Evercookie: browser identifiers that are hard to delete
Summary
Samy Kamkar demonstrates how an identifier is stored in parallel in numerous browser storage mechanisms and restored after individual copies are deleted. Redundancy serves not only availability but can also deliberately undermine users' decisions. Privacy controls fail when browsers treat storage mechanisms separately rather than as a whole.
Ideas
- Cookies, Flash storage, ETags and web storage can redundantly carry the same identifier.
- One remaining copy reconstructs values removed from other storage locations.
- The project highlights the gap between the visible delete function and the actual state.
Recommendations
- Block unnecessary third-party content and separate browser profiles by level of trust.
- Regularly assess tracking protection against new storage and fingerprinting techniques.
References
Links to the original source and the Web Archive open in a new tab.