Skip to main content
QUICK REVIEW

[论文解读] Cookies Invading Our Privacy for Marketing Advertising and Security Issues

Sowmyan Jegatheesan|arXiv (Cornell University)|May 10, 2013
Privacy, Security, and Data Protection被引用 3
一句话总结

本文探讨了第三方Cookie如何实现针对目标广告的普遍在线追踪,引发严重的隐私和安全问题。文章认为,未经用户同意或透明披露而广泛使用Cookie,构成对隐私的侵犯,尤其是当结合JavaScript和Flash技术在多个网站间对用户进行画像时,尽管缺乏监管监督或明确披露。

ABSTRACT

Privacy has been a major concern for everybody over the internet. Governments across the globe have given their views on how the internet space can be managed effectively so that there is some control on the flow of confidential information and privacy to users and as well as to data is achieved. Taking advantage of the lack of one unified body that could govern the online space with its strict and stringent rules certain websites use the text files called cookies in collecting data from users and using them for marketing them in advertisements networks and third party websites with the help of JavaScript and flash technologies. Even before many of us think what is happening around us in the online usage we are being invaded by the cookies and are targeted with their specific information that could tempt us to buy a product or service to which we were longing for in the recent past. Though it may be argued its a kind of marketing strategy to give the customer what he wants but it can no way be something like the user is just being targeted because he has already shown interest in something and he should be disturbed until he gets hold of something. Its purely a security breach as most of the websites dont ask permission for the usage of cookies and setting them into the users browser and the most important thing is no privacy statement is issued that the information is used for targeted marketing. This analysis paper has views from different sources, an example of such an activity that is a potential security breach and various other information of what these sites do to use the deadly cookies for commercial tricks.

研究动机与目标

  • 分析Cookie在实现跨网站用户追踪以支持目标广告中的作用。
  • 突出网站在Cookie部署过程中缺乏用户同意和透明度的问题。
  • 识别与第三方Cookie及追踪技术相关的安全和隐私风险。
  • 考察在线数据收集和用户隐私缺乏统一监管的现状。
  • 展示Cookie如何在用户无意识的情况下被用作商业操纵的工具。

提出的方法

  • 对隐私、数据收集和在线追踪机制的文献与政策进行综述。
  • 分析Cookie、JavaScript和Flash等技术机制在跨网站用户画像中的作用。
  • 回顾实际的基于Cookie的追踪案例,以说明隐私泄露情况。
  • 评估Cookie部署过程中缺乏用户同意和隐私声明的问题。
  • 将当前实践与理想的隐私标准和监管框架进行比较。
  • 使用互联网广告生态系统中的案例研究,展示追踪行为。

实验结果

研究问题

  • RQ1第三方Cookie如何实现对用户在多个网站间的持续追踪?
  • RQ2未经同意使用Cookie所关联的主要隐私和安全风险是什么?
  • RQ3尽管已知存在风险,为何在Cookie部署中仍缺乏透明度和用户同意?
  • RQ4JavaScript和Flash等技术如何增强基于Cookie的追踪效果?
  • RQ5缺乏统一监管机构对在线数据隐私有何影响?

主要发现

  • Cookie被广泛用于在用户不知情或未明确同意的情况下追踪其在多个网站上的活动。
  • 许多网站部署Cookie,但未提供关于其用于目标广告的使用情况的清晰隐私声明。
  • JavaScript和Flash技术的使用放大了Cookie的追踪能力,实现了对用户的详细画像。
  • 缺乏中央监管机构使得网站能够利用隐私保护中的技术漏洞。
  • 用户基于其浏览行为被投放目标广告,通常并不了解其原因或机制。
  • 本文结论认为,当前的Cookie实践严重侵犯了用户隐私和数据安全。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。