Quote:
Originally Posted by isf
A debate wasn't my intention, I was simply putting it in perspective -- exactly as you did with your opening sentence.
|
Fair enough.
Quote:
Originally Posted by isf
I'm not trying to design their system for them, far from it. However if they insist on going ahead with this farce the least they can do is attempt to avoid leaking the uid.
|
It's just an interesting exercise to consider how they could try and work round problems. Invariably it shows that they are likely to come up with other problems. I'm pretty confident that when (if) they do launch, the uids will leak, phorm will be able to get at PII, profiles will be filled with bogus data and the phishing filter will cause more problems than it solves.
Quote:
Originally Posted by isf
The uid is a key to a database containing profile data, we're only talking about leakage due to phorged cookies under 3rd party domains. If a cookie is invalid, they simply overwrite it by spoofing a valid one.
|
Ah, you mean using the 'master' cookie in phorm's own domain? Fair point. If the users in control of their pc's want to tamper with their uid they still can though.