Re: Super Cookies in Privacy Browsing mode

I think we might need a consensus definition of what private browsing mode is, and how it affects servers.  We had some offline conversation about it at the workshop.

For example, for some people ‘private browsing’ starts a sandbox that is initialized from the regular browsing context (cookies and all), but that is discarded at the end of the private browsing session.  There’s no need for supercookies to correlate the regular browsing into private browsing, as the cookies are there.  Correlating the other way will simply raise the ire of users if you are not careful, as it would persist state and hence ‘leak’ from the private session back into the general one.

I have some ideas around codifying ‘private browsing mode’ and how to communicate ‘heh, I am trying to be private here!’ to servers.  Is this a topic of interest to others?

> On Jan 8, 2015, at 12:13 , Rigo Wenning <> wrote:
> Happy New Year!
> Interesting article about how HTTP Strict Transport Security can be used to 
> circumvent the protections in the private browsing mode. But it seems to be 
> fixed in firefox >34. I don't know about the other browsers. 
> --Rigo

David Singer
Manager, Software Standards, Apple Inc.

Received on Thursday, 8 January 2015 22:40:04 UTC