I really appreciated this story. It's so hard to make people care about "small" data leaks when they have no idea what many "small" data leaks can lead to. The bug the journalists discovered that revealed Skype's contact list is the perfect example -- the programmer just did something completely "reasonable" (grabbing avatars) that ended up leaking a vital set of information. Imagine if surveillance was your full tim…
> I'll again state that this is why I feel so strongly that Google Analytics should be updated to be HTTPS by default That's an incredible waste of bandwidth for no improvement in privacy whatsoever. If HTTPS pages were including GA over HTTP, then yes, this would be an issue, but you're already requesting the page over HTTP, if you're getting GA over HTTP. There's simply no advantage whatsoever -- for privacy, secur…
Usage of unencrypted Google Analytics + Google cookies[1] means that you don't need to eavesdrop on individual connections, just one small set: the endpoints to the Google Analytics servers.
Hence, the NSA or other large entities have an economical way to tap a large portion of web traffic.
[1]: http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10...