• User-uploading of files is now fully enabled!! Check out our full announcement for details.

    All accounts with 0 posts on them have been purged. If you are coming back to us after a long time and you find you can't log in, then that would probably be why.

Shutting Down All Session Hijacking/XSS/Cross-Site Request Forgeries

Arnox

Master
Staff member
Founder
Messages
6,520
Some of the most RAMPANT pieces of malware out there right now by far are browser cookie stealers. Pretty much every single attack is focused on getting your browser session tokens and stealing your online accounts. As of this writing, browsers have taken at least SOME steps to fix this, but if someone manages somehow to get into your computer and read your local files, you're fucked. I have been pretty annoyed wondering about this issue for a while now as the solution seems to be laughably simple. Encrypt the goddamn cookies. But web browsers developers at Google and Mozilla are extremely lazy and will only do the bare minimum, so we're stuck with this massive security flaw...

Or are we? I found this article over at Wikiversity detailing a browser extension that actually encrypts the damn cookies. It has an incredibly light browser fingerprint and is open-source. The problem though is that it's only for Chromium-based browsers and it's not even in the Chrome Web Store. But there's clearly some work being done here at least.
 
Back
Top