Quote:
Originally Posted by pseudonym
They WILL leak if a site uses https: for any of its content, they are also expected to leak if a site uses a port other than 80, because Phorm have stated that they only process traffic on port 80.
They MAY also be accessible using client side javascript.
|
fair comment, had not thought about the fact if a user had visited the website on a normal http connection then gone to the same websites on a https conection they should be able to see the cookie complete with UID
now thye other question to that is , is that going to break any websites?
also it is a method of extracting UID's for an attack
Peter