Traffic Tracking Leads to Legal Woes

LOS ANGELES — Behaviorally targeted advertising is taking a blow from privacy advocates, with a series of lawsuits against top companies tracking surfers persistently.

According to a report in Wired, researchers at U.C. Berkeley have revealed a range of highly popular websites that are employing an advanced visitor tracking service that can’t be blocked,  “even when users block cookies, turn off storage in Flash, or use browsers’ ‘incognito’ functions.”

Wired says that the service, known as KISSmetrics, boasts of more accurate and comprehensive tracking than is done by its competitors, including Google Analytics, “tracking the number of visitors, what the visitors do on the site, and where they come to the site from.”

The company reportedly did this through a number of technologies, including the use of ETags and deleted cookie reconstitution, following visitors across multiple domains.

Similar to fingerprints, the ETag, or entity tag, is according to Wikipedia, “one of several mechanisms that HTTP provides for cache validation, and which allows a client to make conditional requests. This allows caches to be more efficient, and saves bandwidth, as a web server does not need to send a full response if the content has not changed.”

Optimistic concurrency control is another cited benefit of ETags, as they prevent simultaneous updates of a single resource from overwriting each other — such as when several parties are working on the same document, or website design, at the same time.

But according to a pair of California residents, they can also be abused as a form of website visitor tracking, which unlike cookie-based systems, is not normally “flushed” or blocked and therefore poses a privacy concern — while violating federal wiretapping and California laws.

The latest suit, by John Kim and Dan Schutzman, which targets KISSmetrics and 25 alleged client companies including GigaOm, iVillage and Spotify, claims that the pair “expected their browser controls to block or delete cookies, preventing them from being tracked online, profiled, and served behaviorally targeted advertisements.”

The action follows a separate suit filed last week against KISSmetrics and Hulu, contending that the companies allegedly violated federal and state laws through their use of ETag tracking technology; a technology which KISSmetrics has distanced itself from.

KISSmetrics CEO Hiten Shah responded to the suits and the allegations surrounding the company’s data collection practices in a written statement, claiming that KISSmetrics “has never shared any information about a user with any third party [and] does not track users across different websites, nor do we have the ability to do so.”

Hoping to eliminate concerns over its business practices, KISSmetrics clarified that it only uses first-party cookies for tracking, does not use ETags or other persistent cookies or objects for tracking purposes and has added stringent support for the “Do Not Track” header, along with a consumer-level opt-out for those who wish to be entirely removed from all KISSmetrics tracking.

While these cases have just begun, their message is clear: the use of unauthorized, persistent cookies or other objects intended to mitigate cache clearing and browser-enacted privacy restrictions, particularly without disclosure, may be a risky way to go.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Utah Governor Signs 'Porn Tax' and VPN Rule Into Law

Governor Spencer Cox on Friday signed into law a bill to tax adult websites and make them liable if minors circumvent geolocation.

BranditScan Launches 'White Glove' Subscription Tier

BranditScan has launched its new White Glove subscription tier for creators.

German Court: Regulator Can't Block Creator's IG Account, Only Posts

A German court has ruled that while a regional media regulatory agency may block specific Instagram posts that include material deemed harmful to minors, it cannot ban an entire Instagram account due to such a post.

Brazil Lays Out Preliminary Guidelines for New AV Requirements

President Luiz Inácio Lula da Silva on Wednesday signed a decree establishing guidelines for new regulations requiring adult websites to age-verify users located in Brazil.

Senate Committee Debates Section 230 Reform

The U.S. Senate Committee on Commerce, Science, and Transportation held a hearing Wednesday on potential changes to Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

Pearl Industry Network Offers Free Creator Memberships

Industry trade group Pearl Industry Network (PiN) has launched its free creator membership initiative.

Sam Bird Acquires Fanblast

Sam Bird, former co-director of global talent agency Surge, has acquired creator monetization tool Fanblast and named himself CEO.

'SheHerGirls' Launches Through Paysite.com

The braintrust behind PoleVixens has officially launched a new membership site, SheHerGirls, also through Paysite.com.

FTC Invites Public Comment on 'Click to Cancel' Rulemaking

The Federal Trade Commission (FTC) announced this week that it is seeking public comment on whether it should amend its Negative Option Rule to better address deceptive or unfair practices.

Aylo Rebuts Indiana AV Suit Claims Over VPN Access

Aylo this week asked a Marion Superior Court judge to dismiss Indiana’s lawsuit alleging that the company violated the state’s age verification law by failing to prevent access by users who employ VPNs and similar means to avoid geolocation.

Show More