Risk

Dataium Settles Browser History Sniffing Charges

The car buyer tracking firm was accused of using JavaScript to illegally identify websites visited by 181,000 named consumers, and selling harvested information.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
11/27/2013 | 7:48:42 AM
Re: Rare glimpse
 How much tracking are you willing to trade for useful websites? 

That's a hard question to answer in the dark. The Dataium case puts a spotlight on how little consumers know about the behind-the-scenes tracking that goes on. I think we're all well aware that Amazon has algorithms that tells us what books or products we might be interested in. But there needs to be greater transparency about the extent to which companies are sharing that information with partners. 
Mathew
50%
50%
Mathew,
User Rank: Apprentice
11/27/2013 | 4:52:24 AM
Re: Rare glimpse
One of the chilling aspects is that just by searching for cars online, even if you haven't registered on a website, data brokers -- including the likes of Equifax, TransUnion, and Experian, which recently confirmed a massive data breach at a subsidiary -- are not only seeing that information, but likely adding it to records that include your real name, address, email addresses, phone numbers, shopping preferences, financial details, and more. 

Furthemore, if that's the case for cars, then by extension every click you make on every website might be getting tracked in the same manner. All of which raises the question of how much tracking are you willing to trade for useful websites? 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
11/26/2013 | 2:43:18 PM
Rare glimpse
Fascinating story  & the details are indeed a rare glimpse into the extent of data mining that takes place unbeknown to most consumers. Hats off to the NJ AG's office for pursuing this!
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.