The dangers of storing cleartext sensitive information in a cookie? | Tutorial & examples | Snyk Learn (2024)

Gotham University is ranked the top university in the northern hemisphere. Getting good grades just isn't enough to get accepted here, they need to be exceptional. For this reason, many of the world's future leaders have spent time in these halls.

Among the current students is Sally, an enterprising cybersecurity student with a questionable moral compass. You see, Sally knows the value of personally identifiable information on the dark web. Student's personal details must be stored somewhere on university servers, and they would fetch a pretty penny if she could get her hands on them!

Cleartext Cookies

Setting the stage

The university has an internal web application to view your details. Sally logs into the application to take a look and to see what she can view...

The dangers of storing cleartext sensitive information in a cookie? | Tutorial & examples | Snyk Learn (1)

The dangers of storing cleartext sensitive information in a cookie? | Tutorial & examples | Snyk Learn (2024)

FAQs

Is it safe to store sensitive data in cookies? ›

A cookie should never contain any sensitive information, especially PII, because cookies are relatively easy for anyone to view if they have access to a browser that the victim has used.

What are the risks of using cookies? ›

Cookies by themselves do not pose security risks, however, they can be used by cybercriminals to impersonate the user, collect financial data, access their accounts or to steal passwords that are stored in the browser.

What not to store in a cookie? ›

Cookies are usually used to save some settings you've set on a certain website, or keep tokens which are used by websites to 'remember' you and not make you type your password again. Sensitive details such as passwords and/or personal information such as addresses and phone numbers.

What is the security vulnerability that is associated with cookies? ›

Cookie poisoning through cross-site scripting (XSS)

Usually, attackers find a page that is vulnerable to XSS injection. By inserting a malicious script into the page, they can get the page to send them the session cookies of everyone who views the page. This way, they can gain access to the data of all these users.

Does clearing cookies protect data? ›

That's because cybercriminals are constantly on the prowl for personally identifiable information stored in cookies, which they can exploit and/or sell on the dark web. Knowing how to clear cookies and cache from your browser is an important step in protecting your personal data online.

Which type of cookies can cause a privacy risk? ›

By tracking users' browsing habits, third-party cookies contribute to the creation of detailed profiles, raising serious privacy concerns. The accumulation of such information allows for the targeted delivery of advertisem*nts and content, often without users' explicit consent.

What problems can cookies cause? ›

Tracking User Activity: Cookies can be used to track a user's activity on a website, including their browsing history and actions such as clicking on buttons and filling out forms. This information can be used by companies to target advertisem*nts and analyze consumer behavior.

Can cookies harm your device? ›

Cookies can't harm your device—they're not a form of malware and can't affect how your computer runs. But keep in mind they do affect your online privacy.

Can cookies collect personal information? ›

Cookies track and store personal information about the user, which websites can use in the future. They store data such as name, residential address, email address, and phone number.

How to safely store cookies? ›

Room temperature: Use airtight containers, cookie jars, or plastic bags to prevent air exposure and moisture loss. Keep cookies in a cool, dry area. Refrigerated: Use airtight containers or sealed plastic bags to store cookies in the fridge. Monitor the moisture level to avoid condensation.

What information should be stored in cookies? ›

Cookies contain information such as pages visited on a website, items in the shopping cart, login details, search history and language preferences. They can also collect personally identifiable information such as name, email address, phone number and other personal data that users enter through website forms.

Is the danger of cookies that they store personal information that others can access? ›

Websites using cookies can collect your information and sell it to third parties. Changing your cookie preferences or removing cookies and other website data in Safari may change or remove them in other apps, including Dashboard.

What is the major vulnerability of cookies stored on common browsers? ›

Cookies (or other session tokens) not generated or transmitted securely are vulnerable to hijacking or poisoning. Cross-site scripting (XSS) is a common way to steal cookies, but a number of methods, including packet sniffing and brute force, may be used to gain unauthorized access to cookies.

What are cookie security flags? ›

The purpose of the secure flag is to prevent cookies from being observed by unauthorized parties due to the transmission of the cookie in clear text. A secure cookie can only be transmitted over an encrypted connection (HTTPS).

Should you store user data in cookies? ›

Answers (1) The downside of using cookie instead of cache is that cookies are stored on a user's device, meaning they can be accessed by malicious actors if the user's device is compromised. Cookies also have limited storage space, so if the data you are storing is large it may not be well suited for a cookie.

Can cookies store personal data? ›

Cookies contain information such as pages visited on a website, items in the shopping cart, login details, search history and language preferences. They can also collect personally identifiable information such as name, email address, phone number and other personal data that users enter through website forms.

Is it safe to store sensitive data in session storage? ›

Both Local and Session Storage provide a simple and efficient way to store data on the client side without frequent server trips. However, due to their limitations in security and capacity, it's crucial to use them judiciously and not for storing sensitive information.

Top Articles
Latest Posts
Article information

Author: Sen. Emmett Berge

Last Updated:

Views: 5648

Rating: 5 / 5 (80 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Sen. Emmett Berge

Birthday: 1993-06-17

Address: 787 Elvis Divide, Port Brice, OH 24507-6802

Phone: +9779049645255

Job: Senior Healthcare Specialist

Hobby: Cycling, Model building, Kitesurfing, Origami, Lapidary, Dance, Basketball

Introduction: My name is Sen. Emmett Berge, I am a funny, vast, charming, courageous, enthusiastic, jolly, famous person who loves writing and wants to share my knowledge and understanding with you.