[2451] in WWW Security List Archive
Re: cookies and privacy
daemon@ATHENA.MIT.EDU (Seth I. Rich)
Thu Jul 18 12:33:23 1996
Date: Thu, 18 Jul 1996 09:35:03 -0400
To: Hal <hfinney@shell.portal.com>, dmk@allegra.att.com
From: "Seth I. Rich" <seth@hygnet.com>
Cc: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu
Hal <hfinney@shell.portal.com>:
>Consider changing the user interface so that we are not so much warned
>when cookies are received by the client, as given control over when they
>are sent. Don't send cookies automatically on every interaction. Only
>send them explicitly upon user request. For example, perhaps a shift
>click or some other modifier or mouse button is needed to send a cookie.
This presupposes that one's using a mouse.
Seth
---------------------------------------------------------------------------
Seth I. Rich - seth@hygnet.com "Info-Puritan elitist crapola!!"
Systems Administrator / Webmaster, HYGNet (pbeilard@direct.ca)
Rabbits on walls, no problem.