Feeds

NSA involved in snooping cookie shocker

What's next?

Internet Security Threat Report 2014

Holy global eavesdropping network, Batman! The NSA has - or rather had - cookies on its website.

Daniel Brandt - he of Google watching and Wikipedia fiddling fame - discovered a pair of cookies lurking on the NSA's (National Security Agency) website. The cookies were set to expire in 2035 and could be used to track your online activity. That's a big no-no under federal rules that forbid the use of most persistent cookies.

The NSA removed the cookies after Brandt brought the issue to the agency's attention and after the AP started asking questions.

"After being tipped to the issue, we immediately disabled the cookies," NSA spokesman Don Weber, told the news service.

Government agencies can use cookies of the non-persistent variety but are discouraged from keeping an ongoing watch on citizens.

The NSA? Cookies?

We know, we know. You're shocked.

In the context of the NSA's constant global monitoring of communications and more recent wiretapping flap, a couple of cookies hardly seem like a big deal. And, in fact, they're probably not. The NSA has played off the appearance of the cookies as an accident. A software upgrade allowed the nasty, persistent buggers to sneak on the website.

As Brandt points out, however, there are no exceptions in federal guidelines for "accidental" snooping.

Or so we think. It seems that just about anything goes these days.

As Ty Webb once remarked: "This isn't Russia. Is this Russia? This isn't Russia." ®

Internet Security Threat Report 2014

More from The Register

next story
BIG FAT Lies: Porky Pies about obesity
What really shortens lives? Reading this sort of crap in the papers
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.