<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 13934</title>
	<link>http://www.metafilter.com/13934//</link>
	<description>Comments on MetaFilter post Comments on 13934</description>
	<pubDate>Thu, 17 Jan 2002 07:06:36 -0800</pubDate>
	<lastBuildDate>Thu, 17 Jan 2002 07:06:36 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 13934</title>
		<link>http://www.metafilter.com/13934/</link>	
		<description>&lt;a href="http://www.computerbytesman.com/privacy/supercookie.htm"&gt;Do you have a &apos;Super Cookie&apos; ??? Another m$ screw-up...&lt;/a&gt; Very interesting since wmp just minutes before tried to access the net through my firewall that is set to block all except a few programs. If you&apos;re running mozilla his &lt;a href=&quot;http://www.computerbytesman.com/privacy/supercookiedemo.htm&quot;&gt;demo  
&lt;/a&gt;  doesn&apos;t  hit but using msie it sures pulls up the ID# of my wmp... time to tighten things down again!!! Another  blasted waste of time  to fix what m$ should not have let out in the first place!!!  Link via... &lt;a href=&quot;http://www.thenoodleincident.com/inflight_correction/log.html&quot;&gt; Inflight Correction&lt;/a&gt;</description>
		<guid isPermaLink="false">post:www.metafilter.com,2002:site.13934</guid>
		<pubDate>Thu, 17 Jan 2002 06:52:07 -0800</pubDate>
		<dc:creator>tilt</dc:creator>		<category>SuperCookie</category>		<category>Microsoft</category>		<category>Windows</category>		<category>WMP</category>		<category>privacy</category>		<category>exploit</category>		<category>IE6</category>		<category>InternetExplorer</category>		<category>computers</category>
	</item>	<item>
		<title>By: yesster</title>
		<link>http://www.metafilter.com/13934/#207335</link>	
		<description>This is not a mistake.  It is an intentional design feature.   Surprised? You shouldn&apos;t be.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207335</guid>
		<pubDate>Thu, 17 Jan 2002 07:06:36 -0800</pubDate>
		<dc:creator>yesster</dc:creator>
	</item>	<item>
		<title>By: tilt</title>
		<link>http://www.metafilter.com/13934/#207350</link>	
		<description>&amp;gt;intentional design feature. Surprised? 

Actually I&apos;m not, I don&apos;t use cookies on any of my sites (I used to) but I sure wish such a feature wasn&apos;t enabled by default! I only use msie and netscape to verify page designs/scripts, mozilla is my preferred browser, and this just reinforces that choice!!!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207350</guid>
		<pubDate>Thu, 17 Jan 2002 07:24:37 -0800</pubDate>
		<dc:creator>tilt</dc:creator>
	</item>	<item>
		<title>By: jlachapell</title>
		<link>http://www.metafilter.com/13934/#207355</link>	
		<description>Opera 6 and NN4.7 both return the key.

Why do we have to continually deal with this kind of crap from Microsoft?!

-joe</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207355</guid>
		<pubDate>Thu, 17 Jan 2002 07:41:13 -0800</pubDate>
		<dc:creator>jlachapell</dc:creator>
	</item>	<item>
		<title>By: yupislyr</title>
		<link>http://www.metafilter.com/13934/#207357</link>	
		<description>&quot;In newer versions of WMP, there is an option on the &quot;Tools | Options&quot; Menu called &quot;Allow Internet sites to uniquely identify your player&quot;. If this option is manually turned off, SuperCookies will also be disabled because Internet Explorer will generate a new player ID number each IE session&quot;

Mine wasn&apos;t even on anyway.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207357</guid>
		<pubDate>Thu, 17 Jan 2002 07:44:19 -0800</pubDate>
		<dc:creator>yupislyr</dc:creator>
	</item>	<item>
		<title>By: holycola</title>
		<link>http://www.metafilter.com/13934/#207363</link>	
		<description>It seems to be off by default in Win XP. I&apos;m using XP Pro with Opera 6 and it didn&apos;t pull the key.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207363</guid>
		<pubDate>Thu, 17 Jan 2002 07:54:27 -0800</pubDate>
		<dc:creator>holycola</dc:creator>
	</item>	<item>
		<title>By: ook</title>
		<link>http://www.metafilter.com/13934/#207382</link>	
		<description>Much as I enjoy microsoft-bashing, this particular problem sounds unintentional. Sure they built a unique ID into every copy of windows media player, but the idea of using that ID to track usage of a different piece of software altogether -- the web browser -- is rather subtle (whoever thought of this first is a pretty smart, er, cookie.)   

