Skip Links

Network World

  • Social Web 
  • Email 
  • Close

The myth of no fingerprints

By Joel Snyder , Network World , 01/12/2004
  • Share/Email
  • Comment
  • Print

Secure Sockets Layer VPN vendors must like frequent flyers: Many of the products we looked at in this review are geared toward the oft-mentioned Internet kiosk user. The idea here is that people travel around and want to log on to these PCs with Internet connections that dot the landscape in airports, hotels and better bus stations.

The problem, of course, is that browsers are notorious for littering the local hard disk with information about where you've been and what you've done. Cookies, URL histories, page caches and files you might have clicked on are all captured on that machine when you're finished.

This detritus apparently gives network managers indigestion. SSL VPN vendors spent a good deal of time trying to soothe this issue with features that clear out the local system after a session is over, wiping the fingerprints off of the local hard disk in an effort to erase any knowledge of a user's actions.

The information left over would let the next person get a clue to what the SSL VPN user did. URL caches, for instance, might be fairly innocuous, but cookie files can have usernames and passwords in them, and cached files might have all sorts of sensitive corporate data in them.

F5 NetworksNeoteris and Whale Communications all put various bells, whistles and bits of code designed to delete more and more data off the systems. For some products, it's a big deal to trumpet in their marketing literature; for others, it's a simple checkbox you might miss.

However, in all the products with this feature, it's a waste of time. This technology is most needed exactly where it will never work. If you're at a kiosk in Charles de Gaulle Airport, you're lucky to have a keyboard, much less a browser that is going to be compatible with these tools. For example, Whale makes it pretty clear in its documentation what the problem is. For its "attachment wiper" to work, you have to not only be running a recent version of Internet Explorer on Windows, but you also must have the browser configured to download and run ActiveX objects, and you must be logged on with elevated privileges.

Whale isn't alone here; anyone who wants to delete files and clean up the browser is going to have to write operating system and browser-specific software that is at odds with your typical Internet kiosk.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed