Cache Cookies for Browser Authentication ( Extended Abstract ) Ari Juels Markus Jakobsson

نویسندگان

  • Ari Juels
  • Markus Jakobsson
  • Tom N. Jagatic
چکیده

Like conventional cookies, cache cookies are data objects that servers store in Web browsers. Cache cookies, however, are unintentional byproducts of protocol design for browser caches. They do not enjoy any explicit interface support or security policies. In this paper, we show that despite limitations, cache cookies can play a useful role in the identification and authentication of users. Many users today block conventional cookies in their browsers as a privacy measure. The cache-cookie tools we propose can help restore lost usability and convenience to such users while maintaining good privacy. As we show, our techniques can also help combat online security threats as phishing and pharming that ordinary cookies cannot. The ideas we introduce for cache-cookie management can strengthen ordinary cookies as well. Because cache cookies have been viewed traditionally as a threat to user privacy, and lack important read-access restrictions, we propose cache-cookie protocols that aim to protect privacy by design. The full version of this paper may be referenced at www.ravenwhite.com.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Cache Cookies for Browser Authentication ( Extended

Like conventional cookies, cache cookies are data objects that servers store in Web browsers. Cache cookies, however, are unintentional byproducts of protocol design for browser caches. They do not enjoy any explicit interface support or security policies. In this paper, we show that despite limitations, cache cookies can play a useful role in the identification and authentication of users. Man...

متن کامل

Active Cookies for Browser Authentication

We propose active cookies as a tool for stronger user/client authentication on the Web. An ordinary cookie is automatically released to any server associated with a particular domain name. It is therefore vulnerable to capture by pharming, that is, spoofing of domain names. An active cookie, by contrast, resists such pharming attacks. Active cookies rely on a new protocol we propose that channe...

متن کامل

Privacy-Preserving History Mining for Web Browsers

We introduce a new technique that permits servers to harvest selected Internet browsing history from visiting clients. Privacy-Preserving History Mining (PPHM) requires no installation of special-purpose client-side executables. Paradoxically, it exploits a feature in most browsers (IE, Firefox and Safari) regarded for years as a privacy vulnerability. PPHM enables privacy-preserving data-minin...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006