Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

11–20 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#11
post #7
post #5

Earlier quoted context omitted.

Jumpshot is Avast. Just a subsidiary.

Does that somehow make it OK?

Without knowing anything about the specifics here... yes, I can confidently say that transmitting information between two companies with the same owner is "ok" and should be expected.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#13
post #7

Earlier quoted context omitted.

Does that somehow make it OK?

Without knowing anything about the specifics here... yes, I can confidently say that transmitting information between two companies with the same owner is "ok" and should be expected.

I meant that it's not OK to collect clickstream data. At all. As I recall, Apple got nailed about Safari doing that, and stopped.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#14
post #7

Earlier quoted context omitted.

Does that somehow make it OK?

Without knowing anything about the specifics here... yes, I can confidently say that transmitting information between two companies with the same owner is "ok" and should be expected.

I think that's splitting hairs, and focusing on the wrong aspect of it. Avast gives clickstream data to a digital marketing company. That company happens to be a subsidiary, so Avast is a digital marketing company. The problem becomes one not of a company sharing your private information with another so it can me monetized, but the initial company monetizing it itself. If you have a problem with your data being used for marketing by your AV vendor, whether it's shared to make it happen is likely of little consequence to you.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#15
post #14

Earlier quoted context omitted.

Without knowing anything about the specifics here... yes, I can confidently say that transmitting information between two companies with the same owner is "ok" and should be expected.

I think that's splitting hairs, and focusing on the wrong aspect of it. Avast gives clickstream data to a digital marketing company. That company happens to be a subsidiary, so Avast is a digital marketing company. The problem becomes one not of a company sharing your private information with another so it can me monetized, but the initial company monetizing it itself. If you have a problem with your data being used…

Exactly.

And there are other risks to users. Once that data has been collected, others may access it, and use it in far more damaging ways. Users in China or Saudi Arabia, for example, may end up in jail, or worse.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#16
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

I think for the purposes of antivirus software, trust issues can be set aside here. Windows Defender ideally has the upper edge for choosing an antimalware solution for Windows in that it's baked in directly to the OS and therefore has more control and ability to prevent malicious activity than a third-party solution. You might not have to trust Microsoft due to privacy concerns, but for something like antivirus software that protects their operating system, intentionally making Windows Defender inferior software just isn't within their best interests.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#17
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

I think for the purposes of antivirus software, trust issues can be set aside here. Windows Defender ideally has the upper edge for choosing an antimalware solution for Windows in that it's baked in directly to the OS and therefore has more control and ability to prevent malicious activity than a third-party solution. You might not have to trust Microsoft due to privacy concerns, but for something like antivirus soft…

How can one "set aside" privacy issues?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#18

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

If nothing else, herd immunity.

That said, I don't know if there's any compelling reason to use something beyond what the OS vendor already provides.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#19

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

If nothing else, herd immunity. That said, I don't know if there's any compelling reason to use something beyond what the OS vendor already provides.

Herd immunity is a decent argument. Still, it is hard to evaluate the effectiveness of the solutions out there.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#20
post #7

Earlier quoted context omitted.

Does that somehow make it OK?

Without knowing anything about the specifics here... yes, I can confidently say that transmitting information between two companies with the same owner is "ok" and should be expected.

Not certain of specifics of this case but in general absolutely no! As a data controller you collect users' data for a purpose. If you use that data for a seprate purpose you need seperate consent from users to use their data.
Post reply on HN