Who left open the cookie jar? A comprehensive evaluation of third-party cookie policies
Who left open the cookie jar? A comprehensive evaluation of third-party cookie policies from the Franken et al., USENIX Security 2018
This paper won a ‘Distinguished paper’ award at USENIX Security 2018, as well as the 2018 Internet Defense Prize. It’s an evaluation of the defense mechanisms built into browsers (and via extensions / add-ons) that seek to protect against user tracking and cross-site attacks. Testing across 7 browsers and 46 browser extensions, the authors find that for virtually every browser and extension combination there is a way to bypass the intended security policies.
Despite their significant merits, the way cookies are implemented in most modern browsers also introduces a variety of attacks and other unwanted behavior. More precisely, because cookies are attached to every request, including third-party requests, it becomes more difficult for websites to validate the authenticity of a request. Consequently, an attacker can trigger requests with a malicious payload from the browser of an unknowing victim… Next to cross-site attacks, the inclusion of cookies in third-party requests also allows fo users to be tracked across the various websites they visit.
When you visit a site A, it can set a cookie to be included in Continue reading
Comarch recently won a contract with South Korean 5G operator LG U+ to replace its OSS stack.
The company's open source partner program will divert revenue to organizations or individuals that allow blockchain-based encrypted storage on personal devices.
Verizon is a CENX customer. CENX employees, including new CEO Edward Kennedy, will become part of Ericsson when the deal closes this quarter.
Remember the Token Ring!!

Cisco targets 1 million routers for SD-WAN; a Cisco SVP shakeup; and Arista's (surprising) first acquisition.