🏆

Sports

Pioneers, champions, Negro Leagues, records, activism and excellence.

♟️

People

Meet the people whose lives, choices and achievements shaped the journey.

📍

Places

Black towns, communities, institutions and places where history happened.

📜

Events

Moments that changed communities, movements, institutions and the nation.

Enter a person, place, event, or topic.
MY'STORY

The MOVE Fire

This is a personal recollection on the Move fire on May 13, 1985 Philadelphia police fired thousands of rounds at the MOVE house, city officials approved dropping an explosive device on the roof, the resulting fire was allowed to burn, 11 people—including five children—died, and 61 homes were destroyed. Philadelphia City Council later called it a “brutal attack carried out by the City of Philadelphia on its own citizens” and acknowledged that no individual faced criminal consequences for the bombing. One timeline correction worth preserving for the BHP record: the major previous MOVE-police confrontation was August 8, 1978, about seven years before the bombing, not a year or two earlier. Officer James Ramp was killed, other police and firefighters were wounded, nine MOVE members were later convicted, and television cameras recorded police beating Delbert Africa during his arrest. The 1985 MOVE Commission later specifically criticized city planners for failing to adequately use lessons from that 1978 confrontation. And that actually strengthens the point you’re making: 1985 did not happen without precedent or institutional memory. There had already been a deadly confrontation with MOVE, years of conflict, negotiations and police involvement before Osage Avenue.

MORE →
BLACK FACTS
The Truths They Never Taught You...

Katherine Johnson — Mathematics to the Moon

Katherine Johnson’s mathematical calculations helped guide some of America’s most important early space missions while she confronted the racial and gender barriers faced by Black women in twentieth-century America.

MORE →
BHP gathered finds from its connected research sources. Showing the 4 strongest Black History matches.
← BACK TO RESULTS
Wikipedia

Zombie cookie

A zombie cookie is a piece of data usually used for tracking users, which is created by a web server while a user is browsing a website, and placed on the user's computer or other device by the user's web browser, similar to regular HTTP cookies, but with mechanisms in place to prevent the deletion of the data by the user. Zombie cookies could be stored in multiple locations—since failure to remove all copies of the zombie cookie will make the removal reversible, zombie cookies can be difficult to remove.[1] Since they do not entirely rely on normal cookie protocols, the visitor's web browser may continue to recreate deleted cookies even though the user has opted not to receive cookies.

Purpose

[edit]

Web analytics collecting companies use cookies to track Internet usage and pages visited for marketing research.[2] Sites that want to collect user statistics will install a cookie from a traffic tracking site that will collect data on the user. As that user surfs around the web the cookie will add more information for each site that uses the traffic tracking cookie and sends it back to the main tracking server.

Zombie cookies allow the web traffic tracking companies to retrieve information such as previous unique user ID and continue tracking personal browsing habits. When the user ID is stored outside of a single browser's cookie storage, such as in a header injected by the network into HTTP requests, zombie cookies can track users across browsers on the same machine.[3]

Zombie cookies are also used to remember unique IDs used for logging into websites. This means that for a user who deletes all their cookies regularly, a site using this would still be able to personalize to that specific user.

Implications

[edit]

A user who does not want to be tracked may choose to decline or block third party cookies or delete cookies after each browsing session.[4] Deleting all cookies will prevent some sites from tracking a user but it may also interfere with sites that users want to remember them. Removing tracking cookies is not the same as declining cookies. If cookies are deleted, the data collected by tracking companies becomes fragmented. For example, counting the same person as two separate unique users would falsely increase this particular site's unique user statistic. This is why some tracking companies use a type of zombie cookie.

Implementation

[edit]

According to TRUSTe: "You can get valuable marketing insight by tracking individual users' movements on your site. But you must disclose your use of all personally identifiable information in order to comply with the Fair Information Practices guidelines".[5]

Possible places in which zombie cookies may be hidden include:

  • Standard HTTP cookies
  • Storing cookies in and reading out web history
  • Storing cookies in HTTP ETags
  • Internet Explorer userData storage (starting IE9, userData is no longer supported)
  • HTML5 Session Storage
  • HTML5 Local Storage
  • HTML5 Global Storage
  • HTML5 Database Storage via SQLite
  • Storing cookies in RGB values of auto-generated, force-cached PNGs using HTML5 Canvas tag to read pixels (cookies) back out
  • Local shared objects (Flash cookies)
  • Silverlight Isolated Storage
  • Cookie syncing scripts that function as a cache cookie and respawn the MUID cookie[6]
  • TCP Fast Open
  • TLS's Session ID

If a user is not able to remove the cookie from every one of these data stores then the cookie will be recreated to all of these stores on the next visit to the site that uses that particular cookie. Every company has their own implementation of zombie cookies and those are kept proprietary. An open-source implementation of zombie cookies, called Evercookie,[7] is available.

Controversies

[edit]

In 2015, TURN, an online advertising clearinghouse,[8] introduced zombie cookies based on Flash Local Shared objects.[9] Privacy advocates quickly denounced the technology.[10]

An academic study of zombie cookies was completed in 2009, by a team of researchers at UC Berkeley,[11] where they noticed that cookies which had been deleted, kept coming back, over and over again. They cited this as a serious privacy breach. Since most users are barely aware of the storage methods used, it's unlikely that users will ever delete them all. From the Berkeley report: "few websites disclose their use of Flash in privacy policies, and many companies using Flash are privacy certified by TRUSTe."[11]

Ringleader Digital made an effort to keep a persistent user ID even when the user deleted cookies and their HTML5 databases. The only way to opt-out of the tracking, was to use the company's opt-out link, which gives no confirmation.[12] This resulted in a lawsuit against Ringleader Digital.

The Zombie Cookie lawsuits were filed suit in the United States District Court for the Central District of California against Quantcast, Clearspring, VideoEgg, and affiliated sites owned by Walt Disney Internet Group, Warner Bros. and others. According to the charges, Adobe Flash cookies are planted to "track Plaintiffs and Class Members that visited non-Clearspring Flash Cookie Affiliates websites by having their online transmissions intercepted, without notice or consent".[13]

Two "supercookie" mechanisms were found on Microsoft websites in 2011, including cookie syncing that respawned MUID cookies.[6] Due to media attention, Microsoft later disabled this code.[14]

Consumer outrage related to Flash cookies and violation of consumers' privacy caused U.S. Congressional Hearings, led by Senators Al Franken and John Rockefeller. Reportedly, the "Zombie Cookie", aka Flash Cookie filings, forced Adobe Systems Inc. to stop processing flash cookies on 98% of all consumers' computing devices.[citation needed]

The online advertising clearinghouse TURN implemented zombie cookies on Verizon mobile phones, using a hidden, unremovable number by which Verizon could track customers. After an article by ProPublica revealed this fact in January 2015, TURN claimed it had suspended usage of their zombie cookies.[8]

References

[edit]
  1. ^ Sorensen, Ove (2013). "Zombie-cookies: Case studies and mitigation". 8th International Conference for Internet Technology and Secured Transactions (ICITST-2013). London: IEEE. pp. 321–326. doi:10.1109/ICITST.2013.6750214. ISBN 978-1-908320-20-9.
  2. ^ "Google Analytics Cookie Usage on Websites - Google Analytics - Google Developers". Retrieved 2014-03-29.
  3. ^ Mayer, Jonathan (14 January 2015). "The Turn-Verizon Zombie Cookie". WebPolicy.org. Retrieved 22 April 2015.
  4. ^ Dixon, Pam. "Consumer Tips: How to Opt-Out of Cookies That Track You". World Privacy Forum. Retrieved 2010-11-10.{{cite web}}: CS1 maint: deprecated archival service (link)
  5. ^ "Online Privacy Best Practices from TRUSTe". truste.com. Archived from the original on 2011-10-26. Retrieved 2014-03-29.
  6. ^ a b Mayer, Jonathan. "Tracking the Trackers: Microsoft Advertising". The Center for Internet and Society. Archived from the original on 2011-09-26. Retrieved 2011-09-28.
  7. ^ "evercookie - virtually irrevocable persistent cookies". samy.pl. Retrieved 2014-03-29.
  8. ^ a b "Zombie Cookie: The Tracking Cookie That You Can't Kill"
  9. ^ "Company Bypasses Cookie-Deleting Consumers - InformationWeek". informationweek.com. 31 March 2005. Archived from the original on 2014-04-30. Retrieved 2017-04-10.
  10. ^ "EPIC Flash Cookie Page". epic.org. Archived from the original on 2020-08-12. Retrieved 2014-03-29.
  11. ^ a b Soltani, Ashkan; Canty, Shannon; Mayo, Quentin; Thomas, Lauren; Hoofnagle, Chris Jay (11 August 2009). "Flash Cookies and Privacy". SSRN Electronic Journal. doi:10.2139/ssrn.1446862. S2CID 6414306.
  12. ^ Cheng, Jacqui (September 22, 2010). "Zombie cookie wars: evil tracking API meant to "raise awareness"". Ars Technica. Retrieved 2014-03-29.
  13. ^ "Web users sue companies claiming use of Flash cookies is a hack". out-law.com. Retrieved 2014-03-29.
  14. ^ Burt, David. "Update on the issue of 'supercookies' used on MSN". Retrieved 28 September 2011.
[edit]

Source: Wikipedia. Article content is retrieved live through the MediaWiki API.

