A new flaw in cookie handling that makes log-ins persistent has been discovered by security researcher Rishi Narang. The new discovery reveals that websites such as Yahoo, LinkedIn and Twitter still keep the cookie/session ID for an authenticated session valid even if they have expired or the user has logged out of his account. Earlier this year, a spam message redirected users to a malicious page where they had their cookies stolen from Yahoo users. If todays report is true, some of the unauthorized account usage reports may still be the result of the cookie harvesting campaign in January.”]

