Re: The Phish that isn't Going Away

"CO-DBA-SC-EL" <[email protected]> Mon, 15 May 2006 18:34:43 -0700
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
"Porpoise" <[email protected]> wrote in message 
news:[email protected]...
(snip)
> The thing is, not that the cookies can run malicious code, but that the 
> user doesn't know whose/what cookies are being downloaded onto their 
> systems. Also that if a hacker managed to get access to a HDD s/he could 
> then have access to any login data stored in any of those 
> cookies.......... as the info is in plain text.....
LOL. There much juicier login data including passwords in the password cache 
in 99% of Windows systems. A hacker getting access to a HDD would not waste 
time with cookies when that good stuff is there for the taking.

The dangers of cookies are an urban legend that is unfortunately distracting 
people from more serious issues. Don't confuse actual damage with privacy 
leaks. Anyway, even on that topic the links provided are over 5 years old, 
dating back from long before web services made the 3rd party cookies 
unnecessary for sophisticated data collection-- all they need to know they 
can get by having one server call a service on another one.

Just MHO.

C_O