Netimperative
Netimperative
  • Home
  • Ads
  • Content
  • Mobile
  • E-commerce
  • Social
  • Regulation
  • Video
  • Viral
Menu
  • Apple
  • Amazon
  • Facebook
  • Google
  • twitter
  • WhatsApp
  • YouTube

Which? Magazine finds IE 9’s anti-tracking feature ‘flawed’

March 21, 2011

Consumers are being warned to think twice before enabling Microsoft’s anti-tracking feature in Internet Explorer 9 (IE9) to their browsers after a potential flaw in the technology was discovered by Which? Computing.


The warning was issued by a lead researcher at Stanford University following tests carried out by Which? Computing that found a potential flaw in the way the Tracking Protection Lists (TPLs) work. TPLs play a central role in how the anti-tracking feature in IE9 works.
IE9 uses TPLs to give users control over third-party content that can have an impact on their online privacy. It does this by blocking web content, such as Flash cookies, web beacons and images, from tracking web browsing behaviour.
How they work
To enable the anti-tracking feature in IE9, users have to download a TPL. Which? Computing found problems if users download and use more than one TPL – creating conflicts between the lists and potentially preventing the anti-tracking feature from operating properly.
Microsoft offers IE9 users access to five different TPLs – one each from Abine, EasyList and TRUSTe and two from PrivacyChoice – which can be downloaded via Microsoft’s website. Consumers can install multiple TPLs and use them alongside their own personalised filtering list.
TPLs contain details on what content to ‘allow’,
and what content to ‘block’ – effectively giving control over how content such as Flash cookies track browsing behaviour.
However, a Which? Computing study found that when a user has downloaded multiple TPLs, all of the rules from all of the TPLs are grouped together into a single list where an ‘allow’ takes precedence over a ‘block’.
For example, a consumer may choose to install two TPLs: one by EasyList and one by TRUSTe. The EasyList TPL might ‘block’ web beacons, whereas the TRUSTe TPL might ‘allow’ them. In this case, the web beacons would be ‘allowed’.
The flaw could mean that users are unknowingly having their web behaviour tracked, despite using the anti-tracking features in IE9.
Which? says
Dr Rob Reid, a senior Which? Policy advisor, said: ‘We’re disappointed with the way these lists work, and feel consumers who install multiple lists could be left with a false sense of security.’
Jonathan Mayer, lead researcher on Stanford University’s ‘Do Not Track’ Project, said the findings by Which? Computing could leave IE9 users open to being tracked: ‘The issue here is that if a user installs TPLs that have ‘allows’ for web content that should be blocked, they leave themselves vulnerable to being tracked,’ he said.
‘The user has to decide which list to trust and get it right. I would urge users to think twice before installing a list, and to consider who it is they trust to compile a list that protects them, and to trust they keep updating the list. My concern with TPLs is that users shouldn’t have to know the difference between a ‘block’ and an ‘allow’ rule. They should just be able to opt out.’
He added: ‘The TRUSTe TPL is almost exclusively what we’d call an ‘allow’ list. It ‘allows’ content from Acxiom, a major data aggregator. If you want to stop your online behaviour from being tracked, the last thing you’d want to do is install a list that guarantees that Acxiom can track you.’
Microsoft responds
Microsoft has acknowledged our findings. Dean Hachamovitch, corporate vice president, IE, said: ‘To your premise, ‘deny’ does equal block, or ‘protect’ from potentially bad things. ‘Allow’ is also essential in order to express relationships such as ‘this content but not that, or none of these except for those’.
‘Saying ‘allow’ beats ‘deny’ is a good bit of wordplay. Reversing it increases the difficulty for well-intentioned list authors to express complex relationships. I understand that this may seem counterintuitive [but] it’s not a unique occurrence in the application of technology to safety.’
He added: ‘The primary consumer role here is choosing a list author they trust. Auditing any such list requires privacy expertise as well as technical acumen. Propping up more checkboxes is unlikely to actually help consumers.’
Which?’s Reid added: ‘We’d like Microsoft to re-evaluate its ‘allow’ and ‘block’ system since we find this all a bit confusing and are worried that consumers will too. Requiring users to understand and apply a block and allow rule across multiple TPLs seems an overly complicated way of opting out of being tracked.
‘We are also concerned that the lack of monitoring and mediation of the TPLs leaves the system and consumers vulnerable to abuse.’
Source: www.Which.co.uk

Uncategorized content, images, Microsoft, Privacy, security

Archives

Tags

advertising agencies Amazon analytics Android Apple apps Australia BBC brands Brazil broadband China Christmas comScore content digital marketing ecommerce email Entertainment Europe Facebook France games Germany global Google government images infographic local marketing media Microsoft music Privacy retail Search security smartphones technology Twitter UK video YouTube

Recent Posts

  • Top six Valentine’s Day ads for 2022
  • 2021 Halloween: digital marketing campaigns we loved this year
  • Empowering employees; the critical link between EX and CX
  • Investing in in-app social features is a must in a world that is crying out to be connected
  • QR codes, Gen Z and the future of OOH

Copyright © 2025 Netimperative.

Magazine WordPress Theme by themehall.com

We use cookies to improve the website and your experience. We’ll assume you’re okay with this, but you’re welcome to opt-out
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT