Microsoft disables 'supercookies' used on MSN.com visitors
New tracking technology a 'colossal privacy gaffe,' researcher says
Computerworld - Microsoft said it has disabled an online tracking technology that, according to a Stanford University researcher, allowed the company to sneakily track users on MSN.com -- even after they deleted their browser cookies and other identifiers.
In an emailed comment Thursday, Mike Hintze, Microsoft's associate general counsel, said the company took "immediate action" when it learned about the presence of so-called "supercookies" on its networks from Stanford University researcher Jonathan Mayer.
After Mayer identified Microsoft as one of several companies using supercookies for targeted advertising, the company investigated. "We determined that the cookie behavior he observed was occurring under certain circumstances as a result of older code that was used only on our own sites, and was already scheduled to be discontinued," Hintze said.
Mayer's research prompted Microsoft to move faster to disable the code, Hintze said. "At no time, did this functionality cause Microsoft cookie identifiers or data associated with those identifiers to be shared outside of Microsoft."
Mayer's report follows one from researchers at the University of California, Berkeley, on the practice by many websites of using tracking mechanisms that can circumvent the privacy settings on a user's browser. The Berkeley researchers also found that many sites, including Hulu, employed supercookie techniques to track users for advertising purposes.
A Hulu spokeswoman yesterday refused to comment on the UC Berkeley report. She pointed instead to a blog post from Hulu earlier this month which said the site acted "immediately" to address the issues identified by the researchers.
"This included suspending our use of the services of the outside vendor mentioned in the study," the blog post noted.
Supercookies are tracking mechanisms that do not rely on traditional browser cookies to store user browsing data. Examples of such cookies include Flash cookies in which user tracking data is stored in a little known Adobe Flash plug-in, and cache cookies in which the data is stored in the entity tags (eTags) used by browsers as a bandwidth saving mechanism.
Such cookies are hard to get rid of, don't expire on their own and can store a lot of information -- making them more appealing than traditional cookies to Internet marketers and web analytics firms. For instance, while an HTTP cookie stores just 4KB of data, Flash cookies can store up to 100KB.
One of the most controversial uses of such cookies has been to recreate or to "re-spawn' cookies that have been deleted by users.
Mayer said his research showed that Microsoft has code on its Live.com, MSN.com and its Atlas third-party advertising networks that would have caused a user's cookie to be recreated -- even after it had been cleared by the user.
"It is difficult to estimate the number of users affected by Microsoft's respawning without knowing more about traffic to Microsoft's web properties and the conditions under which it would set [the identifier ID]," Mayer said in his blog. But the company had the ability to easily associate a user's interactions with msn.com, live.com and the Atlas network both before and after cookie clearing.
"One of the most prolific ad networks was using technologies that are widely frowned upon for circumventing user privacy choices," Mayer told Computerworld via email. "At minimum this was a colossal privacy gaffe."
Privacy Watch
- Privacy advocates vow to continue CISPA fight
- CISPA concerns spread in Congress
- Privacy watchdog, lawmaker push for Google probe
- Privacy groups launch protest against CISPA bill
- Senators call for probe of employers seeking Facebook info
- 36 state AGs blast Google's privacy policy change
- FAQ: What Google's 'Do Not Track' move means
- Google commits Chrome to support 'Do Not Track'
- Google, Microsoft butt heads over IE privacy skirting
- Microsoft slams Google over iPhone, Mac privacy boner


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Privacy White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Privacy Webcasts
