Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is way, way, way worse.

If I'm understanding it correctly, the vendor is offering the following service: place a JS snippet on your website. When a user visits your site, data will be pushed to the vendor's server about the user and what they do on your site (probably keyed on IP and as many other things as they can use to fingerprint). In return for you sharing this data with the vendor, the vendor will give you all of the data on this same user that was contributed by their other clients.

Here is an extreme (yet possible) scenario. You go to a medical forum that uses this software and create an account using your personal email address and real name, both of which you select NOT to be displayed to the public. You then post a message asking about a specific type of back pain you're having. A few hours/days later, you're browsing for a gift for someone, and visit the website of a salon that also uses this software. They can identify that your browser visited medicalforum.com, see the email address and real name you created an account with (since they were passed your form submission directly, without regard to what privacy settings you used for the forum), and see the topic you posted on back pain. So just to be helpful, they email you an advertisement: "Hi {your real name}, we see that you're having some back pain - bring this email in to {salon} for 15% off a massage!"

EDIT: To add, how do you know that you can trust the vendor not to display seriously private data? What if an online store uses this JS, and the vendor has your credit card info, possibly not-so-securely stored? Your information becoming public would be as simple as Asshole Q. Pirate making a fake site with some link-bait, and creating an account with the vendor.



Or worse you go and apply for health insurance online and get denied because of this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: