Clearing privacy settings does not clear Flash cookies

Bug #210106 reported by webd0012
16
This bug affects 2 people
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Binary package hint: firefox

When you clear cookies in Firefox it does not clear Flash cookies. Sites are using this loophole to bypass users' privacy settings and track visitors after their privacy settings are cleared.

It would be great if Firefox would clear Flash cookies as well as HTTP cookies with the privacy settings.

I think this is a critical issue with the browser (and other browsers also).

ProblemType: Bug
Architecture: i386
Date: Tue Apr 1 14:33:22 2008
DistroRelease: Ubuntu 7.10
NonfreeKernelModules: fglrx
Package: firefox 2.0.0.13+1nobinonly-0ubuntu0.7.10
PackageArchitecture: i386
SourcePackage: firefox
Uname: Linux z369x 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux

Revision history for this message
webd0012 (webd0012) wrote :
Revision history for this message
John Vivirito (gnomefreak) wrote :

Are you able to reproduce this with Firefox-3.0? I seem to be unable to reproduce in Firefox-3 in Hardy/Intrepid

Changed in firefox:
status: New → Incomplete
Revision history for this message
shawnlandden (shawnlandden) wrote :

i dont think you know what flash cookies are John vivirito

http://en.wikipedia.org/wiki/Local_Shared_Object

banks, google, ebay all use them to bypass users cookie settings

so to ~/.macromedia/Flash_Player and look at all the tracking that people are doing of you without your consent

Changed in firefox:
status: Incomplete → Confirmed
Revision history for this message
John Vivirito (gnomefreak) wrote :

Scientus. I never said anything that would have you think i didnt know what they are. I asked " is this still reproducible in firefox-3.0. Reason i asked is reporter said it failed on 2.0.0.x please see following:

ProblemType: Bug
Architecture: i386
Date: Tue Apr 1 14:33:22 2008
DistroRelease: Ubuntu 7.10
NonfreeKernelModules: fglrx
Package: firefox 2.0.0.13+1nobinonly-0ubuntu0.7.10
PackageArchitecture: i386
SourcePackage: firefox
Uname: Linux z369x 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux

that is not the latest firefox 2.0 and he didnt reply that he still saw it. I cant reproduce this in 3.0 3.1 nor 3.2.
Please point out in one of my replies that hinted/suggested/ or what not that i didnt know what a flash cookie was.
I kind of have to know what they are to debug build patch ect mozilla apps.

On top of that this bug is not confirmed do the user not being about to comment if he can reproduce it. I would like to see another person seeing this bug, so far this is only bug filed on it AFAICS.
reverting back to incomplete.

Revision history for this message
John Vivirito (gnomefreak) wrote :

Also look at the date that it was filed its been just shy of a year, I cant count on the reporter to comment on it so as it stands you are only one to see this. Also this wouldnt land in 2.0.0.x.

Changed in firefox:
status: Confirmed → Incomplete
Revision history for this message
webd0012 (webd0012) wrote :

Yes, this is still a problem in all major Web browsers.

Firefox should delete all Flash cookies (LSOs) from ~/.macromedia/Flash_Player/#SharedObjects when you clean privacy settings (and the storage directories on Windows/Mac too). Firefox DOM Storage Privacy is another area that should be cleared by Firefox privacy settings.

Basically, Firefox privacy settings are broken because they do not protect your privacy. You have to "chmod 000" the Flash cookies directory (causing some sites to not work) and use about:config to fix the DOM storage problem.

See this page for backgroun on both issues:
https://ssd.eff.org/tech/browsers

Revision history for this message
NoOp (glgxg) wrote :

$ chmod -Rv 0500 .macromedia/Flash_Player/#SharedObjects/ .macromedia/Flash_Player/macromedia.com/support/flashplayer/sys/

is probably a better option. See:
http://www.linuxplanet.com/linuxplanet/tutorials/6709/1/

Revision history for this message
Pieter (diepes) wrote :

Firefox 3.0.13 i was shocked to see the cookies after clearing Private data.

to view cookies
http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html

Revision history for this message
shankao (shankao) wrote :

Yes, the flash cookies remain also with firefox 3.6

I think the firefox package has changed to 'firefox' now.

affects: firefox-3.0 (Ubuntu) → firefox (Ubuntu)
Changed in firefox (Ubuntu):
status: Incomplete → Confirmed
tags: added: privacy
Revision history for this message
dino99 (9d9) wrote :

That will not change till you install the right plugin to do so

Changed in firefox (Ubuntu):
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.