Traffic Tracking Leads to Legal Woes

LOS ANGELES — Behaviorally targeted advertising is taking a blow from privacy advocates, with a series of lawsuits against top companies tracking surfers persistently.

According to a report in Wired, researchers at U.C. Berkeley have revealed a range of highly popular websites that are employing an advanced visitor tracking service that can’t be blocked,  “even when users block cookies, turn off storage in Flash, or use browsers’ ‘incognito’ functions.”

Wired says that the service, known as KISSmetrics, boasts of more accurate and comprehensive tracking than is done by its competitors, including Google Analytics, “tracking the number of visitors, what the visitors do on the site, and where they come to the site from.”

The company reportedly did this through a number of technologies, including the use of ETags and deleted cookie reconstitution, following visitors across multiple domains.

Similar to fingerprints, the ETag, or entity tag, is according to Wikipedia, “one of several mechanisms that HTTP provides for cache validation, and which allows a client to make conditional requests. This allows caches to be more efficient, and saves bandwidth, as a web server does not need to send a full response if the content has not changed.”

Optimistic concurrency control is another cited benefit of ETags, as they prevent simultaneous updates of a single resource from overwriting each other — such as when several parties are working on the same document, or website design, at the same time.

But according to a pair of California residents, they can also be abused as a form of website visitor tracking, which unlike cookie-based systems, is not normally “flushed” or blocked and therefore poses a privacy concern — while violating federal wiretapping and California laws.

The latest suit, by John Kim and Dan Schutzman, which targets KISSmetrics and 25 alleged client companies including GigaOm, iVillage and Spotify, claims that the pair “expected their browser controls to block or delete cookies, preventing them from being tracked online, profiled, and served behaviorally targeted advertisements.”

The action follows a separate suit filed last week against KISSmetrics and Hulu, contending that the companies allegedly violated federal and state laws through their use of ETag tracking technology; a technology which KISSmetrics has distanced itself from.

KISSmetrics CEO Hiten Shah responded to the suits and the allegations surrounding the company’s data collection practices in a written statement, claiming that KISSmetrics “has never shared any information about a user with any third party [and] does not track users across different websites, nor do we have the ability to do so.”

Hoping to eliminate concerns over its business practices, KISSmetrics clarified that it only uses first-party cookies for tracking, does not use ETags or other persistent cookies or objects for tracking purposes and has added stringent support for the “Do Not Track” header, along with a consumer-level opt-out for those who wish to be entirely removed from all KISSmetrics tracking.

While these cases have just begun, their message is clear: the use of unauthorized, persistent cookies or other objects intended to mitigate cache clearing and browser-enacted privacy restrictions, particularly without disclosure, may be a risky way to go.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Teasy Agency Launches Marketing Firm

Teasy Agency has officially launched Teasy Marketing firm.

Ofcom Investigates More Sites in Wake of AV Traffic Shifts

U.K. media regulator Ofcom has launched investigations into 20 more adult sites as part of its age assurance enforcement program under the Online Safety Act.

MintStars Launches Debit Card for Creators

MintStars has launched its MintStars Creator Card, powered by Payy.

xHamster Settles Texas AV Lawsuit, Pays $120,000

Hammy Media, parent company of xHamster, has settled a lawsuit brought by the state of Texas over alleged noncompliance with the state’s age verification law, agreeing to pay a $120,000 penalty.

RevealMe Joins Pineapple Support as Partner-Level Sponsor

RevealMe has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

OnlyFans Institutes Criminal Background Checks for US Creators

OnlyFans will screen creators in the United States for criminal convictions, CEO Keily Blair has announced in a post on LinkedIn.

Pineapple Support to Host 'Healthier Relationships' Support Group

Pineapple Support is hosting a free online support group on enhancing connection and personal growth.

Strike 3 Rejects Meta 'Personal Use' Defense in AI Suit

Vixen Media Group owner Strike 3 Holdings this week responded to Facebook parent company Meta’s motion to dismiss Strike 3’s suit accusing Meta of pirating VMG content to train its artificial intelligence models.

Pornhub, Stripchat: VLOP Designation Based on Flawed Data

In separate cases, attorneys for Pornhub and Stripchat this week told the EU’s General Court that the European Commission relied on unreliable data when it classified the sites as “very large online platforms” (VLOPs) under the EU’s Digital Services Act, news organization MLex reports.

New Age Verification Service 'AgeWallet' Launches

Tech company Brady Mills Agency has officially launched its subscription-based age verification solution, AgeWallet.

Show More