Microsoft

The cost of Avast’s Free Antivirus: companies can spy on your clicks

Your antivirus should protect you, but what if it’s handing over your browser history to a major marketing company? Relax. That’s what Avast told the public after its browser extensions were found harvesting users’ data to supply to marketers. Last month, the antivirus company tried to justify the practice by claiming the collected web histories…

Your antivirus should protect you, but what if it’s handing over your browser history to a major marketing company?

Relax. That’s what Avast told the public after its browser extensions were found harvesting users’ data to supply to marketers. Last month, the antivirus company tried to justify the practice by claiming the collected web histories were stripped of users’ personal details before being handed off.

“The data is fully de-identified and aggregated and cannot be used to personally identify or target you,” Avast told users, who opt in to the data sharing. In return, your privacy is preserved, Avast gets paid, and online marketers get a trove of “aggregate” consumer data to help them sell more products.

There’s just one problem: What should be a giant chunk of anonymized web history data can actually be picked apart and linked back to individual Avast users, according to a joint investigation by PCMag and VICE’s Motherboard.

How ‘De-Identification’ Can Fail

The Avast division charged with selling the data is Jumpshot, a company subsidiary that’s been offering access to user traffic from 100 million devices, including PCs and phones. In return, clients—from big brands to e-commerce providers—can learn what consumers are buying and where, whether it be from a Google or Amazon search, an ad from a news article, or a post on Instagram.

The data collected is so granular that clients can view the individual clicks users are making on their browsing sessions, including the time down to the millisecond. And while the collected data is never linked to a person’s name, email or IP address, each user history is nevertheless assigned to an identifier called the device ID, which will persist unless the user uninstalls the Avast antivirus product.

For instance, a single click can theoretically look like this:

abc123x 2019/12/01 12:03:05 Amazon.com Apple iPad Pro 10.5 – 2017 Model – 256GB, Rose Gold Add to Cart

At first glance, the click looks harmless. You can’t pin it to an exact user. That is, unless you’re Amazon.com, which could easily figure out which Amazon user bought an iPad Pro at 12:03:05 on Dec. 1, 2019. Suddenly, device ID: 123abcx is a known user. And whatever else Jumpshot has on 123abcx’s activity—from other e-commerce purchases to Google searches—is no longer anonymous.

PCMag and Motherboard learned about the details surrounding the data collection from a source familiar with Jumpshot’s products. And privacy experts we spoke to agreed the timestamp information, persistent device IDs, along with the collected URLs could be be analyzed to expose someone’s identity.

“Most of the threats posed by de-anonymization—where you are identifying people—comes from the ability to merge the information with other data,” said Gunes Acar, a privacy researcher who studies online tracking.

He points out that major companies such as Amazon, Google, and branded retailers and marketing firms can amass entire activity logs on their users. With Jumpshot’s data, the companies have another way to trace users’ digital footprints across the internet.

“Maybe the (Jumpshot) data itself is not identifying people,” Acar said. “Maybe it’s just a list of hashed user IDs and some URLs. But it can always be combined with other data from other marketers, other advertisers, who can basically arrive at the real identity.”

The ‘All Clicks Feed’

The cost of Avast's Free Antivirus: Companies can spy on your clicks

Image: PC Mag

According to internal documents, Jumpshot offers a variety of products that serve up collected browser data in different ways. For example, one product focuses on searches that people are making, including keywords used and results that were clicked.

We viewed a snapshot of the collected data, and saw logs featuring queries on mundane,

Read More

Be the first to write a comment.

Leave a Reply

Microsoft

Microsoft fixes problem that let Edge replicate Chrome tabs without permission

Enlarge Microsoft reader comments 79 Microsoft has fixed a problem that resulted in tabs from Google Chrome being imported to Microsoft Edge without user consent, as spotted by The Verge. Microsoft has kept mum on the situation, making the issued update the first time Microsoft has identified this as a problem, rather than typical behavior

Microsoft fixes problem that let Edge replicate Chrome tabs without permission
Enlarge
Microsoft

reader comments

79

Microsoft has fixed a problem that resulted in tabs from Google Chrome being imported to Microsoft Edge without user consent, as spotted by The Verge. Microsoft has kept mum on the situation, making the issued update the first time Microsoft has identified this as a problem, rather than typical behavior for the world’s third-most-popular browser.

In late January, The Verge Senior Editor Tom Warren reported experiencing the puzzling Edge issue. After updating his computer, Edge launched with the tabs that Warren most recently used in Chrome. He eventually realized that Edge has a feature you can toggle, reading: “Always have access to your recent browsing data each time you browse on Microsoft Edge.” The setting is reachable in Edge by typing “edge://settings/profiles/importBrowsingData.” Interestingly, it allows Edge to import browsing data from Chrome every time you open Edge, but data from Firefox can only be imported manually. However, Edge was seizing Chrome tabs without this setting enabled. Others reported having this problem via Microsoft’s support forum and social media, as well.

