Mixpanel analytics accidentally slurped up passwords
techcrunch.com
techcrunch.com
I've used Mixpanel as a developer and also been disturbed how they combine analytics data with the user profiles creating really detailed profiles what they do on their website. Even that wouldn't be such a big deal if it was obvious to the user but really there is no law stopping companies from doing it. I hope GDPR will clear this thing out in the future and companies can't operate without user's direct consent and opt-in becomes the standard instead of opt-out.
I get the outrage at being tracked by third parties across the web, but that’s different from making it illegal for any website to track any of your activity on their site.
The days of the Internet being the Wild West are coming to a close, and not a moment too soon.
Side note: it’s disturbing it took Mixpanel nine months to notice they were ingesting sensitive data. Turn on All The Ad Blocking.
If we have to break the web, we break the web. Digital rights supercede tech profits.
I still don't understand how they plan to enforce this law worldwide, though. The EU is powerful, sure, but if I was China I might just tell them to piss off when they come knocking.
It's not really Chinese companies doing the tracking, it's American ones.
The EU is simply too big a market for them to ignore.
(The trick depends in part on companies wanting access to EU more than EU wanting a particular company to sell to its people.)
Why you do need consent for is to gather unneeded personal data or to send personl data to 3rd party providers for processing that is not essential to your service.
You are not allowed to deny people access to your site based on lack of this kind of consent.
If you collect and process PIIs of EU citizens, the EU will do whatever it goddamn likes with you, which currently means some pretty high fines.
Here's roughly what you must comply by, if you're not blocking the whole of the EU.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
> Avoid making consent to processing a precondition of a service.
Does it mean I have to ensure my users can use the service even if I'm not allowed to "process" their data? I assume this must mean "processing" data for reasons not directly connected to the actual service. (E.g. using the data to gather business intelligence or sell it to third parties)
You're wrong.
You see, the "Cookie Law" was a test. Can a gentle legal nudge make the web self-regulate into respecting its users? It turned out that no, it can't. Remember, you only have to show a cookie warning if you're doing something inherently user-hostile. That almost every site has one only shows how little anyone cares. Well, the gloves are off, GDPR is the next iteration, designed to make people care. If you're doing something shady, GDPR will make you explain, in points, how exactly are you going to fuck the user over, and make you request explicit consent for each single fuckery you want to do - and does not let you make the service conditional on the user bending over. The user is supposed to be able to tell "no" to everything and still use the service.
Whatever pains this creates for businesses on-line, frankly, it's deserved.
I don't see how the informed consent bit wont become the same mindless box-ticking exercise web users already undertake?
You can "use" the service, but it'll be positioned that it's not an option but to accept.
I feel this time around, such a construct will open the company to legal liability, and there's plenty of people (myself included) who will gladly report shady practices like that. EU seems really into making consent actually meaningful, so why I can't be sure, I'm convinced the "mindless box-ticking exercise" scenario won't play out.
IANAL, but I also think a lot of companies will be well argued on using "Legitimate interests" as a basis for processing instead for a lot of things.
Then others will argue on "Consent should not be a precondition of signing up to a service unless necessary for that service." and use "processing is necessary for the performance of a contract" as the basis (especially if there's money involved).
Obviously, the large companies will be able to handle this better and employ decent legal teams to argue for using those basis' - not because they're "good actors", just they've got the cash and knowledge to argue better. It's the smaller business owners (who as with VAT MOSS) are going to be screwed over the most.
I sincerely hope the fines will put a couple of companies out of business as a warning to the remainder.
But other small and medium websites all over the world that don’t have EU operations will mostly just ignore this, as they should. It’s going to be nearly impossible to enforce for those companies, it’s a violation of national sovereignty, and half the regulations don’t even make much sense. How exactly are you supposed to avoid storing the personal information of EU residents when personal information includes IP address and that EU resident can be anywhere in the world? Or you have to delete the info if asked, but other laws require you to keep it? Now every medical facility in the world has to have entire new compliance procedure just in case an EU resident stumbles through their door?
Yeah, color me skeptical. You can pass any law you want, but it’s only as good as your ability to enforce it. If you think the US is going to help the EU collect multiple-million-dollar fines from some small business in Oklahoma, well, you’re going to be very disappointed.
We’ll see, but I doubt that in a couple years things will have changed all that much.
