News: 1652684650

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ad-tech firms grab email addresses from forms before they're even submitted

(2022/05/16)


Tracking, marketing, and analytics firms have been exfiltrating the email addresses of internet users from web forms prior to submission and without user consent, according to security researchers.

Some of these firms are said to have also inadvertently grabbed passwords from these forms.

In [1]a research paper scheduled to appear at the Usenix '22 security conference later this year, authors Asuman Senol (imec-COSIC, KU Leuven), Gunes Acar (Radboud University), Mathias Humbert (University of Lausanne) and Frederik Zuiderveen Borgesius, (Radboud University) describe how they measured data handling in web forms on the top 100,000 websites, as ranked by research site [2]Tranco .

[3]

The boffins created their own [4]software to measure email and password data gathering from web forms – structured web input boxes through which site visitors can enter data and submit it to a local or remote application.

[5]

[6]

Providing information through a web form by pressing the submit button generally indicates the user has consented to provide that information for a specific purpose. But web pages, because they run JavaScript code, can be programmed to respond to events prior to a user pressing a form's submit button.

And many companies involved in data gathering and advertising appear to believe that they're entitled to grab the information website visitors enter into forms with scripts before the submit button has been pressed.

[7]

"Our analyses show that users’ email addresses are exfiltrated to tracking, marketing and analytics domains before form submission and without giving consent on 1,844 websites in the EU crawl and 2,950 websites in the US crawl," the researchers state in their paper, noting that the addresses may be unencoded, encoded, compressed, or hashed depending on the vendor involved.

Most of the email addresses grabbed were sent to known tracking domains, though the boffins say they identified 41 tracking domains that are not found on any of the popular blocklists.

"Furthermore, we find incidental password collection on 52 websites by third-party session replay scripts," the researchers say.

[8]

Replay scripts are designed to record keystrokes, mouse movements, scrolling behavior, other forms of interaction, and webpage contents in order to send that data to marketing firms for analysis. In an adversarial context, they'd be called keyloggers or malware; but in the context of advertising, somehow it's just session-replay scripts.

Gunes Acar, one of the report co-authors, was also the co-author of [9]a similar research project in 2017 that looked at data gathering by session-replay companies Yandex, FullStory, Hotjar, UserReplay, Smartlook, Clicktale, and SessionCam.

Evidently, not much has changed since then, except perhaps that email addresses have become more desirable as unique identifiers now that privacy-oriented browsers like Brave, Firefox, and Safari are taking more steps to block cookies and tracking scripts.

Email addresses, the researchers observe, represent a cookie replacement because they're unique, persistent, and can be used to track people across applications, platforms, and even offline interactions that may be tied to an email address like loyalty card transactions.

[10]Europe's GDPR coincides with dramatic drop in Android apps

[11]Google's FLoC flopped, boffins claim, because it failed to provide promised privacy

[12]Privacy pathology: It's time for the users to gather a little data – evidence

[13]Apple iOS privacy clampdown 'did little' to reduce tracking

The website categories with the most leaking forms include: Fashion/Beauty (11.1 per cent, EU; 19 per cent US); Online Shopping (9.4 per cent EU; 15.1 per cent US); and General News (6.6 per cent EU; 10.2 per cent US).

Websites categorized as Pornography had the best privacy when it comes to surreptitious form data harvesting.

"A somehow surprising result was the following: despite filling email fields on hundreds of websites categorized as Pornography, we have not a single email leak," the researchers say, noting that previous studies of adult-oriented websites have relatively fewer third-party trackers than similarly popular general interest websites.

Those pesky regulations

The report authors say that EU websites practicing email exfiltration may be in violation of at least three GDPR requirements: transparency, purpose limitation, and prior consent. Firms found to be violating these rules can be fined up to $20m euros or 4 per cent of annual revenue, per [14]Article 83(5) .

The US doesn't have a federal data privacy law, though it's conceivable one of the [15]handful of US states with applicable privacy rules could take action against pre-submission form harvesting. But given the toothlessness of US privacy regulation over the past decade, don't expect much.

