View Single Post
Old 07-13-2013, 07:12 PM   #1
MattW
Connoisseur
MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.MattW ought to be getting tired of karma fortunes by now.
 
Posts: 91
Karma: 2129612
Join Date: Dec 2007
Location: Vienna, Austria
Device: Sony PRS-650, Sony PRS-T1, Sony PRS 505, Sony PRS T2, Kindle PW
Amazon outdoing PRISM

So Amazon's 1Button App for Chrome and Firefox not only sends each and every website you visit to Amazon servers, it also reports your Google searches (plus results) to Amazon and Alexa.

And despite what their privacy statement says, because this data is sent to an Amazon URL your browser automatically and very helpfully includes the cookies Amazon uses to identify your account, so this information is everything but anonymous -- in fact, it allows Amazon to store your entire browsing history, Google searches (and, as a bonus, execute arbitrary Javascript code on any third party website).

Now, I'm not getting into the whole Is-Amazon-Evil-Or-Not Debate (in fact, I think very highly of their customer service and have been a loyal customer for years), but whichever way you look at it, this is just wrong.

The apologists might say that Amazon doesn't make use of this data, but why does it then collect it in the first place? And by doing so compromises its customers privacy and security since the 1Button App can easily be modified to allow third parties to spy on you (and even read the content of your SSL encrypted HTTPS webtraffic) as shown here:

http://blog.kotowicz.net/2013/07/jea...-1-button.html

Matt
MattW is offline   Reply With Quote