According to a report in Wired, there are lots of sites out there (including whitehouse.gov) who are actively circumventing the common practice and zombifying the cookies you thought you’d deleted:
More than half of the internet’s top websites use a little known capability of Adobe’s Flash plugin to track users and store information about them, but only four of them mention the so-called Flash Cookies in their privacy policies, UC Berkeley researchers reported Monday.
Unlike traditional browser cookies, Flash cookies are relatively unknown to web users, and they are not controlled through the cookie privacy controls in a browser. That means even if a user thinks they have cleared their computer of tracking objects, they most likely have not.
What’s even sneakier?
Several services even use the surreptitious data storage to reinstate traditional cookies that a user deleted, which is called ‘re-spawning’ in homage to video games where zombies come back to life even after being “killed,” the report found. So even if a user gets rid of a website’s tracking cookie, that cookie’s unique ID will be assigned back to a new cookie again using the Flash data as the “backup.”
This would be a good opportunity for Adobe (who control the Flash cookie capability) and the browser developers to get together and provide end users with enhanced capability to turn off these zombies. Probably a tiny percentage of current users ever bother to delete cookies, so it’s not like this would seriously undermine legitimate uses of cookies, but it would put a bit more control of how personal information is used back in the hands of the individual.
Of course, back here in the real world, I don’t honestly expect any such thing, but regulation is almost always the wrong answer to a given problem on the internet. But that’s what we’re likely to get . . .



