{"id":6952,"date":"2017-11-27T15:47:39","date_gmt":"2017-11-27T15:47:39","guid":{"rendered":"https:\/\/ounews.co\/?p=6952"},"modified":"2017-11-27T15:47:39","modified_gmt":"2017-11-27T15:47:39","slug":"websites-watch-every-move-ignore-privacy-settings","status":"publish","type":"post","link":"https:\/\/www.open.ac.uk\/blogs\/news\/science-mct\/computing-communications\/websites-watch-every-move-ignore-privacy-settings\/","title":{"rendered":"How websites watch your every move and ignore privacy settings"},"content":{"rendered":"<p>Hundreds of the world\u2019s top websites routinely track a user\u2019s every keystroke, mouse movement and input into a web form \u2013 even before it\u2019s submitted or later abandoned, according to the <a href=\"https:\/\/freedom-to-tinker.com\/2017\/11\/15\/no-boundaries-exfiltration-of-personal-data-by-session-replay-scripts\/\">results of a study<\/a> from researchers at Princeton University.<\/p>\n<p>And there\u2019s a nasty side-effect: personal identifiable data, such as medical information, passwords and credit card details, could be revealed when users surf the web \u2013 without them knowing that companies are monitoring their browsing behaviour. It\u2019s a situation that should alarm anyone who cares about their privacy.<\/p>\n<p>The Princeton researchers found it was difficult to redact personally identifiable information from browsing behaviour records \u2013 even, in some instances, when users have switched on privacy settings such as <a href=\"https:\/\/www.eff.org\/issues\/do-not-track\">Do Not Track<\/a>.<\/p>\n<p>The <a href=\"https:\/\/webtransparency.cs.princeton.edu\/no_boundaries\/session_replay_sites.html\">research found<\/a> that third party tracking services are used by hundreds of businesses to monitor how users navigate their websites. This is proving to be increasingly challenging as more and more companies beef-up security and shift their sites over to <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Security\/Transport_Layer_Security\">encrypted HTTPS pages<\/a>.<\/p>\n<p>To work around this, session-replay scripts are deployed to monitor user interface behaviour on websites as a sequence of time-stamped events, such as keyboard and mouse movements. Each of these events record additional parameters \u2013 indicating the keystrokes (for keyboard events) and screen coordinates (for mouse movement events) \u2013 at the time of interaction. When associated with the content of a website and web address, this recorded sequence of events can be exactly replayed by another browser that triggers the functions defined by the website.<\/p>\n<h2>Enhanced user experience<\/h2>\n<p>What this means is that a third person is able to see, for example, a user entering a password into an online form \u2013 which is a clear privacy breach. Websites that employ third party analytics firms to record and replay such behaviour is, they argue, in the name of \u201cenhancing user experience\u201d. The more they know what their users are after, the easier it is to provide them with targeted information.<\/p>\n<p>While it\u2019s not news that companies are monitoring our behaviour as we surf the web, the fact that scripts are quietly being deployed to record individual browser sessions in this way has concerned the study\u2019s co-author, Steven Englehardt, who is a PhD candidate at Princeton.<\/p>\n<figure><iframe loading=\"lazy\" src=\"https:\/\/www.youtube-nocookie.com\/embed\/l0Yc8s0DTZA?wmode=transparent&amp;start=0\" width=\"440\" height=\"260\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/figure>\n<figure><span class=\"caption\">A website user replay demo in action.<\/span><figcaption><\/figcaption><\/figure>\n<p>\u201cCollection of page content by third-party replay scripts may cause sensitive information, such as medical conditions, credit card details, and other personal information displayed on a page, to leak to the third-party as part of the recording,\u201d <a href=\"https:\/\/freedom-to-tinker.com\/2017\/11\/15\/no-boundaries-exfiltration-of-personal-data-by-session-replay-scripts\/\">he wrote<\/a>. \u201cThis may expose users to identity theft, online scams and other unwanted behaviour. The same is true for the collection of user inputs during checkout and registration processes.\u201d<\/p>\n<p>Websites logging keystrokes has been an issue known for a while to cybersecurity experts. And Princeton\u2019s empirical study raises valid concerns about users having little or no control over their surfing behaviour being recorded in this way.<\/p>\n<p>So it\u2019s important to help users control how their information is shared online. But there are increasing signs of usability trumping security measures that are designed to keep our data safe online.<\/p>\n<h2>Usability vs security<\/h2>\n<p>Password managers are used by millions of people to help them easily keep a record of different passwords for different sites. The user of such a service only needs to memorise one key password.<\/p>\n<p>Recently, a <a href=\"http:\/\/oro.open.ac.uk\/46871\/\">group of researchers<\/a> at the University of Derby and the Open University discovered that the offline clients of password manager services were at risk of exposing the main key password when stored as plain text in memory that could be sniffed or dumped by whole system attacks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/counter.theconversation.com\/content\/87962\/count.gif?distributor=republish-lightbox-basic\" alt=\"The Conversation\" width=\"1\" height=\"1\" \/>User experience is not an excuse for tolerating security flaws.<\/p>\n<p>Written by <a href=\"https:\/\/theconversation.com\/profiles\/yijun-yu-120245\">Yijun Yu<\/a>, Senior Lecturer, Department of Computing and Communications, <em><a href=\"http:\/\/theconversation.com\/institutions\/the-open-university-748\">The Open University<\/a><\/em><\/p>\n<p>This article was originally published on <a href=\"http:\/\/theconversation.com\">The Conversation<\/a>. Read the <a href=\"https:\/\/theconversation.com\/how-websites-watch-your-every-move-and-ignore-privacy-settings-87962\">original article<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hundreds of the world\u2019s top websites routinely track a user\u2019s every keystroke, mouse movement and input into a web form \u2013 even before it\u2019s submitted or later abandoned, according to the results of a study from researchers at Princeton University. And there\u2019s a nasty side-effect: personal identifiable data, such as medical information, passwords and credit [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":6953,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[496,2115,2464],"class_list":["post-6952","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computing-communications","tag-computing","tag-stem","tag-yijun-yu"],"_links":{"self":[{"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/posts\/6952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/comments?post=6952"}],"version-history":[{"count":0,"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/posts\/6952\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/media\/6953"}],"wp:attachment":[{"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/media?parent=6952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/categories?post=6952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.open.ac.uk\/blogs\/news\/wp-json\/wp\/v2\/tags?post=6952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}