Wikipedia

HTTP cookie

An HTTP cookie (also called web cookie, Internet cookie, browser cookie, or simply cookie) is a small block of data created by a web server while a user is browsing a website and placed on the user's computer or other device by the user's web browser. Cookies are placed on the device used to access a website, and more than one cookie may be placed on a user's device during a session. Cookies serve useful and sometimes essential functions on the web. They enable web servers to store stateful information (such as items added in the shopping cart in an online store) on the user's device or to track the user's browsing activity (including clicking particular buttons, logging in, or recording which pages were visited in the past). They can also be used to save information that the user previously entered into form fields, such as names, addresses, passwords, and payment card numbers for subsequent use. Authentication cookies are commonly used by web servers to authenticate that a user is logged in, and with which account they are logged in. Without the cookie, users would need to authenticate themselves by logging in on each page containing sensitive information that they wish to access. The security of an authentication cookie generally depends on the security of the issuing website and the user's web browser, and on whether the cookie data is encrypted. Security vulnerabilities may allow a cookie's data to be read by an attacker, used to gain access to user data, or used to gain access (with the user's credentials) to the website to which the cookie belongs (see cross-site scripting and cross-site request forgery for examples). Tracking cookies, and especially third-party tracking cookies, are commonly used as ways to compile long-term records of individuals' browsing histories — a potential privacy concern that prompted European and U.S. lawmakers to take action in 2011. European law requires that all websites targeting European Union member states gain "informed consent" from users before storing non-essential cookies on their device.

MORE →
No preview image
Wikipedia

Zombie cookie

A zombie cookie is a piece of data usually used for tracking users, which is created by a web server while a user is browsing a website, and placed on the user's computer or other device by the user's web browser, similar to regular HTTP cookies, but with mechanisms in place to prevent the deletion of the data by the user. Zombie cookies could be stored in multiple locations—since failure to remove all copies of the zombie cookie will make the removal reversible, zombie cookies can be difficult to remove. Since they do not entirely rely on normal cookie protocols, the visitor's web browser may continue to recreate deleted cookies even though the user has opted not to receive cookies.

MORE →
No preview image
Wikipedia

Secure cookie

Secure cookie is a type of an HTTP cookie that has the Secure attribute set, which limits the scope of the cookie to "secure" channels (where "secure" is defined by the user agent, typically web browser). When a cookie has the Secure attribute, the user agent will include the cookie in an HTTP request only if the request is transmitted over a secure channel (typically HTTPS). Although seemingly useful for protecting cookies from active network attackers, the Secure attribute protects only the cookie's confidentiality. An active network attacker can overwrite Secure cookies from an insecure channel, disrupting their integrity. This issue is officially referred to as Weak Integrity. However, some browsers, including Chrome 52 and higher and Firefox 52 and higher, forgo this specification in favor of better security and forbid insecure sites (HTTP) from setting cookies with the Secure directive. Even with Secure, some sources recommend that sensitive information never be stored in cookies, on the premise that they are inherently insecure and this flag can't offer real protection. Secure attribute is not the only protection mechanism for cookies, there are also HttpOnly and SameSite attributes. The HttpOnly attribute restricts the cookie from being accessed by, for instance, JavaScript, while the SameSite attribute only allows the cookie to be sent to the application if the request originated from the same domain.

MORE →
No preview image
Wikipedia

Session (computer networking)

In computer science and networking, a session is a two-way link, a relatively high layer in the OSI stack enabling interactive information exchange between two or more communication devices or ends – be they computers, automated systems, or live active users (see login session). A session is established at a certain point in time, and then 'torn down' - brought to an end - at some later point. A session may involve more than one message in each direction. A session is typically stateful, meaning that at least one of the communicating parties needs to hold current state information to be able to communicate. An established session is the basic requirement to perform a connection-oriented communication. A session also is the basic step to transmit in connectionless communication modes. However, any unidirectional transmission does not define a session. Communication Transport may be implemented as part of protocols and services at the application layer, at the session layer or at the transport layer in the OSI model. Application layer examples: HTTP sessions, which allow associating information with individual visitors A telnet remote terminal session Session layer example: A Session Initiation Protocol (SIP) based Internet phone call Transport layer example: A TCP session, which is synonymous to a TCP connection, or an established TCP socket. In the case of transport protocols that do not implement a formal session layer (e.g., UDP) or where sessions at the protocol level are too short-lived, sessions are maintained by a higher level program. For example, a HTTP exchange between a browser and a remote host that includes a HTTP cookie with a unique session ID may identify a state such as information about the user's preferences or authorization level. Maintaining session continuity between HTTP requests requires a session ID. The session ID is embedded within the or links of dynamic web pages so that it is passed back to the CGI. CGI then uses the session ID to ensure session continuity between transaction phases.

MORE →
TOPIC OF THE DAY

Greenwood / Black Wall Street

Before the 1921 destruction of Tulsa’s Greenwood District, Black residents had created a remarkable center of business and community life. The district included stores, professional offices, entertainment venues and homes owned by Black citizens. Understanding Greenwood means learning what was built—not only what was burned.

MORE →
TRIVIA QUESTION OF THE DAY

Which Black woman became the first elected to the United States Congress?

Shirley Chisholm, elected in 1968.