Maybe, but the GDPR also has much higher fines when it comes to a data breach. So there's quite an incentive for companies to care a little more about user privacy.
Yeah but soon adblock and 3rd party adaptation will reach critical mass, we will start to see, 3rd party tools integrated as 1st party (with subdomains etc) then adblocks will be not much efficient
It's good the GDPR is coming on the data collection front, because the only way you can stop this fuckery is through out-of-band threat of legal problems.
As well, serving malware 1st party may have some legal consequences if got caught.
Why would they inform the end user though ? The end user doesn't even know what Mixpanel is and would be confused if they emailed them directly. Informing the clients (BMW, Samsung etc.) is the right thing to do which they did. I'm sure they had to do a postmortem and make sure a fix is in place before informing the clients and urging them to update the SDK.
So that the end users can grasp to which extent their privacy was violated? If a third-party I never heard of, contacted me and told me they got my login details, I would be bloody furious. And that is a good thing if people are enabled to this.
They did minimize how many people they told. Lol.
In the words of Nixon they “Earned everything [they] got.”
"What're all these batteries and horses and staples doing coming up in my advertising???"
Isn't the underlying problem with the web browser that allows this, or are browsers just fundamentally broken when it comes to protecting users?
The core technical problem is that scripts can read data. But that's kind of their job. "Solving" that would require to reduce the functionality of webpages.
The core social problem is that people include third-party analytics and advertisements. Solving that would require to destroy the entire adtech industry.
I'm all for the latter solution.
There is no way to win this fight except regulations and oversight
The great thing is that it's so quick and easy to enable/disable/customize too. For example, I've identified two scripts that block websites from loading when it doesn't get loaded... so I allow those to load on every website -- no ads, but the site still loads.
Mixpanel is blocked by default in the blacklist that I subscribe to.
I saw the adiode.com one on https://www.merriam-webster.com if you want to have a look for yourself.
I hit that one pretty much every other day somewhere; I wonder, how did it spread so quickly? It must be linked to by some popular ad network or analytics package.
I haven't found any indication on how to do it "legally" or a small "howto". I'm also not interested in an IBM solution that would cost me 10 times my earnings
Compiling a list of all personal data currently located in your systems and making sure you have a legal basis for each item, goes a long way towards compliance (though of course this is not all you need to do)
- WooCommerce on url xxx: phone number, email,name & address. Google Analytics & facebook Pixel. Requirement for e-commerce fullfillment and analysing website performance / ad performance.
- Mailchimp : email and name, when accepting WooCommerce "Terms and conditions" n°2. Requirement for recurring ecommerce updates/changes of new products.
- OpenERP: ( invoicing - local network) - Firstname, lastname, address, email, phone, orders. Requirement for invoicing
Somehow i can't believe that would be sufficient.
I really doubt most small-medium businesses without ties to the EU are going to pay any attention. Just like VAT actually.
With Mailchimp you probably need to let your customers separately opt into their e-mail being used for marketing purposes, as again that use is not strictly required to fulfil their order.
Same with any other information - your customers need to be aware of all the ways you will use their data. If any uses are not covered by a legal agreement, there needs to be an option to opt-in.
Here's the commit in question: https://github.com/mixpanel/mixpanel-js/commit/98a1845c5c55f... - as referenced here: https://github.com/mixpanel/mixpanel-js/issues/164 .
The meat of it is that the check of the type of the <input> node to ensure it's not "password" or "hidden," now wraps the iteration over attributes as well as inclusion of the value.
That heuristic, though, is far from perfect: see, for instance, https://www.troyhunt.com/bypassing-browser-security-warnings... . And even if you're not doing something funky like that, you're not out of the woods. For instance, it's highly likely that a site collecting "secret answers" in plaintext input fields (for password resets) would leak that information to Mixpanel if Autotrack were turned on. This commit does nothing to change that scenario. And while Autotrack is now opt-in, it can be done entirely by a business team with zero interactions with engineering, if (for example) a tag management solution is set up: see https://mixpanel.com/blog/2015/03/27/community-tip-implement... and https://help.mixpanel.com/hc/en-us/articles/115004613366-Wha...
SaaS analytics companies, especially those able to slurp up everything into a managed data lake and provide perfect retroactive analysis capabilities, provide a great experience compared to self-hosted solutions, but it's inevitable that you'll end up giving them more information than you'd originally planned. For many businesses, that's the right decision, but it should be one made with eyes wide open.