Millions of email addresses leaking to advertising and analytics companies
medium.com
medium.com
‘This type of email user data in a URL bar synced into Javascript pixels is most typically blocked by a regular person through “Ad blockers” or through browsers like Safari, Brave, and Firefox — those browsers use Javascript/cookie blocking as a default features to protect users (each browser handles it slightly differently). This breach and research included here would impact all Chrome users of these websites who went through these specific user flows and who didn’t proactively block all Javascript (a rarely used option) or use a Chrome “Ad blocker” extension that blocked this type of Javascript. Some people using the other “safe” browsers (Safari/Brave/Firefox) could have been protected from the leak due to their 3rd party Javascript requests being blocked.’
Original title too long. It was: The 2020 URL Querystring Data Leaks — Millions of User Emails Leaking from Popular Websites to Advertising & Analytics Companies
The meat in the story, is a real problem - irresponsible mingling of PII in analytics data.
So as soon as there was an @\S+\. in a url we were anonymizing the full url. Customers were not happy though
But I can tell you that this was present on a lot of websites including Bank websites
1. Do nothing until it gets reported in a large dead tree medium.
2. Blame the reporter for not understanding technology.
3. Deny it happened.
4. Say it only affected a small subset of people.
5. Say it was only a single rogue "trusted partner" involved.
6. Put out the boilerplate "We can do better" press release.
7. Keep cashing the checks.
8. Lather. Rinse. Repeat.
So, basically any 3rd party analytics has the ability to do this, query string or no?
Each email adhering to some rule (magicmarker[a-f0-9]+)goes to my account.
Each registration anywhere gets unique email address generated as magicmarker<b64(hash(domain+salt))>@mydomain.com Salt is there to keep it unguessable.
When I get any spam, I can redirect it to /dev/null and verify from where it came from to sent hate mail to domain owner or whatever.
0 spam. 0 tracability. Ability to track who sold/leaked my mail address.
Several email providers treat a + symbol as the end of the first part of the address and ignore everything between it and the @.
I think the responder’s point was that analytics providers just ignore things after a + too
IME: I’ve never had anyone remove it (although some don’t accept it and others will have bugs that result in an unusable account if you register with it.) I used one with the company I most recently interviewed at (they used a third party service for the HR site and I’ve had trouble with sites like that selling my email address which is just so enraging honestly.) Every. Single. Time. I logged in to fill out a form after getting hired I had to call HR and have them reset my account because of some weird bug.
Though similarly, email usernames ('local part') are case sensitive but I've never encountered a mail server where this was the case. I imagine if a nefarious party stripped the markers, they'd lose the tiniest percentage of their audience that way.
(Aside: Your own approach to using + is quite clever as it's the total opposite to most users, so you'll see who pulls this trick ;-))
The one I use (purelymail.com) allows for underscores to serve this purpose, which will never be stripped. It's also super cheap (less than $1/month), though because of its low volume and AWS IP, my messages have a problem with getting marked as spam. The next comparable service I found that offered effectively infinite addresses was $50/year, so I fall back to gmail if I really need to send email.
they don't know the "higher engagement" is because the mobile user's browsers are literally frozen
and the A/B test says "keep going with the B test!" "do it again!" in a tree that keeps evolving down one side of the graph towards more and more obnoxious experiences that the company doesn't even know is obnoxious
given the misaligned incentives I think this is also an area California can regulate or threaten to regulate, I don't like "tech regulation" but I can't think of any other party to curb the behavior. If you like "private sector solutions" more than "government solutions" then Apple and Google can pull the rug under all the other company's feet by crashing sites on the user's phone using other user's crowd sourced data, or making certain analytics packages not run, etc.
Pretty common to find large websites that just happen to not work right in browser configurations that don't match their developer configuration even if they aren't obscure.
The website isn't exactly quick to load, but that appears to be because it is very large.
The clients had forms data being sent as get-requests and from there email addresses and even more personal data in the URL (street, date of birth, and even more) was being transmitted into the analytics tools and also into marketing tools.
Regarding GDPR this is a breach and needs to be communicated to officials as well as the people affected.
Even a bank was affected by this type of implementation when customers wanted to open an account or make a loan application.
It shouldn't require much experience to know when to use POST or some other HTTP verb - banks certainly have no excuse.
Marketing 101: User actions should take as little clicks as possible, so the action should be performed as soon as the user clicks the (GET) link.
Nope, some email clients might prefetch urls in email for various reasons. You should absolutely NOT do this (unless you are decitefully trying to game you engagement metrics.) The only case where you might be able to get away with it is when the user has an active login session that you can verify prior to performing the action.
I always ask the sales person where the hell they found the email because I just used it once somewhere long time ago.
One could argue Advertising shouldn’t exist or that Google should not store anything. But the GDPR argument is BS, although admittedly legal.
It is like throwing a small rock in to the neighbors yard and asking them to retrieve it for you.
CCPA is not nearly as strict as the GDPR and it is not illegal, unfortunately.
I feel this article really stunk of an attempt to over-sensationalize some sloppy coding that is probably happening on 50% of the websites in the world. To think otherwise is nothing but a utopian view of reality.
“Do you have each other’s emails?” is real and normal usage.
It’s fine to “get off my lawn” this, but it won’t help solve the data leak posted here.
(BTW I think it sucks you're getting hammered by downvotes FWIW I upvoted you just to counter balance them.)
I'm not for a moment suggesting this isn't bad but if you run about warning people of something important it helps to be clear and not risk exaggeration / ambiguity (or you play into downplayera hands and potentially waste the time of honest folk)
The title is plain wrong.
I which people would be a bit more clear in the language they use, especially if it's about vulnerabilities.
To write "email" is correct. It would be more precise to write "email address" to make the distinction from "email message." But it is not the cultural norm to equate "email" with "email message" as you seem to do.
Juuust kidding. My point is: they probably do not have the used more clear language, because their internal concept of what email is is so fuzzy. That would be my guess anyway.