Traffic Tracking Leads to Legal Woes

LOS ANGELES — Behaviorally targeted advertising is taking a blow from privacy advocates, with a series of lawsuits against top companies tracking surfers persistently.

According to a report in Wired, researchers at U.C. Berkeley have revealed a range of highly popular websites that are employing an advanced visitor tracking service that can’t be blocked,  “even when users block cookies, turn off storage in Flash, or use browsers’ ‘incognito’ functions.”

Wired says that the service, known as KISSmetrics, boasts of more accurate and comprehensive tracking than is done by its competitors, including Google Analytics, “tracking the number of visitors, what the visitors do on the site, and where they come to the site from.”

The company reportedly did this through a number of technologies, including the use of ETags and deleted cookie reconstitution, following visitors across multiple domains.

Similar to fingerprints, the ETag, or entity tag, is according to Wikipedia, “one of several mechanisms that HTTP provides for cache validation, and which allows a client to make conditional requests. This allows caches to be more efficient, and saves bandwidth, as a web server does not need to send a full response if the content has not changed.”

Optimistic concurrency control is another cited benefit of ETags, as they prevent simultaneous updates of a single resource from overwriting each other — such as when several parties are working on the same document, or website design, at the same time.

But according to a pair of California residents, they can also be abused as a form of website visitor tracking, which unlike cookie-based systems, is not normally “flushed” or blocked and therefore poses a privacy concern — while violating federal wiretapping and California laws.

The latest suit, by John Kim and Dan Schutzman, which targets KISSmetrics and 25 alleged client companies including GigaOm, iVillage and Spotify, claims that the pair “expected their browser controls to block or delete cookies, preventing them from being tracked online, profiled, and served behaviorally targeted advertisements.”

The action follows a separate suit filed last week against KISSmetrics and Hulu, contending that the companies allegedly violated federal and state laws through their use of ETag tracking technology; a technology which KISSmetrics has distanced itself from.

KISSmetrics CEO Hiten Shah responded to the suits and the allegations surrounding the company’s data collection practices in a written statement, claiming that KISSmetrics “has never shared any information about a user with any third party [and] does not track users across different websites, nor do we have the ability to do so.”

Hoping to eliminate concerns over its business practices, KISSmetrics clarified that it only uses first-party cookies for tracking, does not use ETags or other persistent cookies or objects for tracking purposes and has added stringent support for the “Do Not Track” header, along with a consumer-level opt-out for those who wish to be entirely removed from all KISSmetrics tracking.

While these cases have just begun, their message is clear: the use of unauthorized, persistent cookies or other objects intended to mitigate cache clearing and browser-enacted privacy restrictions, particularly without disclosure, may be a risky way to go.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Sansyl Group Acquires Blue Donkey Media

Sansyl Group, parent company of AdultPrime Network, has acquired Blue Donkey Media B.V., owner of Dutch adult site Meiden van Holland, among several other erotic websites and television channels.

Pineapple Support to Hold Mental Health Summit

The annual Pineapple Support Mental Health Summit is taking place Dec. 15-17.

Ofcom Fines AVS Group $1.3 Million for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed a penalty of one million pounds, or approximately $1.3 million, on AVS Group Ltd. after an investigation concluded that the company had failed to implement robust age checks on 18 adult websites.

Updated: Aylo to Help Test EU Age Verification App

Pornhub parent company Aylo plans to participate in the European Commission’s pilot program for its “white label” age verification app, a spokesperson for the company has confirmed.

Missouri Lawmaker Attempts to Revive 'Health Warnings' for Adult Sites

A Missouri state representative has introduced a bill that would require adult sites to post notices warning users of alleged physical, mental, and social harms associated with pornography, despite a previous federal court ruling against such requirements.

New Age Verification Service 'BorderAge' Launches

French startup company Needemand has officially launched its subscription-based age verification solution, BorderAge.

Ruling: Italy's 'Porn Tax' Applies to All Content Creators

Italy’s tax revenue agency has ruled that the nation’s 25% “ethical tax” on income generated from adult content applies even to smaller independent online content creators.

Proposed New Hampshire AV Bill Appears to Violate Constitution

A bill in the New Hampshire state legislature, aimed at requiring adult sites to age-verify users in that state, contains a provision that seemingly contradicts the Supremacy Clause in Article VI of the U.S. Constitution.

AEBN Publishes Report on Fetish Trends

AEBN has published a report on fetish categories from its straight and gay theaters.

Online Child Protection Hearing to Include Federal AV Bill

A House subcommittee will hold a hearing next week on a slate of bills aimed at protecting minors online, including the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law.

Show More