Forum Moderators: open

Message Too Old, No Replies

Yahoo Web Beacons- are they malevolent?

Rumor spreading that they are spyware

         

Automan Empire

1:58 am on May 18, 2005 (gmt 0)

10+ Year Member



I'm noticing a rumor starting to spread about Yahoo's web beacons. People are saying that they are used to track where everyone surfs, etc. The biggest potential concern to webmasters is that the rumor is circulating with instructions to disable beacons on your computer. (I understand they have benevolent applications like seeing if a particular e-mail was read.)

Would anyone care to elaborate on the purpose of Web Beacons, particularly if they are something to be concerned about for the average (nontechnical) web surfer? Thanks.

martinibuster

4:06 am on May 18, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Not spyware.
[privacy.yahoo.com...]

Ordinary stuff.

Automan Empire

7:00 am on May 18, 2005 (gmt 0)

10+ Year Member



I guess it's the same kind of overreaction as when cookies were new.
Thanks for the response. We'll see if this is a small or large paranoia bubble.

Meanwhile, anyone care to expand on the concept? I didn't find much on WW, the best I could search. I read about them being a 1-pixel image that can be called from remote websites, emails with HTML, etc, which then pulls information strings about the user. Am I kind of right so far?
Pretty clever, really, as long as it's not bad...

StupidScript

6:05 pm on May 18, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



martinibuster ... while it is surely "normal" it is also definitely "spyware".

From the "Outside the Yahoo! Network" paragraph:

Information recorded through these web beacons is used to report aggregate information about Yahoo! users to our partners. This aggregate information may include demographic and usage information. No personally identifiable information about you is shared with partners from this research.

(emphasis mine)

Although Y! insists in the next paragraph that they require partners who use the Y! beacon system to disclose that info, etc., I ask you: have you ever seen such a disclosure on a Y! partner site? Have you ever been offered a chance to deny the beacon, as you would a cookie?

"Spyware" is a piece of software (in this case activated by the inclusion of a 'web bug') that collects information from you and your system without your knowledge. In this case, page views, geographic, bandwidth, IP, user-agent and other information. Sure Y! doesn't share your IP address (personally-identifiable info), but they certainly collect it.

Unless a beacon is clearly identified and you have been asked permission for its use, you are being saddled with an undetected piece of spyware. The onus is on Y! to fully disclose that this piece of software is GOING TO BE installed (however lightly) on your system, and for what purpose, just like any other piece of spyware. It is not your responsibility to determine the presence of a beacon and get rid of it, despite their most-generous offer to let you opt-out of the program ... should you manage to find your way over to the web beacon/privacy page you linked to.

You can set your browser to warn you before accepting a cookie. Can you set it to warn you before accepting a web beacon? No.

There is a fundamental difference in the security permissions required and the availability to the host between cookies and beacons, as Y! beacons can (and do) send data to Y! from any site their code is placed on whereas Y! cookies can only be read from Y!'s own servers/domains.

They use beacons because of this, to supplement the Y! localized data they gather using cookies and sessions. They are not the same thing.

martinibuster

6:44 pm on May 18, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Spyware is SOFTWARE, hence the suffix "ware". Beacons are not software. This is just an image pinging a server. No big deal.

Additionally you can opt out, which makes it as inconsequential as anything can be. No story here. No big deal.

StupidScript

8:54 pm on May 18, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



You're right ... the beacons themselves are just the trigger for the software. Nonetheless, they are an integral part of the spyware .. remove them and you've got no program at all.

You can only opt-out if you (a) are aware that they exist, (b) can find the opt-out form and then (c) determine that the opt-out procedure (based on the IP used in the opt-out process ... gotta do it for every IP address you may use, dial-up or otherwise) has functioned correctly.

Opt-out = spyware/malware behavior
Opt-in = ethical behavior

If they do not inform you that a bug has been planted on your system, they are behaving like malware producers. If they DO inform you that a bug is about to be planted on your system, and offer you a choice of whether you wish to include your system in the operation of their program, THAT's ethical behavior.

Did you know when Y! planted their first bug on your system? I'll bet 99.9% of Y! users do not know that they are bugged, and so would not begin to know how to opt-out.

Opt-out is like adding a line of text in invisble ink on a car repair bill that says "You authorize us to debit your bank account whenever we want to" and then telling you after the fact that you can opt-out of that clause ... if you catch them debitting your account.

How about "opt-out and remove all traces of any of my data from your system"? Not gonna happen.

It's only legal for now because nobody has challenged it significantly.

Automan Empire

4:46 pm on May 19, 2005 (gmt 0)

10+ Year Member



Thanks for the info and analysis, script. Sounds like I'm onto something after all...