Quote:
	
	
		
			
				
					Originally Posted by  pseudonym
					 
				 
				They WILL leak if a site uses https: for any of its content, they are also expected to leak if a site uses a port other than 80, because Phorm have stated that they only process traffic on port 80. 
 
They MAY also be accessible using client side javascript. 
			
		 | 
	
	
 fair comment, had not thought about the fact if a user had visited the website on a normal http connection then gone to the same websites on a https conection they should be able to see the cookie complete with UID
now thye other question to that is , is that going to break any websites?
also it is a method of extracting UID's for an attack
Peter