Super Cookies - Can they be deleted?

I call tech support one day...


Their answer was:

1) "Clear history & website data from safari".


2) Settings>Safari>Clear History and Website Data


3) Settings>Safari>Advanced>Website Data>Remove All Website Data


But, in my case, there are persistent data that survive the "clear." Usually from random sites I've visited.


The chat was dropped, and the tech couldn't solve this problem ...


After much research, I found several articles...


This one was very interesting.


Copy of part of the Article Follows-


"Apple Users Can't Get Rid Of The New ‘Super Cookies’ That Track Private Web Browsing



Rob Price Business InsiderJanuary 10, 2015

A security flaw means that users of almost every modern web browser can be surreptitiously tracked online without their knowledge, Ars Technica reports, even when they make use of “private browsing.”

Apple users are particularly vulnerable, as their devices do not have a function that lets users delete super cookies from their browsers.

Most websites place what’s called a “cookie” on visitors’ computers, which is used to track them and record their preferences. It’s how websites can remember your password, for example. Like your web browsing history, they’re easy to delete. If you use your browser’s “private browsing” mode they’re never saved in the first place — and advertisers can't track you, and other computer users can't go back and see what you looked at.

However, a flaw in a modern web security feature called “HTTP Strict Transport Security” (HSTS) allows websites to plant “super cookies” that can be used to track web users’ browsing habits even when private browsing is enabled.

Here’s how it works.

Security researcher Sam Greenhalgh writes that HSTS “allows a website to indicate that it should aways be accessed using a secure connection that encrypts your communication with the site.” This “flag” is then saved by your web browser, ensuring that any future visits to the website are secure. But this can also be abused, using this feature to store a unique number that can be used to track your web browser.

And because HSTS carries over into private browsing, it means the “super cookie” can be used to track you whether you’re attempting to cover your steps or not.

Greenhalgh says that Apple’s Safari web browser is especially vulnerable to the exploit. While clearing cookies on Mozilla’s Firefox, Google Chrome or Opera also erases HSTS flags, deleting the super cookies, there’s no way to do so on Safari on iOS devices.

This means that if you’ve had super cookies placed on your iPad or iPhone, there’s effectively no way to get rid of them short of reformatting the entire machine."


This problem has been around fir a number of years...


Hopefully Apple will one day, fix it...


Dr. Paul Monte

iPad Pro Wi-Fi, iOS 10.3.2

Posted on Jul 5, 2017 7:41 PM

Reply
2 replies

Aug 22, 2017 8:54 AM in response to DocMonte

In SOME instances, not all, you might clear persistent website data as follows:


1. Make note of the information in Settings>Safari>Advanced>Website Data.


2. One by one, open Safari and go to the site indicated in the Website Data. When the page opens, do not clear the History, but momentarily close Safari, and the open Settings>Safari>Advanced>Website Data, and manually remove ONLY that entry. Then, select Remove All Website Data. Close Settings. Open Safari. The page you went to should no longer be open. Check, and if necessary, clear all History in Safari. Close Safari, and then check to see if that data entry has been removed in Settings>Safari>Advanced>Website Data. This works for SOME, but not all the persistent super cookie remnants. If manages to cull my list down to six using this approach.


We are helpless until Apple decides to value the security of its clients over market forces that want to track our each and every move. Makes me want to consider opening an Anonymizer account.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Super Cookies - Can they be deleted?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.