Avast caught selling user data
forbes.com
forbes.com
https://www.vice.com/en_us/article/qjdkq7/avast-antivirus-se...
https://www.pcmag.com/news/the-cost-of-avasts-free-antivirus...
We can assume these may also be populated by automatically generated comments to suggest support or rejection of the content. Sometimes this leads me into [rabbit-hole] investigations through a user's post history if I am significantly moved by their angle(s).
I needn't read anything more than the title, as the meat content would likely just be an assimilation of empirical evidence and/or gossip. I'm not even going to bother turning off ad blocker or using archive.is with this one - in aggregate I just see it as yet another "distrust [insert internet company] with your data" offensive (defensive?) campaign.
I'm also not really sure what agenda the "modern, salaried digital author" is supposed to be succumbing to. Clickbait? If they're salaried then they aren't paid per click. Again, the journalist is a known employee of a known organisation. To think of anonymous commenters as more reliable feels a little baffling to me.
Everyone has an agenda, and everyone taking a voluntary action does so specifically in pursuit of an agenda.
The “impartial observer” is a sometimes-useful analytical fiction, not a thing that exists in the real world.
Having said that, I'm still glad Forbes picked it up. Forbes is read by the C-Suite of industries outside Tech. Vice and PC Mag? Not so much.
https://blog.avast.com/a-message-from-ceo-ondrej-vlcek
https://www.nasdaq.com/articles/avast-cuts-data-access-to-ju...
"For these reasons, I – together with our board of directors – have decided to terminate the Jumpshot data collection and wind down Jumpshot’s operations, with immediate effect." Ondrej Vlcek, CEO.
A lot of staff will be laid off, but I think this was the only good choice.
They sell which apps are installed on your phone and how often you use each [1], they sell your credit card transactions [2], they sell your emails [3], they sell your web browsing activity (jumpshot on this list) [4], and they sell your precise timestampped locations [5].
Senators are trying to get Yodlee investigated by the FTC [6] and they sell data to numerous companies. Second Measure's (YC S15) entire business model is cleaning up and reselling Yodlee's data.
[1] https://alternativedata.org/data-providers//category,app-usa...
[2] https://alternativedata.org/data-providers//category,credit-...
[3] https://alternativedata.org/data-providers//category,email-c...
[4] https://alternativedata.org/data-providers//category,web-tra...
[5] https://alternativedata.org/data-providers//category,geo-loc...
[6] https://thehill.com/policy/technology/478766-lawmakers-call-...
As I always read (and I don't agree much), everyone says "it's better to ask forgiveness than to ask for permission".
There you go.
GDPR has (intentionally?) a huge loophole: It is up to national agencies to enforce it, with no individual right to sue. These are heavily underfunded thus enforcement is weak to non-existent.
That said I assume nearly all companies out there are not in compliance. To the point of the article, privacy policies are mostly not detailed enough and it will take some time before companies come into compliance.
This is the trade off between a strict PCI level compliancy policy with a strict checklist of things to do and the "vague" GDPR compliancy which was created that way to be independent of technology changing over time. The downside is it's not clear how to be really compliant and companies do the very minimum on what they think they get away with.
Also there are so many huge violations, that yes, the data protection agencies can't cover everything, so they start from the top with the companies that get the most complaints (1&1 getting a 10M EUR fine) or have the biggest missteps. I assume the Buchbinder fine will be much larger than the 1&1 fine, and it will for the first time proof to companies that they are still responsible when they hire an IT company to manage their data - which was the point of the parent.
Until the GDPR arrived data leaks were just "Ooopsy" moments to companies. This culture has festered for decades and it will take some time to change.
And my comment was to the parent "and the information they sell to the end user? Is it secretly there deep in some terms of service" where the GDPR requires you to tell people what you do with the data in terms that they understand it without obfuscating the message or hand weaving. I would have wished that companies need to open their process directory to the public though.
Can't deny the irony in security software compromising security though.
They have a free product, but not everything they offer is free.
- https://www.avast.com/en-us/store
There are ways to provide a slimmed down version for people to use and try and that way they can advertise their other products inside their software where you can pay to use them.
They simply chose to do this. Regardless if it's paid or not, this was a business decision.
No, you are not, and you should not be expected to suspect that. This is moral fatalism.
So the business case doesn't sell the data (that's screaming for trouble), but rather uses it for their own ads.
So I disagree that "free" means "collects all your mouse clicks and sells them off to the highest bidder".
Wow, that's a nice way of blaming your users.
In this case Avast made only 5-10 % of revenue this way. The rest is made through various micro-transactions etc. IIRC.
Its like adware-blocker would install its own adware upon removal of all the others. But it would be a 'good' one ie for 'optimizing internet connection' or similar bullshit.
Trust is a finicky issue - long time to build, can be lost with 1 mistake. This event can kill Avast company in long term. Stupid, stupid move from owners, only explainable by greed, and not really justifiable.
What makes this newsworthy compared to the "regular" data collection done by Facebook and Google?
Users trust this kind of programs normally more. It's the fallacy of "oh they help us to be protected from bad guys so they can't be bad themselves"
Through many (most?/nearly all?) anti-virus companies are untrustworthy in my opinion so it's not really surprising for me.