sraun: portrait (Default)

[personal profile] sraun 2004-06-12 06:29 pm (UTC)(link)
Rumor has it the sausage meme steals passwords.

My source is [livejournal.com profile] pewtergryphon, her source is [livejournal.com profile] linaelyn, the latter has a writeup at
http://www.livejournal.com/users/linaelyn/627662.html
wibbble: A manipulated picture of my eye, with a blue swirling background. (Default)

[personal profile] wibbble 2004-06-12 06:32 pm (UTC)(link)
It can only steal passwords if you type your password in.

What it does do is exploit the existing cookie (which LJ relies on for you to stay logged in) to post in your journal without asking you. This same technique can be used to, say, have a web page which adds someone to your friends list without your permission. The sausage meme 'merely' automatically posts itself without asking, which is still obnoxious.