[Rhodes22-list] URL posting tips

John Lock jlock at relevantarts.com
Mon Mar 31 12:09:43 EDT 2008


At 11:29 AM 3/31/2008 -0400, Michael D. Weisner wrote:
>In addition, take a good look at the TinyURL web page pointed to by your
>link.  If you are an Amazon customer, they place an Amazon "PayBox"
>(graphic) in the left column complete with YOUR NAME displayed!  If you want
>their version of just how secure it is, read:

It's a little known fact that you can log yourself out of Amazon.com, 
so this kind of cookie tracking doesn't happen.

Once you login to your Amazon account, the web software places a 
cookie in your browser that identifies you at Amazon.  That's why you 
see the cute little "Hello..." or "Welcome back..." message when you 
return to Amazon the next time.

The "Amazon Honor System" merely lets affiliates take advantage of 
the fact that there is no obvious logout function on the Amazon 
website.  So, the Amazon-provided code can decipher the cookie 
information and personalize the graphic icon at affiliate websites.

So... if this makes you a little uneasy, just go back to Amazon.com 
and look at the header message.  You'll see the "hello" message right 
at the top, followed by a "(Not  xxxxx?)" link, where xxxxx is 
usually your first name from your Amazon account.  Just click that 
link to be logged out of Amazon and remove the stored cookie information.

Most knowledgeable developers know that cookie in formation is not 
secure and either encrypt that data or just don't place anything of 
any value in there.  In Amazon's case, the data is encrypted, so you 
have to use on of their special links to make any use of it.  Since 
it is run entirely from Amazon's server (no affiliate accessible 
code), they can change the encryption algorithm at any time to keep 
hackers guessing.

Cheers!

John Lock
~~~~~~~~~~~~~~~~~~
s/v Pandion - '79 Rhodes 22
Lake Sinclair, GA
~~~~~~~~~~~~~~~~~~



More information about the Rhodes22-list mailing list