Google: Claims of bypassing Safari security settings 'mischaracterized'

 

Connecting state and local government leaders

The search giant defends itself against claims of subverting Safari, as Microsoft says IE's settings were also bypassed.

Google is defending itself against claims that it bypassed the privacy settings in the Safari and Internet Explorer browsers by saying that it was only providing features enabled by signed-in Google account holders and did not collect personal information.

The statement from the company came after the Wall Street Journal reported on how Google was bypassing Safari’s settings, members of Congress called on the Federal Trade Commission to investigate whether Google violated its settlement agreement with the agency, and Microsoft said IE’s settings also were being bypassed.

In a letter to FTC Chairman Jon Leibowitz, Reps. Edward Markey (D-Mass.), Joe Barton (R-Texas) and Cliff Stearns (R-Fla.) described the issue as a “major concern. ... Google’s practices could have a wide sweeping impact because Safari is a major Web browser used by millions of Americans." The browser is used on both iPhones and computers.

Stanford University graduate student Jonathan Mayer discovered the code, the WSJ reported. A technical adviser to the newspaper, Ashkan Soltani, independently confirmed his findings.

“Once the coding was activated, it could enable Google tracking across the vast majority of websites,” reported the WSJ. Three other companies are using similar techniques: Vibrant Media Inc., WPP PLC's Media Innovation Group LLC and Gannett Co.'s PointRoll Inc.

Google removed the cookies after being contacted by the WSJ.

Safari blocks third-party cookies by default but does allow tracking for some purposes and only from sites that users directly visit. For the workaround, the Google used its DoubleClick network to see if Safari users were signed into Google. If they were, the cookie allowed Google to serve personalized ads and gave users the ability to use its “+1” button.

The findings appeared to contradict Google’s instructions on how to avoid tracking in Safari. A Google site stated that Safari’s privacy settings prevented tracking by Google. The statement was removed after the story broke, said the WSJ.

Google also used similar code to track Microsoft’s Internet Explorer users. In a blog post, Dean Hachamovitch, corporate vice president of Internet Explorer, said Google is circumventing IE users’ privacy preferences by bypassing its P3P Privacy Protection. Hachamovitch recommended IE users install IE 9 and add a Tracking Protection List to avoid being tracked by Google. He also said Microsoft may make changes to its products in light of the issue.

In a statement, Google spokesperson Rachel Whetstone said the WSJ article “mischaracterizes what happened and why. We used known Safari functionality to provide features that signed-in Google users had enabled. It’s important to stress that these advertising cookies do not collect personal information.” She added that it was unintentional and that anyone who opted out of Google’s Web-based advertising program was not affected.

In response to the report, Apple spokesman Bill Evans said, “We are aware that some third parties are circumventing Safari’s privacy features, and we are working to put a stop to it.”

The congressmen were particularly concerned by the findings since Google will begin tracking users across its product lines March 1. Users will not be able to opt out other than by closing their Google account, GCN has reported.

However, the upcoming changes will not apply to government clients.

"The new Privacy Policy does not change our contractual agreements, which have always superseded Google's Privacy Policy for enterprise customers," Google Vice President of Enterprise Amit Singh said in a released statement from the company.

The discovery isn’t the only privacy lapse the government is looking into concerning Google. The FTC will investigate Google, Apple and other technology firms for their processes around collecting personal data of young children via mobile apps, reported the Washington Post.

While child privacy laws require companies to obtain permission from parents to collect data about users under 13, as well as clearly explain what information is being collected and how it will be used, Apple, Google and others rarely disclose this, and application developers don’t provide much information on their privacy practices, said the FTC.

Yet responsibility for privacy breaches ultimately are our own fault, said Thomas Claburn in an Information Week article.

“We rely on free services like Gmail while insisting on ‘privacy,’ a term that we probably can't even define to our collective satisfaction,” Claburn said. “We accept terms of service contracts and privacy policies that explain in excessive detail how we will not get privacy, how our information will be used, and then we object. If you object to the way Google does business, use ad-blocking software. ... Perhaps everyone will follow this advice, Google will collapse, and then we can all just go back to fee-for-service computing. How does a $0.25 per search and $99 for an Android 5.0 upgrade sound?”

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.