The authors say they attempted to contact 58 first-parties and 28 third-parties with GDPR requests. They report receiving 30 responses from the first-parties, which varied from surprise and remediation to justifications of one sort or another.

"fivethirtyeight.com (via Walt Disney’s DPO), trello.com (Atlassian), lever.co, branch.io and cision.com were among the websites that said they had not been aware of the email collection prior to form submission on their websites and removed the behavior," the report says.

Marriott, meanwhile, said the information collected by digital analytics firm Glassbox helps with customer care, technical support, and fraud prevention.

Third-parties Taboola, Zoominfo, and ActiveProspect defended their data collection practices.

Facebook, aka Meta, is among the third-parties involved in this. The researchers say that email addresses or their hashes were spotted being sent to facebook.com from 21 different websites in the EU.

"On 17 of these, Facebook Pixel’s Automatic Advanced Matching feature was responsible for sending the SHA-256 of the email address in a SubscribedButtonClick event, despite not clicking any submit button," the report says.

[16]Advanced Matching – called out recently for [17]harvesting student loan data – is designed to collect hashed customer data, such as email addresses, phone numbers, and names from checkout, sign-in, and registration forms. The researchers speculate that on these sites, Facebook's script treats clicks on non-submit buttons as a click event for the submit button.

Facebook did not respond to a request for comment.

The report concludes that browser vendors, regulators, and privacy tool makers need to deal with this issue because it isn't going away. "Based on our findings, users should assume that the personal information they enter into web forms may be collected by trackers – even if the form is never submitted," the report concludes. ®

Get our [18]Tech Resources



[1] https://www.usenix.org/conference/usenixsecurity22/presentation/senol

[2] https://tranco-list.eu/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YoIgxwvXJUkAo5NsHjLBMwAAAIw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://github.com/leaky-forms

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoIgxwvXJUkAo5NsHjLBMwAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoIgxwvXJUkAo5NsHjLBMwAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YoIgxwvXJUkAo5NsHjLBMwAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YoIgxwvXJUkAo5NsHjLBMwAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://freedom-to-tinker.com/2017/11/15/no-boundaries-exfiltration-of-personal-data-by-session-replay-scripts/

[10] https://www.theregister.com/2022/05/09/gdpr_europe_apps/

[11] https://www.theregister.com/2022/05/05/googles_floc_flopped_boffins_claim/

[12] https://www.theregister.com/2022/05/03/opinion_column_privacy/

[13] https://www.theregister.com/2022/04/08/apple_ios_privacy/

[14] https://gdpr.eu/article-83-conditions-for-imposing-administrative-fines/

[15] https://www.ncsl.org/research/telecommunications-and-information-technology/state-laws-related-to-internet-privacy.aspx

[16] https://developers.facebook.com/docs/meta-pixel/advanced/advanced-matching

[17] https://www.theregister.com/2022/04/30/meta_student_data/

[18] https://whitepapers.theregister.com/



GDPR?

Headley_Grange

I started an order with John Lewis and got as far as filling in my details on the order form before the process crashed due to my blockers and for one reason or another I never completed the order. John Lewis started sending me marketing emails shortly after that. I complained and they pointed to the incomplete order being a "relationship" under GDPR rules that permitted them to send me stuff. I raised a case with the ICO and they confirmed that by completing the form, even though I'd not submitted it or given informed consent, that this constituted enough of a relationship under the GDPR regs for John Lewis to send me marketing mail as long as there was a clear way to unsubscribe.

Re: GDPR?

thosrtanner

not sure whether I should upvote that (detailing the problem) or downvote it (because arrggh)

So have one of these to drown your sorrows ------------------>

Re: GDPR?

Cederic

I really don't understand the ICO's position there. As you say, you didn't provide informed consent, and claiming a relationship because you happened to use their website really does not sound like the law being interpreted as intended - otherwise all tracking would become legal.

You're now making me regret buying two 'white goods' appliances from them in the last six weeks :(

thosrtanner

And this is why I have noscript installed at home. Not at work, because I can't install stuff from external sites ...

On the plus side, looks like I can re-enable javascript on all those pr0n websites I visit.

Anonymous Coward

Well if your IT guys are not installing NoScript by default I'd worry about their competence.

Cederic

Yeah, his IT guys want multiple support calls every minute from anybody and everybody in the company frustrated that their web browsers don't work properly.

They want the overhead of maintaining a whitelist for each browser, and keeping it updated with every software installation, external service sign-up and new plug-in required, plus pre-emptively identifying when external services have updated their own site.

Above all, I completely agree that they want to demonstrate competence at fully securing a system, even though it'll get them accused of incompetence for failing to provide a working one.

Anonymous Coward

> I raised a case with the ICO

That was your biggest mistake. The ICO consistently take the side of the corporates, after all consumers are supposed to consume, not complain.

One way to get them to backtrack is to appeal their decisions but it takes energy and time (and they know this).

b0llchit

...inadvertently grabbed passwords...

What a load of crap! These tracking pimps do not take stuff "inadvertently". This is done because of gross negligence or premeditation. Both are enough reason to put them up against the wall and make sure they never ever get access to the internet again.

Reversal of burden of proof in these cases would be one change in the GDPR making life a lot easier. These firms caught in this crap should not be allowed to hide behind the "oh, we're so sorry" bullshit mantle.

Busted

An_Old_Dog

"Inadvertant password grabbing" -- I'll chortle over that one for at least a week.

"Honest, guv'nor, we had no idea we was doin' that!"

fitzpat

I want to know the 41 domains not on block lists.

The paper doesn't out them

only 41 (why not 42...)?

Anonymous Coward

for FecalBarf?

The blocklist (downloadable from several sources) I'm currently using has over 800 domains/IP addresses associated with Zuckfart.

Yes, I detest FB and the rest of the antisocial media crowd.

It is a constant war of attrition. If this keeps going, Fartpaper and the rest will soon own most of the internet. Sooner or later these empires will crash and burn just like Rome. May it be soon... very soon.

don't worry Cleggy... I'm not on your platform nor any of the others so you can't ban me.

Is this really a problem?

DS999

How often does one fill out a form then decide not to click "submit"?

I mean, sure, it is sleazy and possibly even illegal depending on where you live, but I already assumed they were doing this and I'll be shocked if there is even one Reg reader who is surprised by this.

It provides an opportunity to mess with them though, you can go to web sites and fill in a false email address like say that of your local legislator, police office or what have you...and no one can blame you for what happens after because you never clicked submit!

Re: Is this really a problem?

wolfetone

It's a problem depending on what you're doing.

SurfShark, for example, require an email to start the process of signing up to their services. I was looking for a VPN provider for multiple machines and was going through the process, but I only got as far as putting in an email.

Not even a few hours later I get a load of emails from them about completing the order.

Now if the website is demanding an email right at the first part of the process, and not allowing you to continue to see the plans etc, that then becomes a problem as all I've really consented to was to view the packages they provide. I've not consented to being harassed by them asking me to carry on the order.

Autocomplete

Fazal Majid

Will “helpfully” fill in many fields like email.

Good thing I use a separate email for each website (Apple’s email privacy feature before its time).

Re: Autocomplete

Flocke Kroes

If you are not careful, autocomplete will also send your name, address and phone number. So far I have not seen credit card number, expiry date and CVC in auto complete, but I am sure that is only one developer's typo away from happening.

It is tempting to enable javascript, go to the John Lewis website, enter my MP's email address and half complete an order.

Re: Autocomplete

wolfetone

" If you are not careful, autocomplete will also send your name, address and phone number. So far I have not seen credit card number, expiry date and CVC in auto complete, but I am sure that is only one developer's typo away from happening. "

I'm not that familiar with auto complete as I like the misery of typing in all of my details every single time, but I'm fairly sure on my wife's iPhone her credit card details are part of some sort of auto complete? So it could well happen, but I don't know enough first hand about the facility.

Re: Autocomplete

Doctor Syntax

I'm sure a little research would find a few other email addresses that you could inadvertently enter in error and have to change, such as John Lewis's CEO's.

Facebook involved

Mr Dogshit

NO! Surely not?

Of what you see in books, believe 75%. Of newspapers, believe 50%. And of
TV news, believe 25% -- make that 5% if the anchorman wears a blazer.