CFA/Security-Research/Cookies

< CFA‎ | Security-Research
Revision as of 00:24, 8 August 2007 by Galen (talk | contribs) (→‎Conclusions)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

« Comparative Feature Analyses
« Security Notes
« Security Research


Current Capabilities

  • Accepting cookies
    • Exceptions
    • Show cookies/cookie manager
    • Discard when quitting

Upcoming Capabilities

Features by 3rd parties or other browsers

  • Accept cookies only from the current site (OmniWeb)
  • Block/prompt/accept third-party cookies (IE)

Additional features

Screenshots

 

Conclusions

  • Outside of privacy concerns, cookie security concerns lie in cross-site scripting
    • One site can gain unauthorized access to another site's cookies through flaws in the website. Is this something the browser can prevent?