Flash Cookies Now Managed Locally

 

   Adobe Flash cookies, aka "local shared objects" (LSOs), have come under fire in recent months.  Although almost all cookies {Chapter 3 Security+ 3ed} can be managed through the configuration settings of the local Web browser, that has not been the case with Flash Cookies.  And trying to delete them manually can be a real headache: not only are they buried deep on your computer in several different locations, they can be even be brought back to life after the cookie is deleted.  The only want to manage them was to go to the Adobe Web site at http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager02.html#118539 and navigate through a confusing list of options (see Jan 17 2011 blog posting).

   Now that is all changing--for the better.

   Last Thursday (May 12 2011) Adobe released an update called Adobe Flash Player 10.3, which is supported by Android, Linux, Mac OS, and Windows. While there are some performance improvements ("Media Measurement" and "Acoustic Echo Cancellation"), the big news surrounds security.  First, for Mac OS X users with the Flash Player installed it will now automatically check each week for new updates and then notify the user if any are available (this previously was not available for Mac as it was for Windows users).

   The second enhancement of Flash Player 10.3 involves managing Flash cookies.  For the Web browsers Mozilla Firefox 4 and Microsoft Internet Explorer (IE) 8+ flash cookies can be deleted through the Web browser (in IE click Tools | Safety | Delete Browsing History).  In case you're not convinced this works, Microsoft has an interesting Web site that lets you test it on your own browser; go to http://ie.microsoft.com/testdrive/Browser/FlashCookies/Default.html. Soon Safari and Google Chrome will also have this feature.  For right now in Chrome when you delete cookies (Wrench | Tools | Clear browsing data) you'll see an embedded link entitled "Adobe Flash Player storage settings . . ." that takes you to the Adobe Web site for managing them.

   In addition, Flash cookies can be managed through the operating system itself.  For Windows just type "Flash" in the Windows Search Box to display the Flash Player Settings Manager (to see a picture of it go to http://goo.gl/G0uDx).  From here you can set up blocking options, local storage settings by site, and also delete Flash cookies.

   Stay secure!

http://community.cengage.com/infosec