freunde.ma-nic.de

Search

Items tagged with: corporations

Which websites featured on the Federation have the worst privacy?


My last post highlighted how ticking the OEmbed box to add a website picture to a post can compromise Federation users if it contains a tracker.

[:]




[:]

I also mentioned tools, like Disconnect, we could use to detect websites which track their users. In this post I reveal some of the most popular reference websites on the Federation with low privacy and high tracking rates.

I believe Federation users should consider not embedding, or at least warning their readers about the surveillance techniques carried out by these sites.

A Princeton University study identified almost a million websites that track their users. Here are just 5 examples of websites whose stories are commonly quoted on the Federation:

WIRED


Wired is a popular website referenced on the Federation by many users because it publishes great tech-based stories. But how private is it?
Although it offers an ‘ad-free’ version for subscribers, normal visitors are ruthlessly fleeced for their data.

WIRED has embed deals (agreements to embed tracking codes into their pages for money or gain) with a staggering 171 third parties including Google, Amazon, Facebook, Vogue, GQ, Golf Digest, Bonappetit and Vanity Fair.




Some tracking beacons embedded on WIRED and captured by Ublock Origin

[:]

151 of these third parties are known tracking or advertising companies like Google, Amazon, Facebook, Turn, Add This, Scorecard Research, Adobe, Twitter Analytics, Typekit, Criteo and Quantserve. Aggressive trackers like Google Tag Manager (GTM), Add This and Turn are present here.

Below is a screengrab of the many scripts NoScript has blocked from the WIRED website, the 33 scripts, gifs and beacons blocked by Ublock Origin and a couple by Disconnect.




[:]

WIRED sets 25 short-term and 28 long-term cookies itself, while allowing its third party partners (including 69 tracking companies) to set 26 short-term and 133 long-term cookies.

It uses Google Analytics without the anonymization feature enabled, so user details are sent to Google servers.

All WIRED servers are based in the US so GDPR privacy rules can be ignored.

Websites loading this many scripts/cookies are usually blacklisted by most users, not least because they drain a device’s battery.

WIRED claims that subscribing with them will mean an ad free experience, but I find it hard to believe that a subscription to WIRED will suddenly load a clean page without a single tracker retrieving data. But then I am not a WIRED subscriber. Please comment if you are and have no trackers.

[:]

+++++++++++++++++++++++++++++++++++++++++++

FOSSPOST


Seen by some as a safe pro-privacy resource celebrating Free and Open Source Software, FOSSPOST lets its users down by digitally fingerprinting their devices and loading 19 trackers into a browser.

[:]




[:]
FOSSPOST has embed deals with 27 third parties, making its embed renting in the ‘low’ category, including Google, Amazon, Creative Commons and WordPress.

13 of these are known tracking or advertising companies like Google, Amazon, Mailerlite, One Signal and the data-hungry caterpillar that is WordPress.

FOSSPOST sets 2 short-term and 2 long-term cookies itself while allowing its third party partners (including 3 tracking companies) to set 4 long-term cookies.

It uses Google Analytics without the anonymization feature so user details are sent to Google servers. All FOSSPOST servers are based in the US so GDPR privacy rules can be ignored.

[:]
+++++++++++++++++++++++++++++++++++++++++++

TECHCRUNCH


Acquired by Yahoo’s parent company, Oath (a company that includes AOL), under the Verizon umbrella, in 2010, this is a popular reference source for researchers and Federation users.

Historically, Yahoo deserves some kudos as they were one of the few big tech companies that objected to sharing their users’ details with the PRISM
spy program.

The Bush administration threatened them with $250k a day fines until they complied. Verizon bought them in 2017. Yahoo suffered the largest data breach in history in 2018.

The link to this NYT story is not embedded (consider blocking the GTM tracker on the site)

https://www.nytimes.com/2014/09/12/technology/documents-unsealed-in-yahoos-case-against-us-data-requests.html

TECHCRUNCH.com fingerprints the user’s device and dumps 2-7 Yahoo trackers in their browser, depending on the page loaded.

