Skip to content

SuperCookie Built Into TLS 1.2 and 1.3

https://soylentnews.org/article.pl?sid=18/11/20/0326226

https://www.privateinternetaccess.com/blog/2018/11/supercookey-a-supercookie-built-into-tls-1-2-and-1-3/

Proposed 'about:config' mitigation:

security.tls.enable_0rtt_data existing key false security.ssl.disable_session_identifiers create new key true privacy.firstparty.isolate existing key true security.ssl.enable_false_start existing key false

Trac:
Username: heyjoe

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information