The Edge setting as seen on a Windows 11 23H2 system running Edge 122. You can have data continuously imported from Chrome or on demand from Firefox, but other browsers don't appear.
Enlarge / The Edge setting as seen on a Windows 11 23H2 system running Edge 122. You can have data continuously imported from Chrome or on demand from Firefox, but other browsers don’t appear.
Andrew Cunningham

Microsoft didn’t respond to The Verge’s initial request for comment, but this week it released an Edge update that seems to address matters. Microsoft’s release notes from February 15 say:

Edge has a feature that provides an option to import browser data on each launch from other browsers with user consent. This feature’s state might not have been syncing and displaying correctly across multiple devices. This is fixed.

Microsoft seems to be saying that the status (enabled or disabled) of Edge’s importing data ability wasn’t syncing correctly across people’s Microsoft devices. However,

!–>
Read More

Continue Reading
Microsoft

Microsoft sure seems to be thinking about some sort of portable Xbox

Enlarge / A demo of “Project Xcloud” streaming running on a mobile device, circa 2019. reader comments 117 Further ReadingAfter weeks of rumors, Microsoft says four games are going to “other consoles” Yesterday’s news that four unnamed Microsoft games are coming to “the other consoles” was a bit anticlimactic after weeks of now-refuted rumors about

A demo of "Project Xcloud" streaming running on a mobile device, circa 2src19.
Enlarge / A demo of “Project Xcloud” streaming running on a mobile device, circa 2019.

reader comments

117

Yesterday’s news that four unnamed Microsoft games are coming to “the other consoles” was a bit anticlimactic after weeks of now-refuted rumors about games like Starfield and Indiana Jones and the Great Circle going to the PlayStation 5. Yet even as those rumors die, Microsoft seems to be actively feeding new rumors regarding plans for some sort of portable gaming device.

In an interview with the Verge accompanying yesterday’s “multi-platform” business announcement, Microsoft Xbox CEO Phil Spencer was asked directly about any handheld hardware plans, including his recent penchant for liking some social media posts discussing handheld game consoles. While Spencer said he had “nothing to announce,” he talked up a lot of other handheld gaming hardware when talking about how Xbox could capture more “player hours.”

So, okay, what keeps people from playing certain hours? Well there’s some sleep, school, and kind of normal life, but some of it is just access. Do I have access to the games that I want to play right now? Obviously we’re kind of learning from what Nintendo has done over the years with Switch, they’ve been fantastic with that. So when I look at Steam Deck and the ROG and my Legion Go, I’m a big fan of that space.

Spencer went on to say that “real work” still needs to be done to get Windows to work better with controller input and on smaller 7- to 8-inch screens. That’s the kind of OS work we’d note would be very useful if Microsoft is planning to release a Windows-based gaming portable of its own (we’re assuming Microsoft would not want to ditch Windows in favor of SteamOS). “That’s a real design point that our platform team is working with Windows to make sure that the experience is even better,” he said.

Advertisement

Spencer gave even more direct hints along the same lines in an interview with Bloomberg, where he

!–>
Read More

Continue Reading
Microsoft

Diablo 4 will make a hellish addition to Xbox Game Pass this March

Diablo 4 is coming to Game Pass this March. Xbox’s Sarah Bond made the announcement this evening, as part of the company’s business update podcast. In a follow up post on social media, Xbox said Diablo 4’s upcoming Game Pass debut is part of Microsoft’s “promise to offer Activision Blizzard games” on the subscription service…

Diablo 4 is coming to Game Pass this March.

Xbox’s Sarah Bond made the announcement this evening, as part of the company’s business update podcast. In a follow up post on social media, Xbox said Diablo 4’s upcoming Game Pass debut is part of Microsoft’s “promise to offer Activision Blizzard games” on the subscription service…
Read More

Continue Reading
Microsoft

How to get antivirus software for cheap

Plenty of folks use Microsoft Windows’ built-in antivirus protection, but sometimes you need more than what it offers. Security suites from independent companies like Bitdefender, Norton, and AVG can make it easier to stay on top of online security, by providing expanded and additional features that shield you more thoroughly…

Plenty of folks use Microsoft Windows’ built-in antivirus protection, but sometimes you need more than what it offers. Security suites from independent companies like Bitdefender, Norton, and AVG can make it easier to stay on top of online security, by providing expanded and additional features that shield you more thoroughly…
Read More

Continue Reading