[:]




[:]

TECHCRUNCH has embed deals with 27 third parties, including Google, Facebook, Yahoo and WordPress.
15 of these are known tracking or advertising companies like Google, Facebook, Yahoo, WordPress, Atwola, Typekit, AOL and Scorecard Research.

TECHCRUNCH sets 4 short-term and 5 long-term cookies itself while allowing its third party partners (including 4 tracking companies) to set 1 short-term and 7 long-term cookies.

It uses Google Analytics but interestingly enables the anonymization feature so some user details are not sent to Google servers.

All servers are based in the US so forget about GDPR privacy rules.

[:]

+++++++++++++++++++++++++++++++++++++++++++

THE REGISTER .co.uk


Although a great resource with well-written and groundbreaking stories, it isn’t as private as I’d hoped.

There is no obvious digital fingerprinting but it seems to have gathered more Google syndication in the last couple of years, (9 of its 16 embed deals are with the Big G). 12 known tracking or advertising companies like Google, Admedo and the Amp Project gather data.

THE REGISTER sets 3 short-term and 4 long-term cookies itself while allowing its third party partners (including 2 tracking companies) to set 7 long-term cookies.

It uses Google Analytics without enabling the anonymization feature so user details are sent to Google servers. Although THE REGISTER’s domain is in the UK, both its data and email servers are based in the US so GDPR privacy rules could be compromised here, though I am not a lawyer.

[:]
+++++++++++++++++++++++++++++++++++++++++++

The Guardian .com


I’ve been sitting on this for a few years now but it’s about time I blew the whistle.

I first noticed the Guardian newspaper’s website was digitally fingerprinting its users’ devices when they published an article on, um, Canvas Fingerprinting.

That page has been removed since, but they still continued doing it, long before Facebook, though not before Google.

[:]




[:]

I’ve kept quiet about this surveillance because I admire the paper for its incredible journalism, especially exclusives like the Snowdon revelations, and its general championing of freedom issues across many sectors of society. But the hypocrisy has started to wear me down.

[:]



Some tracking items & widgets embedded on Guardian .com and captured by Ublock Origin

The Guardian has embed deals with a privacy-sapping 142 third parties, including Google, Amazon, Bing, Twitter, and, despite being one of its main critics, Facebook. 132 of these third party partners are known tracking or advertising companies like Google, Amazon, Facebook, Turn, AddThis, Scorecard Research, Blue Kai, Twitter Analytics, Rubicon, Criteo and Quantserve.

Some of the most aggressive trackers like GTM, AddThis and Turn are present here.

The Guardian also sets 3 short-term and 5 long-term cookies itself, while allowing its third party partners (including 51 tracking companies) to set 10 short-term and 131 long-term cookies.

Yes, we NEED the Guardian’s continued existence, but castigating Facebook et al while allowing them to track its users doesn’t sit well with me.

The website uses Google Analytics but at least enables the anonymization feature, so some user details are not sent to Google servers.

Although The Guardian’s data servers are in Germany, their email servers are based in the US so GDPR privacy rules could be compromised here, though, again, I am not a lawyer.

In conclusion, I’ve given just 5 examples of popular sites Federation users quote in their posts.

I am NOT advocating a boycott of these sites but politely suggest we don’t OEmbed them, just feature a hyperlink and give readers the heads-up about these privacy concerns.

Alternatively, look for other sources featuring the same story. It’s also worth highlighting which websites do NOT add a tracker when we OEmbed a story, or have a low level of surveillance. Please promote those guys.

#news #fakenews #journalism #FreePress #PressFreedom #theguardian
#privacy #tracking #trackers #facebook #social #mass-surveillance #gdpr #google #location #user #device #setup #private #secure #internet #tips #tricks #online #os #windows #apple #ios #advertising #ad #revenue #streams #developers #media #data #corporations #telemetry #consent #spyware #surveillancecapitalism #humanrights, #anonymity #cookies #surveillance #browser #proxy #relay #network #www #leaks #fingerprint #activity #activitytrackers #thefederation #pods #federation #fediverse #friendica #mastodon #pleroma #socialhome # #Gnusocial #Funkwhale #Peertube #pixelfed #hubzilla #Diaspora
 


How can Federation users post more safely?


You know how it goes. We find a great story online and we want to share it with our supporters or feature it in our feed with appropriate hashtags for maximum reach.

But do we check the website featuring the story for privacy before we post?

When we embed a link by selecting the OEmbed box (often ticked by default) this displays an image or video on our post from the website we’ve featured.




They may look cool, but these images can contain beacons or other trackers. Embedded trackers also load into the browsers of any user who scrolls down the public feeds.

Should we ensure the website is safe before linking to it?


Actually some do. Posts that don’t feature a website’s images (with the OEmbed box unchecked as below) can actually protect Federation users from a serious amount of surveillance.

Some thoughtful users actually reproduce the article’s main points in their post, to protect their readers from visiting the site itself. They usually supply a link to the original content if one wants more detail and perhaps is protected with tracker blockers. So how do we know a site we recommend is safe?

Here are some privacy tips:


• Consider checking the page’s security/privacy before linking to it.

Using Tor, or a beefed-up Firefox fork or version (for detecting digital fingerprinting), and/or Disconnect, NoScript or Ublock Origin add-ons to reveal a multitude of trackers.




[:]

• There is usually more than one website featuring the same story. Consider picking the website with the least trackers and digital fingerprinting.

• Issue a warning in your post about any of the site’s surveillance methods and privacy issues you’ve detected.

• Embedding a picture/video could also make users vulnerable. Consider unchecking the OEmbed box.




In the next post I’ll give examples of a number of websites with low privacy and excessive trackers, commonly featured in the public feeds.

#secure #windows #media #data #corporations #tracking #trackers #facebook #social #mass-surveillance #gdpr #google #alphabet #location #user #setup #private #secure #internet #chrome #tips #tricks #online #os #mobile #ie #safari #apple #ios #ad #revenue #streams #developers #telemetry #consent #windows10 #windows7 #windows81 #microsoft #linux #debian #ubuntu #mate #gnome #grub #iphone #firefox #advertising #android #chrome #browser #browsers #phone #phones #device #Tor #privacy, #humanrights, #anonymity #security #cookies #surveillance #browser #web #onion #router #torbrowser #bridge #proxy #relay #leaks #fingerprint #activity #activitytrackers #spyware #surveillancecapitalism #thefederation #pods #federation #fediverse #friendica #mastodon #pleroma #socialhome #ganggo #Misskey #Gnusocial #Funkwhale #Peertube #pixelfed #hubzilla #Diaspora
 

Do NOT consume palm oil. Palm oil plantations KILL helpless orangutans on purpose. When you eat processed food products with palm oil, THIS is what you are buying.

Palm Oil Investigations


Bild/Foto
Palm oil and species extinction
​Quote Taken from COP (Centre For Orangutan Protection)
"Orangutans’ #poaching is done deliberately as a policy made by #palmoil #corporations. Therefore they hire local people as pest busters, who serve the #corporation with #killing any #wild #animals, including #orangutans, which spoil #palm oil trees within the #plantations. The pest busters will bring up a cut-off hand of an #orangutan they have killed and hand it to the corporation as a proof. When they find an adult female orangutan with her baby, they will usually kill the ‘mother‘ and take away the baby for pet or sale".

It is estimated that over 50 Orangutan are killed every week due to #deforestation. #Forest homes are cleared by either heavy machinery or fire. Orangutans are left starved with no #food source and often trapped in pockets of isolated areas with no way out and often wander onto plantations searching for food. The orangutan are considered a pest by many of the oil palm companies as they often destroy young palm plants in the hope of finding food.​ They are run over by excavation equipment, doused in petrol and burnt alive, captured, tortured, beaten, shot with air guns or slaughtered. As forest home is destroyed they become vulnerable to poachers. Infant orangutans have monetary value and are often kept as pets or illegally smuggled, the only way a mother will let go of her infant is if she has been killed.
#animalrights #wildlife #habitat #vegan #veganism
 
Later posts Earlier posts