Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove ID string from third party opt-out cookie #5886

Closed
mattab opened this issue Jul 26, 2014 · 4 comments
Closed

Remove ID string from third party opt-out cookie #5886

mattab opened this issue Jul 26, 2014 · 4 comments
Labels
Task Indicates an issue is neither a feature nor a bug and it's purely a "technical" change. wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it.

Comments

@mattab
Copy link
Member

mattab commented Jul 26, 2014

The CNIL has suggested that it would be more readable and useful to remove the ID found in the 3rd party opt-out cookie. Having an ID in that cookie is not a problem but it's a bit confusing as it almost looks like it's a visitor ID (though its only a static ID that will be the same for all opt-out cookies).

More info: the reason an id appears there is that our cookies are signed. @robocoder do you think there is still a security advantage to signing our cookie? Maybe we could now safely remove the signing part of the Cookie class.

@mattab mattab added this to the Piwik 2.5.0 milestone Jul 26, 2014
@robocoder
Copy link
Contributor

We sign the cookie to ensure the cookie was created by Piwik by a user who explicitly opted out. If you remove the ID, then third-party developers can easily spoof the cookie (e.g., via a browser extension).

You're welcome to remove the ID, but I think some users would prefer it be configureable and/or default to prevent spoofing.

@robocoder
Copy link
Contributor

An alternative is to rename the cookie to something more innocuous, e.g., opt_out_confirmation.

@robocoder
Copy link
Contributor

Either way, CNIL's suggestion has no weight. First, it's not an ID -- it isn't personal identifiable information that needs to be kept confidential. Second, removing it would allow spoofing, which would be counter to the principle of data security.

@mattab mattab modified the milestones: Current milestone, Future releases Aug 1, 2014
@mattab mattab added P: normal and removed P: major labels Aug 1, 2014
@mattab
Copy link
Member Author

mattab commented Aug 1, 2014

Thanks for your input. I've moved out of backlog as this is low priority.

@mattab mattab added Task and removed P: normal labels Aug 3, 2014
@mattab mattab closed this as completed Apr 26, 2015
@mattab mattab added the wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it. label Apr 26, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Task Indicates an issue is neither a feature nor a bug and it's purely a "technical" change. wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it.
Projects
None yet
Development

No branches or pull requests

2 participants