Risk
11/26/2013
12:42 PM
Connect Directly
RSS
E-Mail

Dataium Settles Browser History Sniffing Charges

The car buyer tracking firm was accused of using JavaScript to illegally identify websites visited by 181,000 named consumers, and selling harvested information.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
11/27/2013 | 7:48:42 AM
Re: Rare glimpse
 How much tracking are you willing to trade for useful websites? 

That's a hard question to answer in the dark. The Dataium case puts a spotlight on how little consumers know about the behind-the-scenes tracking that goes on. I think we're all well aware that Amazon has algorithms that tells us what books or products we might be interested in. But there needs to be greater transparency about the extent to which companies are sharing that information with partners. 
Mathew
50%
50%
Mathew,
User Rank: Apprentice
11/27/2013 | 4:52:24 AM
Re: Rare glimpse
One of the chilling aspects is that just by searching for cars online, even if you haven't registered on a website, data brokers -- including the likes of Equifax, TransUnion, and Experian, which recently confirmed a massive data breach at a subsidiary -- are not only seeing that information, but likely adding it to records that include your real name, address, email addresses, phone numbers, shopping preferences, financial details, and more. 

Furthemore, if that's the case for cars, then by extension every click you make on every website might be getting tracked in the same manner. All of which raises the question of how much tracking are you willing to trade for useful websites? 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
11/26/2013 | 2:43:18 PM
Rare glimpse
Fascinating story  & the details are indeed a rare glimpse into the extent of data mining that takes place unbeknown to most consumers. Hats off to the NJ AG's office for pursuing this!
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0993
Published: 2014-09-15
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2014-2375
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

CVE-2014-2376
Published: 2014-09-15
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2377
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

CVE-2014-3077
Published: 2014-09-15
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
CISO Insider: An Interview with James Christiansen, Vice President, Information Risk Management, Office of the CISO, Accuvant