Google Tracked iPhones, Bypassing Apple Browser Privacy Settings
online.wsj.com
online.wsj.com
I don't use an iPhone, but I imagine if it's like other browsers, there's some setting that says:
[x] Accept cookies from sites [ ] Accept third party cookies
When I don't check the second box, it doesn't mean "Don't accept cookies, unless condition X is true", e.g. the web site implemented a popular hack. It means really don't accept third party cookies, and I don't give a shit if the +1 button breaks.
It doesn't sound like Safari's behavior on the hidden forms is intentional. It sounds like a bug, but it's irrelevant either way. I hope Apple patches this soon and forces people to opt in to third party cookies.
I'm glad that they actually set the default to reject them (a funny contrast to the address book policy). Firefox allows third party cookies by default because I always have to turn it off when setting up the browser on a new PC.
Not even the most rabid Google apologists can spin this one.
The WSJ also ran a blog post about this which says (at the very end):
"An update to the software that underlies Safari has closed the loophole that allows cookies to be set after the automatic submission of invisible forms. Future public versions of Safari could incorporate that update. The people who handled the proposed change, according to software documents: two engineers at Google."
"software documents" is linked to http://trac.webkit.org/changeset/92142
So it appears that Google engineers have already closed this loophole.
This somehow reminds me of the time when Chrome marketing ended up paying for links to their site, and then the Web search group had to punish them with a demotion.
I don't think that "unlimited user tracking by advertising networks, regardless of good-faith user efforts to limit data tracking" was at all part of any tacit agreements reached by the internet community. The principle that communication networks should be transparent in how they operate, and allow users of the network to meaningfully control their interactions with them is a meta-principle that is pretty clearly implicit in the design of the internet, and I don't think the current widespread use of tracking technologies and data analysis without informed user consent is consistent with those principles.
"It's a force of nature" is only a good argument against a policy when it is accompanied by other valid arguments. There are many things which are "only human nature" or "a force of nature" which for the sake of society and/or personal liberty we restrict.
Saying "it's only a force of nature" won't get you far with a judge. And telling people that they can't use the internet if they value their privacy is an unreasonable restriction on personal liberty. Period.
I agree that Google can user track, but only so far, and if they need to go to such extremes, we need rules, guidelines or even laws to draw the line very starkly.
special computer code is my favorite
I wonder if anyone can throw some light on this matter if there's a way they could be doing this "by mistake", or "unintentionally" or something else. For example could the +1 button be a cause? I don't know but I'm curious.
Every other major browser vendor.
Just because everybody is making money selling user information and attention to the advertisers does not negate the fact that Apple's choice is sitting on the safer side for user privacy. And you know what's also common practice? Scrap user's address book and beam it up the cloud.
Apple is at fault in both cases for failing to safeguard users from the abusers.
Path and Google are the abusers.
And I think there might be a non subtle, non nuanced difference here.
The bug, to be specific, is to submit a form using POST in an iframe; the POST response is then able to set cookies. In this case they did the POST in a hidden iframe with no data.
Just asking: Isn't it a kind of a subtle lie to say that advertising cookies do not collect personal information? Of course, there isn't a personal information in the cookie itself, but that cookie is used to identify my profile in those third party databases, so they know who I am, and that profile already can contain anything they collected about me in the past, including personal information.
UPDATE: This article seems to confirm that the Google's spokesman statement is indeed misleading -> http://cyberlaw.stanford.edu/node/6701
If you're on a Google property, Google has every right to serve all the DoubleClick cookies it likes. All the WSJ's witch-hunt + Safari's pain-in-the-ass non-standard defaults mean is that Google will have to do the work to serve its DoubleClick cookies off the google.com domain - which, as people switch more and more to mobile, they will inevitably do.
This leaves us with the choice of either using the workaround, or not providing a consistent experience that users expect.
If Safari worked like every other major browser in this regard-- allowing users to OPT-IN to the stricter cookie policy--then WSJ would be right in nailing Google for working around it.
I think Google did nothing wrong. They worked around a browser's non-standard default behavior, which is something we all do multiple times a day. Only when non-standard behavior is OPT-IN is there willful disregard for the user's intent in employing a work-around.
If so, I strongly disagree. Cars have a "locked" and "unlocked" state. They provide a button, which anyone can locate, for the owner to toggle the state. When you try to open the door, and it won't budge, it's immediately obvious that the door is locked. This is nothing at all like what happens when Safari disables 3rd party cookies by default.
But if you want a CAR analogy... It's like making a car that ships without windshield wipers pre-installed. You justify this by saying it makes it harder for passers-by to put ads on your car. And 90% of the people who drive the car can't figure out WHY they can't see the fracking road when it's raining!
This is worse because I turn off third party cookies in Firefox. On an iPhone, I would have no way to turn off third party cookies (the ones that are submitted using the hack).
Should it start ignoring robots.txt files because some people may have inadvertently cut&pasted stricter ones than they might really want?
Shame on Apple.
Since you clearly can't trust app developers or websites to not try and exploit your information, you HAVE to trust your device to do what it says. The fact that this was exposed by the standard +1 button doesn't exactly mean it was difficult to do. It wasn't some 0-day exploit that they're using, it's a failure of the browser.