Greasemonkey scripts please be careful everyone but this really sucks

pcslookout

Lifer
Mar 18, 2007
11,959
157
106
I don't understand why people would do this but thankfully it doesn't give them your password. Still its very low thing to do.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: pcslookout
I don't understand why people would do this but thankfully it doesn't give them your password. Still its very low thing to do.

They do it because many cookies are poorly obfuscated and by getting them then can impersonate your account on those sites.
 

pcslookout

Lifer
Mar 18, 2007
11,959
157
106
Originally posted by: bsobel
Originally posted by: pcslookout
I don't understand why people would do this but thankfully it doesn't give them your password. Still its very low thing to do.

They do it because many cookies are poorly obfuscated and by getting them then can impersonate your account on those sites.

That sucks. Who is to blame for poor obfuscated cookies ? Is it best to block all cookies ?
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
That sucks. Who is to blame for poor obfuscated cookies ? Is it best to block all cookies ?

The website developer is responsible for the cookies contents. In the past you'd often see things simply in clear text (e.g. bsobel:password in the cookie). As things progressed many developers started obfuscating or encrypting the data. Encrypted data presuming the sites key is private is pretty safe. Obfuscation isnt, once one person figures out how its hidden he can decode all cookies of the sort.

As for turning off cookies, no that would make many sites unusable (cookies are used here, for example, to track who you are)

Bill

 

pcslookout

Lifer
Mar 18, 2007
11,959
157
106
Is there anyway to scan each greasemonkey script before installing it to make sure its safe ? This really sucks.
 

nova2

Senior member
Feb 3, 2006
982
1
0
"Is there anyway to scan each greasemonkey script before installing it to make sure its safe"

the only way to be 100% sure is to look at it yourself or spend time with perl regexp and be very through - covering all possibilities (including of course what to do if the parser becomes confused)