RE: IE6 Privacy and Secure Web Site

From: Jean-François Asselin (jfasselin@micrologic.ca)
Date: 01/23/02


Date: Wed, 23 Jan 2002 13:55:33 -0500
From: Jean-François Asselin <jfasselin@micrologic.ca>
To: <dross@ITWSouthland.com>, <focus-ms@securityfocus.com>

It is unnecessary to change the global setting. You can choose to allow
all cookies from a specific web site or domain, thus enabling the user
to authorize cookies from that secure web site, and still keep the
default settings to Medium High or higher. (just as you can set IE to
always reject cookies from particular web sites).

> -----Original Message-----
> From: dross@ITWSouthland.com [mailto:dross@ITWSouthland.com]
> Sent: January 23, 2002 12:22 PM
> To: focus-ms@securityfocus.com
> Subject: IE6 Privacy and Secure Web Site
>
>
> Internet Explorer 6 security settings: cookies and secure web sites.
>
> Internet Explorer 6 has the ability to set the level of
> security (Privacy) for the cookies a web site places in the
> internet files folder. The default setting is set to medium.
>
> Example:
> User goes to a web site to access secure data. The user is
> prompted for logon and password. The Logon proceeds fine but
> when the user attempts to use the features of the secure web
> site they are prompted to enable cookies in their browser.
> Cookies are enabled by default in the browser
> (IE6/Privacy) set to medium. To enable the features of the
> secure web site the privacy setting must be set to low. The
> secure web site then places two cookies in the internet file
> folder. The first cookie contains the logon information for
> the user and remains (Persistent) in the internet file folder
> after the user has logged off the site. The second cookie
> contains the web IP of the user and disappears (Session)
> after the user has logged off. The data stored within the
> first cookie is not encrypted, the logon is displayed as
> clear text and the password as ???. The logon is set by the
> secure web site and is a value which should never be used as
> a logon and the password is limited in set and size.
>
> This does not seem to be safe and secure.
> With about nine or is it eleven unresolved vulnerabilities
> currently in ie6 the following setting have been made to the browser.
>
> ie6 Advanced Settings
> Under Security Check: Do not save encrypted pages to disk
> and Empty Temporary Internet Files folder when browser is closed
>
> Have the user manually: Delete Cookies...Delete Files...and
> reset the Privacy setting to medium (prefer medium high)
> after logging off secure web site.
>
> Recommendations please, is this a problem with ie6, the
> secure web site and the use of cookies or both.
>
> Daniel Ross
> System Support Analyst
> ITW Southland
> dross@itwsouthland.com
> (757) 213-2445
>
>



Relevant Pages

  • Re: How do we get there from here?
    ... I can't tell you how often I try to do something on a web site and finally ... figure out I have cookies turned off...then have to open up my browser to ... Will it contain tokens that will be replaced by ... >>> both tokenized, so the content in them is session driven by cookies, ...
    (comp.databases.pick)
  • RE: IE6 Privacy and Secure Web Site
    ... cookies for any secure sites that need them while keeping the other sites ... IE6 Privacy and Secure Web Site ... |use the features of the secure web site they are prompted to ...
    (Focus-Microsoft)
  • [NEWS] Datalex BookIt! Consumer Password Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Datalex PLC's BookIt! ... Storing authentication credentials in cookies is never a good idea as ...
    (Securiteam)
  • Re: How do we get there from here?
    ... > figure out I have cookies turned off...then have to open up my browser to ... If 10% of the potential shoppers can't view the web site at all, ... CSS is currently tested only under IE6 and the latest FF: ...
    (comp.databases.pick)
  • Re: Zone Alarm 3.0 Some Bad News for web sites !
    ... I would be perfectly fine with the automatic blocking of cookies. ... What is the point of a web site if no one can find you? ... is dependant on visitors whether a personal, public service or a business ... there is some privacy issue here, ...
    (comp.security.firewalls)