October 18, 2005 4:00 AM PDT

Perspective: When the cookie crumbles

See all Perspectives
Consumers are often asked to choose between privacy and convenience.

Supermarket shoppers sign up for membership cards that, when swiped, provide automatic savings in return for recording all the holder's purchases. Electronic sensors in commuters' cars allow them to pass through tollbooths without stopping, but they also record the date and time each specific vehicle drives past. GPS devices in cell phones help towers deliver signals, but they also let the carrier know where the subscriber is at all times.

Perhaps the best illustration of the privacy-convenience trade-off is the Web browser. By now, most Internet users are familiar with the "cookie," a digital tag that allows Web sites to remember passwords, and often a little more. Cookies can be easily deleted, and all but forgotten.

Well, yes. But what many Web users don't realize, at least consciously, is that browsers also save, or cache, previously accessed files, images and other documents to local hard drives to make the Web surfing experience as efficient as possible. The browser's "back" button tells us that some information is stored, but not how much and for how long. Web users probably hadn't given those questions much thought until desktop search engines came along.

For the majority of Web surfers, ignorance is bliss.

Desktop search engines index all the content of a hard drive, including e-mails, files and Web pages visited, for near-instantaneous retrieval. And here's the kicker: Like their powerful Web counterparts, most desktop search tools cache information, so they can even find files after they have been deleted. These handy little tools provide a stark reminder that Web browsers leave a trail of crumbs indicating where their users have been and what they've been doing there.

For recreational Web users, this fact has its own set of implications. For remote workers using the Web to access sensitive corporate information, leaving such evidence behind can mean exposing intellectual property, running afoul of industry or government regulations, or worse.

Many businesses are starting to use (get ready, it's a mouthful) secure sockets layer virtual private networks, or SSL VPN for short, to create safe connections for remote workers. The great benefit of SSL VPNs is their ability to access corporate information from any location, public or private, armed with only a Web browser. When data is passing over the connection, it is encrypted in, well, SSL, and very secure. But what happens when it gets to the PC? Because people use a browser for SSL VPN, their information is cached just like any other Web site. The fact is, after e-mails, Web pages and documents pass through the VPN, they remain on the PC, easily retrievable by anyone with the time, inclination and a tool capable of searching the hard drive.

We in the security industry stay up nights worrying about stuff like this, but for the majority of Web surfers, ignorance is bliss. Still, it doesn't require a security professional's imagination to envision a hacker writing programs to scour public PCs in hotels, Internet cafes or airports for valuable information left there by unknowing remote workers or consumers. Fortunately, the security industry has fashioned a one-two punch using browser plug-ins to overcome the VPN's loose lips.

The first, a plug-in called a "cache cleaner," wipes the browser clean at the end of every session. This would seem to solve the problem, but it's not foolproof, since a browser crash or prematurely terminated session can cause a cache cleaner to malfunction. To be certain of safety, the plug-ins are starting to be used in conjunction with session encryption that encrypts every piece of data after it exits the VPN tunnel and hits the remote PC. This way, when the user walks away, the archived data is impossible to read.

These security technologies are new, so be sure to ask your IT administrator about them before you log in from the road. And please, remote workers of the world...encrypt!

Biography
Dean Ocampo is a product marketing manager at Check Point Software Technologies.

More Perspectives

See more CNET content tagged:
SSL VPN, desktop search engine, Check Point Software Technologies Ltd., SSL, VPN

Add a Comment (Log in or register) 2 comments
extremely useful article -- thanks!
by dmm October 19, 2005 6:45 AM PDT
what i said.
Reply to this comment
extremely useful article -- thanks!
by dmm October 19, 2005 6:45 AM PDT
what i said.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    At the TechCrunch50, an unfair advantage?

    Inside baseball: How Webware and other blogs can compete with TechCrunch in covering the TechCrunch50 event.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.