Traffic Tracking Leads to Legal Woes

LOS ANGELES — Behaviorally targeted advertising is taking a blow from privacy advocates, with a series of lawsuits against top companies tracking surfers persistently.

According to a report in Wired, researchers at U.C. Berkeley have revealed a range of highly popular websites that are employing an advanced visitor tracking service that can’t be blocked,  “even when users block cookies, turn off storage in Flash, or use browsers’ ‘incognito’ functions.”

Wired says that the service, known as KISSmetrics, boasts of more accurate and comprehensive tracking than is done by its competitors, including Google Analytics, “tracking the number of visitors, what the visitors do on the site, and where they come to the site from.”

The company reportedly did this through a number of technologies, including the use of ETags and deleted cookie reconstitution, following visitors across multiple domains.

Similar to fingerprints, the ETag, or entity tag, is according to Wikipedia, “one of several mechanisms that HTTP provides for cache validation, and which allows a client to make conditional requests. This allows caches to be more efficient, and saves bandwidth, as a web server does not need to send a full response if the content has not changed.”

Optimistic concurrency control is another cited benefit of ETags, as they prevent simultaneous updates of a single resource from overwriting each other — such as when several parties are working on the same document, or website design, at the same time.

But according to a pair of California residents, they can also be abused as a form of website visitor tracking, which unlike cookie-based systems, is not normally “flushed” or blocked and therefore poses a privacy concern — while violating federal wiretapping and California laws.

The latest suit, by John Kim and Dan Schutzman, which targets KISSmetrics and 25 alleged client companies including GigaOm, iVillage and Spotify, claims that the pair “expected their browser controls to block or delete cookies, preventing them from being tracked online, profiled, and served behaviorally targeted advertisements.”

The action follows a separate suit filed last week against KISSmetrics and Hulu, contending that the companies allegedly violated federal and state laws through their use of ETag tracking technology; a technology which KISSmetrics has distanced itself from.

KISSmetrics CEO Hiten Shah responded to the suits and the allegations surrounding the company’s data collection practices in a written statement, claiming that KISSmetrics “has never shared any information about a user with any third party [and] does not track users across different websites, nor do we have the ability to do so.”

Hoping to eliminate concerns over its business practices, KISSmetrics clarified that it only uses first-party cookies for tracking, does not use ETags or other persistent cookies or objects for tracking purposes and has added stringent support for the “Do Not Track” header, along with a consumer-level opt-out for those who wish to be entirely removed from all KISSmetrics tracking.

While these cases have just begun, their message is clear: the use of unauthorized, persistent cookies or other objects intended to mitigate cache clearing and browser-enacted privacy restrictions, particularly without disclosure, may be a risky way to go.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Federal AV Proposal Scores Minor Win in House but Remains in Doubt

A newly announced bipartisan agreement in the U.S. House of Representatives Committee on Energy and Commerce may soon bring a proposed federal age verification law before the full House, but the measure continues to face an uphill battle.

Arizona Governor Vetoes 'Protect Act' With New Consent Provisions

Arizona Governor Kate Hobbs on Friday vetoed HB 2133, the “Protect Act,” which would have imposed new requirements for adult content uploaded online.

Brazil Begins Monitoring 18 Adult Sites for AV Compliance

Brazil’s National Data Protection Authority (ANPD) is now monitoring 18 high-traffic adult websites for compliance with the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires such sites to age-verify users located in Brazil.

Ofcom Fines First Time Videos $100,000 for AV Noncompliance

U.K. media regulator Ofcom on Thursday imposed a fine of 80,000 pounds (more than $100,000) against First Time Videos, which operates FTVGirls.com and FTVMilfs.com, for failing to implement age checks required for compliance with the Online Safety Act.

Curves Ahead: How BBW Creators are Turning Differentiation Into Competitive Advantage

For centuries, curves have been celebrated as a symbol of beauty, sensuality and power. From the soft opulence of Rubens paintings to the glamorous silhouettes of pinup icons, fuller figures have long occupied a place in art, fashion and fantasy.

Woodhull Freedom Foundation to Host Virtual 'Pride' Edition of 'Fact Checked' Series

Woodhull Freedom Foundation is hosting a Pride Month virtual edition of its series “Fact Checked by Woodhull.”

'InMelanin' Relaunches Through PAYSITE

InMelanin.com has officially relaunched through PAYSITE.

Pearl Industry Network Partners With Takedown Piracy

Industry trade group Pearl Industry Network (PiN) has officially partnered with Takedown Piracy.

Hollywood Reporter Spotlights XBIZ Miami in Feature on Fan Platforms

Last month's XBIZ conference serves as the setting for a new Hollywood Reporter feature examining the competitive fan platform market.

F2F, Image Angel Launch 'Forensic Watermarking' for Traceability

Friends2Follow (F2F) and Image Angel have partnered to launch a new traceability solution to combat unauthorized content sharing with the use of forensic watermarks.

Show More