![]() |
#1 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 11,732
Karma: 128354696
Join Date: May 2009
Location: 26 kly from Sgr A*
Device: T100TA,PW2,PRS-T1,KT,FireHD 8.9,K2, PB360,BeBook One,Axim51v,TC1000
|
candy.js spyware embedded in ebooks
From Digitalbookworld:
http://www.digitalbookworld.com/2015...about-readers/ Quote:
Nice of them to warn us. They don't say what format ebooks or what vendors carry this spyware so anybody with randy penguin UK titles run into this? |
|
![]() |
![]() |
![]() |
#2 | |
Connoisseur
![]() ![]() Posts: 81
Karma: 110
Join Date: Oct 2012
Device: Kindle, Paperwhite, Oasis, Kobo Elipsa 2E
|
Quote:
|
|
![]() |
![]() |
![]() |
#3 |
A Hairy Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,269
Karma: 20170561
Join Date: Dec 2012
Location: Charleston, SC today
Device: iPhone 15/11/X/6/iPad 1,2,Air & Air Pro/Surface Pro/Kindle PW & Fire
|
Running it through Calibre and Sigil definitely cleans it out...I can guarantee NONE of the ebooks that I've taken through this process have any spyware...or any JS at all...
lol The power of cleaning your own books!! |
![]() |
![]() |
![]() |
#4 |
Surfin the alpha waves ~~
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 25,769
Karma: 459220161
Join Date: Dec 2010
Location: New Jersey
Device: Jetbook Lite & Mini, Nook STR, Kobo, Hanvon N516, Kindle 2, Androids
|
All of my ebooks are "cleansed," but none of my ereaders are connected to wifi. So, while I am bothered by unannounced payloads in any digital product, and by the vendors who think they somehow have the right to do this, I'm pretty well still under the radar.
|
![]() |
![]() |
![]() |
#5 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 11,732
Karma: 128354696
Join Date: May 2009
Location: 26 kly from Sgr A*
Device: T100TA,PW2,PRS-T1,KT,FireHD 8.9,K2, PB360,BeBook One,Axim51v,TC1000
|
Would be nice to know which format(s) need extra disinfection.
And which bookstores are collaborating. |
![]() |
![]() |
![]() |
#6 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 28,262
Karma: 203719142
Join Date: Jan 2010
Device: Nexus 7, Kindle Fire HD
|
It's going to have to be specific to a device/app, I'd think. They can't just make any-old ebook start collecting data willy nilly. Unless they're in cahoots with the firmware devs for device manufacturers, that javascript file is going to sit there like a lump in most cases. Kobo does some js, but I certainly don't think they do any old js. Epub3 allows js, but there's still going to be limitations on what it can do.
I rip open a lot of ebooks (including Penguin ones) from a lot of vendors and I've never come across this file. I'm guessing it's going to be found in something cloud-based or in the dedicated apps for ebook subscription programs. |
![]() |
![]() |
![]() |
#7 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 5,658
Karma: 103020299
Join Date: Apr 2011
Device: pb360
|
Quote:
|
|
![]() |
![]() |
![]() |
#8 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 6,937
Karma: 89256247
Join Date: Nov 2011
Location: Charlottesville, VA
Device: Kindles
|
From their Google Analytics for Ebooks page:
Quote:
|
|
![]() |
![]() |
![]() |
#9 |
No Comment
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,240
Karma: 23878043
Join Date: Jan 2012
Location: Australia
Device: Kobo: Not just an eReader, it's an adventure!
|
I expect they're gonna be getting a cease and desist letter from Candy Crush, which owns that trade mark on 'candy'.
If this .js stores the data in the ebook, does that mean that it changes the ebook? If it is a DRMed ebook, which means it is encrypted, how are they going to accomplish this? This must only work in Apple/Android/Windows, because I don't see it working on Kindle/Kobo without participation from Amazon/Kobo. |
![]() |
![]() |
![]() |
#10 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 6,937
Karma: 89256247
Join Date: Nov 2011
Location: Charlottesville, VA
Device: Kindles
|
Quote:
Last edited by jhowell; 08-03-2015 at 06:16 PM. |
|
![]() |
![]() |
![]() |
#11 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 11,732
Karma: 128354696
Join Date: May 2009
Location: 26 kly from Sgr A*
Device: T100TA,PW2,PRS-T1,KT,FireHD 8.9,K2, PB360,BeBook One,Axim51v,TC1000
|
Quote:
Going by the above reports it sounds like Apple and Google are in on it. |
|
![]() |
![]() |
![]() |
#12 |
Argos win Grey Cup!
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 7,659
Karma: 31487351
Join Date: Aug 2009
Location: Raleigh, NC
Device: Paperwhite, Kindles 10 & 4 and jetBook Lite
|
Is this something that would work with smartphones, but not with dumb eInk readers?
|
![]() |
![]() |
![]() |
#13 |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 9,707
Karma: 32763414
Join Date: Dec 2008
Location: Krewerd
Device: Pocketbook Inkpad 4 Color; Samsung Galaxy Tab S6
|
Sounds like another reason to always clear your books of any infections, be it javascript or DRM...
|
![]() |
![]() |
![]() |
#14 |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 279
Karma: 517736
Join Date: Oct 2012
Device: kindle
|
I wonder why would publisher care if buyer read the book or not?
|
![]() |
![]() |
![]() |
#15 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,108
Karma: 60231510
Join Date: Nov 2011
Location: Australia
Device: Kobo Aura H2O, Kindle Oasis, Huwei Ascend Mate 7
|
I doubt that e-ink devices from Amazon or Kobo are involved with this particular effort, as their e-ink devices already collect information, including of course page read data. Unfortunately it is not entirely clear exactly what data is being collected and how. This is a link to an Electronic Frontiers Foundation paper on the matter from 2012.
https://www.eff.org/deeplinks/2012/1...rt-2012-update A couple of things to note: 1. In relation to many of the questions addressed in their chart, the answer is uncertain. 2. It appears that the software itself has not been analysed. To quote from the paper: Unfortunately, unpacking the tracking and data-sharing practices of different e-reader platforms is far from simple. It can require reading through stacked license agreements and privacy policies for devices, software platforms, and e-book stores. That in turn can mean reading thousands of words of legalese before you read the first line of a new book. Legal agreements are useful to determine what can explicitly be done within the agreement, but does not really tell us much about whether it is being done or whether the agreement is being complied with. I suspect some of the answers have been obtained by asking the companies concerned, or by implication. 3. It is three years old. And I doubt the privacy situation has improved in the meantime. If you want to be certain of preserving your privacy, the only solution is to see that your device never goes online. It is almost certainly okay to connect your device to an online computer via Calibre, but I wouldn't be so sure about closed source products like, say, Kindle4PC or Kobo desktop and the like. Privacy is probably completely out the Window on Android or IOS. |
![]() |
![]() |
![]() |
Thread Tools | Search this Thread |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
[O'Reilly] Embedded Systems ebooks - 50% off till August 16, 2013 at 5:00am PT | Cyberman tM | Deals and Resources (No Self-Promotion or Affiliate Links) | 0 | 08-09-2013 03:38 AM |
Kindle 3 scans 2 worms and 1 spyware after using Calibre? | dancingbacon | Devices | 4 | 06-13-2011 08:05 AM |
Candy Wars: The Tooth Fairies vs The Candy King - OUT NOW | R.G. Cordiner | Self-Promotions by Authors and Publishers | 18 | 05-01-2011 09:47 PM |
Kid in a candy store | Baldrake | Amazon Kindle | 8 | 12-08-2010 10:43 PM |