ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

IE privacy flaw still causing leaks

Stefanie Olsen, CNET News.com CNet

Published: 16 Jan 2002 11:47 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

New privacy-enhancing controls in Microsoft's Internet Explorer 6.0 can be rendered useless by a long-known security flaw in Windows Media Player, a noted security expert said on Tuesday.

The software giant has heavily promoted the privacy features of its new browser, which includes support for recently approved standards known as P3P (Platform for Privacy Preferences). Among other things, the standards aim to give Web surfers more control over electronic markers known as cookies, which can be used to peek into people's online activities.

This week, computer privacy and security consultant Richard Smith warned that a unique ID created under default settings for the Windows Media Player provides a simple override for those measures. The flaw allows a malicious Web site to create what he described as a "supercookie" capable of tracking people using any version of Internet Explorer and Netscape Navigator, regardless of the privacy settings they choose.

"Using simple JavaScript code on a Web page, a Web site can grab the unique ID number of the Windows Media Player belonging to a Web site visitor," Smith said. "This ID number can then be used just like a cookie by Web sites to track a user's travels around the Web."

Although Microsoft has provided a fix to the flaw, Smith said the solution does not go far enough.

"There are many people who have never run Windows Media Player, yet they are still vulnerable to the problem," he said.

Confusing solution?
Smith, who said he first discovered the flaw and notified Microsoft last March, reported the hole in a posting on the Bugtraq security mailing list.

A Microsoft representative said the company issued a patch for the problem in May, allowing people to change Windows Media Player's default settings. The fix also solves a recently identified vulnerability that allows a malicious set of Web sites to profile a person through the media player, according to Microsoft.

In Windows Media Player versions 6.4 and 7.1, people can turn off the option "Allow Internet Sites to uniquely identify your player" in their settings to stop potential tracking by creating a different number for each IE session. In addition, they can uninstall Windows Media Player or turn off JavaScript.

"Although we typically do not discuss privacy issues in security bulletins, the privacy issue in this case is eliminated by applying the patch and then selecting the new user settings," a Microsoft representative wrote via email.

Smith, however, said many people may not make the connection that they need to tweak Windows Media Player, a free product that is distributed with most copies of the Windows operating system, to fix a privacy leak in IE.

The privacy alert comes as Microsoft has been touting the privacy-enhancing features of its latest browser. P3P allows consumers to set their browser preferences to reject Web sites with inadequate privacy policies. But as Microsoft promotes new security and privacy initiatives, it has repeatedly faced disclosures of new vulnerabilities.

In the past several months, for example, more than half a dozen security problems have been found with the latest version of Internet Explorer. Most recently, a security researcher revealed a bug in IE 6 that could let an attacker send an HTML email, which in turn could steal cookies, allow access to files, or direct the victim to a false Web site.

Last month, Microsoft urged people to apply a patch for a severe security hole found in Windows XP, which the software titan had boasted was its "most secure operating system yet."

All of the flaws drive a truck through Microsoft's efforts to promote privacy.

"The real issue is, here you have Microsoft spending time and money on promoting how wonderful P3P is, and there is a simple workaround," Smith said. "If Web sites get annoyed by too many people turning off cookies or using P3P, they can use supercookies instead, bypassing decisions users have made. It potentially becomes a game of spy vs spy."

For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
38 out of 104 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Discussions

1000030281 1000030281

Facebook Bans Firefox 3

Sunday 20 July 2008, 2:33 AM

1 comment
roger andre roger andre

SP3 Under Suspicion Again

Saturday 19 July 2008, 9:29 PM

2 comments

Blog Posts

Avatar roger andre

Facebook Bans Firefox 3

Saturday 19 July 2008, 7:54 PM

1 comment
Avatar geek

Windows Vista

Friday 18 July 2008, 7:58 PM

0 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme