Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

1/28/2013
02:42 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Faces Safari Privacy Claim In U.K.

Google is attempting to have similar claims dismissed in the U.S. for lack of harm.

10 Best Business Tools In Google+
10 Best Business Tools In Google+
(click image for larger view and for slideshow)
Overlooking the irony of fighting for privacy on a social network, a few users of Apple's Safari browser in the United Kingdom have marked Data Privacy Day by launching a Facebook page to coordinate possible legal claims against Google. The group seeks to punish Google for bypassing privacy controls in Apple's Safari browser on desktop and mobile devices as a means to present personalized content.

The law firm Olswang has been retained to coordinate any claims. The first claimant, Judith Vidal-Hall, said in a statement, "Google claims it does not collect personal data but doesn't say who decides what information is 'personal.' Whether something is private or not should be up to the Internet surfer, not Google. We are best placed to decide, not them."

Google's circumvention of privacy controls in Safari was revealed in February 2012 by Stanford graduate student Jonathan Mayer. Rachel Whetstone, Google's SVP of communications and public policy, explained at the time that the company bypassed Safari's controls "to enable features for signed-in Google users on Safari who had opted to see personalized ads and other content -- such as the ability to '+1' things that interest them."

[ Are you finding your access to some apps being restricted? Read Facebook Blocks Vine, Wonder Apps. ]

In November, Google agreed to pay $22.5 million to settle a Federal Trade Commission claim that it had violated a previous agreement with the agency by misrepresenting privacy assurances affecting users of Apple's Safari browser. It did so denying that it had violated its FTC consent decree.

Google declined to comment. But a week ago, the company asked for the dismissal of a similar case brought in the U.S. because its placement of cookies didn't really harm anyone.

In its filing, Google explains that what happened was an unforeseen consequence of developing a Google+ feature that allowed Google+ users to see personalized content. It did so by developing what it calls an Intermediary Cookie, to serve personalized content without breaching the anonymity that users are afforded on its ad network.

Apple's Safari browser defaults to blocking third-party cookies, which are used by ad networks. But it allows exceptions under certain circumstances. One exception is what's known as the "Safari One In, All In Rule," which allows all cookies from a given domain if one from that domain has already been stored in the user's browser. Another is the "Safari Form Submission Rule," which allows cookies from a third-party domain if the user submitted a form from that domain.

Google used the "Safari Form Submission Rule" to place its Intermediary Cookie and inadvertently opened Safari's doors to any cookie under the "Safari One In, All In Rule." As a consequence, Safari users began accepting cookies from Google's DoubleClick ad network despite representations to the contrary.

"To the extent that this unexpected outcome had any effect, it is only that a more tailored ad may have been displayed to the browser than otherwise would have been," Google said in its legal filing, noting that no specific harm had been documented as a result of its actions.

Dan Tench, a partner at Olswang, dismissed Google's explanation in an email. "We do not know what Google's response to our clients' complaints will be since we have received no reply to our letters," he said. "In any event, Google's explanation for its secret tracking would be no answer to our clients' complaints under U.K. law."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18238
PUBLISHED: 2020-02-26
Moxa ioLogik 2542-HSPA Series Controllers and IOs, and IOxpress Configuration Utility ioLogik 2500 series firmware, Version 3.0 or lower IOxpress configuration utility, Version 2.3.0 or lower. Sensitive information is stored in configuration files without encryption, which may allow an attacker to a...
CVE-2019-17274
PUBLISHED: 2020-02-26
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
CVE-2019-17275
PUBLISHED: 2020-02-26
OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers.
CVE-2020-3169
PUBLISHED: 2020-02-26
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root on an affected device. The vulnerability is due to insufficient validation of arguments passed to a spe...
CVE-2020-3170
PUBLISHED: 2020-02-26
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could expl...