One can certainly question why they felt the media player itself needed a unique ID, though.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207382</guid>
		<pubDate>Thu, 17 Jan 2002 08:30:31 -0800</pubDate>
		<dc:creator>ook</dc:creator>
	</item>	<item>
		<title>By: BentPenguin</title>
		<link>http://www.metafilter.com/13934/#207394</link>	
		<description>Smells like a fetal int-prop rights managment mechanism to me...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207394</guid>
		<pubDate>Thu, 17 Jan 2002 08:54:50 -0800</pubDate>
		<dc:creator>BentPenguin</dc:creator>
	</item>	<item>
		<title>By: dwivian</title>
		<link>http://www.metafilter.com/13934/#207425</link>	
		<description>On by default in XP Professional, just received on my new computer yesterday....

And, when I turn that option off, they still get the key....so, is the supercookie really off?  Who can say?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207425</guid>
		<pubDate>Thu, 17 Jan 2002 09:16:19 -0800</pubDate>
		<dc:creator>dwivian</dc:creator>
	</item>	<item>
		<title>By: ook</title>
		<link>http://www.metafilter.com/13934/#207446</link>	
		<description>dwivian, do you get the same key when the ID option is off, or a randomly generated one each time you restart your browser?

&lt;font size=-2&gt;(can&apos;t test this myself; I&apos;m using OSX. There, I said it.)&lt;/font&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207446</guid>
		<pubDate>Thu, 17 Jan 2002 09:35:56 -0800</pubDate>
		<dc:creator>ook</dc:creator>
	</item>	<item>
		<title>By: lucien</title>
		<link>http://www.metafilter.com/13934/#207482</link>	
		<description>From today&apos;s news &lt;a href=&quot;http://www.siliconvalley.com/docs/news/svtop/ms011702.htm&quot;&gt;Gates makes security top focus&lt;/a&gt;

The good - &lt;i&gt;&quot;Gates called on employees to make a fundamental change in the way they think about developing products, emphasizing security over new functions.&quot; &lt;/i&gt;

And the bad (?) - &lt;i&gt;&quot;....Issuing a statement doesn&apos;t solve any problems,&apos;&apos; said Bruce Schneier, chief technology officer at Counterpane Internet Security in San Jose. Microsoft is notorious for treating security as a public-relations problem. &quot;&lt;/i&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207482</guid>
		<pubDate>Thu, 17 Jan 2002 10:20:59 -0800</pubDate>
		<dc:creator>lucien</dc:creator>
	</item>	<item>
		<title>By: hincandenza</title>
		<link>http://www.metafilter.com/13934/#207485</link>	
		<description>Doesn&apos;t work for me- XP Pro.  See, every time I go to the page I get a &lt;b&gt;prompt&lt;/b&gt; as to whether I want to run an &lt;b&gt;ActiveX&lt;/b&gt; control, and not &lt;b&gt;trusting&lt;/b&gt; the webpage enough, I say &lt;b&gt;no&lt;/b&gt;.  And then it doesn&apos;t even get to run its little activex control.  Funny what a simple securing of your browser can do, you open-legged web-browsing sluts.  :)  Oh, and the option was turned off by me a long time ago in WMP anyway.

I&apos;m not saying this isn&apos;t an MS snafu, but do Linux folk or UNIX folk laugh at novice users who use those OSes and don&apos;t secure them?  MS shouldn&apos;t leave their OSes so open by default with these little backdoors, but I&apos;m pretty sure the WMP cookie is not much different than the realplayer cookie that&apos;s been around since early versions.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207485</guid>
		<pubDate>Thu, 17 Jan 2002 10:24:08 -0800</pubDate>
		<dc:creator>hincandenza</dc:creator>
	</item>	<item>
		<title>By: umberto</title>
		<link>http://www.metafilter.com/13934/#207513</link>	
		<description>Usually I go through obvious options and turn things like this off immediately.  Mine has been off since I upgraded WMP, I reckon, and the last 12 characters do seem randomly generated with every browser restart.

Can anyone deconstruct the first part of the cookie and see what --if anything-- is being revealed by the first 20 characters?  I&apos;m guessing os, browser, and version id, maybe, but you never know.

-umberto</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207513</guid>
		<pubDate>Thu, 17 Jan 2002 11:01:39 -0800</pubDate>
		<dc:creator>umberto</dc:creator>
	</item>	<item>
		<title>By: delfuego</title>
		<link>http://www.metafilter.com/13934/#207528</link>	
		<description>Russ Cooper has a &lt;a href=&quot;http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0201&amp;L=ntbugtraq&amp;D=1&amp;O=D&amp;F=P&amp;P=3582&quot;&gt;good explanatory post&lt;/a&gt; on NTBugTraq about this.  Summary: it&apos;s not a bug, and if you turn off the option to uniquely identify yourself, then WMP returns a randomly-generated GUID, not the one that is unique to your copy of WMP.

And thanks to hincandenza for pointing out that Real has had this same unique ID around for a &lt;i&gt;long&lt;/i&gt;, long time in their media player.

Gawd, people are so apt to jump onto a bandwagon...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.13934-207528</guid>
		<pubDate>Thu, 17 Jan 2002 11:28:12 -0800</pubDate>
		<dc:creator>delfuego</dc:creator>
	</item>
	</channel>
</rss>
