Google's tracking of Safari users could lead to FTC investigation
Privacy advocates say Google's circumvention of antitracking controls could violate a privacy settlement with the agency
IDG News Service - Google's alleged circumvention of do-not-track controls on Apple's Safari browser could lead to big fines from the U.S. Federal Trade Commission if the agency determines Google has violated a privacy settlement the company agreed to in March, some privacy advocates said Friday.
Violations of a settlement with the FTC can lead to fines of US$16,000 per violation, per day. It's unclear how many times Google may have circumvented do-not-track protections on the Safari browser, distributed with iPhones, iPads, some iPods and Macintosh computers.
Google was "incredibly stupid" to slip tracking cookies into Safari, given that the company is under scrutiny by the FTC and privacy advocates, said Justin Brookman, director of consumer privacy at the Center for Democracy and Technology. "I'd be very surprised if there was not some type of FTC action."
An FTC spokeswoman said the agency was aware of the allegations, but could not comment beyond that.
On Friday, Stanford University graduate student Jonathan Mayer published information about Google and three other companies defeating Safari's do-not-track protections.
Google said it did not intentionally install tracking cookies. "We used known Safari functionality to provide features that signed-in Google users had enabled," Rachel Whetstone, Google senior vice president for communications and public policy, said in a statement. "It's important to stress that these advertising cookies do not collect personal information."
Google designed a link between its servers and Safari browsers that allowed Google to collect anonymous information about users, Whetstone said.
"However, the Safari browser contained functionality that then enabled other Google advertising cookies to be set on the browser," she added. "We didn't anticipate that this would happen, and we have now started removing these advertising cookies from Safari browsers."
Even if Google installed tracking cookies inadvertently, that could lead to problems with the FTC, Brookman said. "Technological work-arounds to evade browser privacy settings are unacceptable," he added.
Consumer Watchdog, a privacy advocate that has been critical of Google, called on the FTC to investigate the company for unfair and deceptive business practices.
"They have been lying about how people can protect their privacy in their instructions about how to opt out of receiving targeted advertising," said John Simpson, the group's privacy project director. "Consumer Watchdog has asked the FTC to act because this clearly violates Google's consent agreement with the commission."
The incident also shows the need for the U.S. Congress to pass do-not-track legislation, Simpson added.
Google has shown a history of disregarding privacy concerns, with its Street View cars snooping on Wi-Fi networks, its sharing personal information on its ill-fated Buzz social networking service, and now this, added Jeffrey Chester, executive director of the Center for Digital Democracy, a privacy group.
"In its rush to gather more data on users to boost its marketing revenues, and fight off competition from Facebook, Google has sidelined the privacy implications," he said. "There's a pattern in Google behavior that reveals a company in hot pursuit of a user's data."
Chester rejected Google's explanation that it wasn't collecting personal data from Safari users. "They know very well that such behavioral targeting cookies are tied to unique individuals and reveal important personal information," he said.
Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is firstname.lastname@example.org.
- Mission Critical: Managing Mobile Applications & Content Smartphones, tablets and other mobile devices have become embedded in enterprise processes, thanks to the consumerization of IT and a new generation of...
- Securing Mobility, From Device to Network At one time, the process of managing and securing mobile devices and applications was fairly straightforward. Most organizations worried about one application (email)...
- Planning for Mobile Success Many organizations are seeing clear and quantifiable benefits from the deployment of mobile technologies that provide access to data and applications any time,...
- The Challenges and Opportunities of Mobile Application Development Nearly all business users now demand mobile devices--their own or company-owned--along with anywhere access to corporate applications and data. What turns mobile devices...
- Keep Servers Up and Running and Attackers in the Dark An SSL/TLS handshake requires at least 10 times more processing power on a server than on the client. SSL renegotiation attacks can readily...
- On Demand: Mastering the Art of Mobile Content Management Mobile device usage in the enterprise has skyrocketed, and it continues to escalate. IT must answer to users who demand access to their... All Legal White Papers | Webcasts