Study: 86% of top websites expose visitors to third-party tracking cookies

How prevalent is the use of tracking cookies that get planted on your computer after browsing a website so it can keep track of what you're doing? Turns out that not only do the major websites like to plant their own tracking cookies on you, they're also happy to stick a lot of third-party cookies on you, too.

Does two-factor authentication need to be fixed?

According to Keynote Systems, an analysis it did of online behavioral tracking on 269 top websites across four industries — "news & media," "financial services," "travel & hospitality," and "retail," -- showed that 86% of the sites place one or more third-party tracking cookies on their visitors.

Keynote Systems, whose long-time services include performance-monitoring of websites, also says its study shows that 60% of these third-parties had at least one tracker that didn't promise to comply with at least one common tracking standard. Keynote says that of the 211 third-party trackers it identified, "only one committed to honor a visitor's request not to be tracked via the new 'Do Not Track' feature." This gives consumers a way to opt out if being tracked. Keynote says it also checked to figure out if there was a "promise to anonymize data."

Keynote found that nearly all the websites in the "travel & hospitality" and "news & media" categories have third-party tracking. The "news & media" sites are said to "expose site visitors to an average 14 unique third-party tracking companies during the course of a typical visit." Keynote also adds that it was also "surprising" that three out of four websites in the "financial services" category also "expose visitors to third-party tracking."

Keynote Systems says the tracking phenomenon is all about advertising and revenues that websites can pull in.

"Behavioral advertising, a common use of third-party tracking data, is an increasingly common practice on the Web and one of the primary ways websites fund their operations. Third-party trackers place cookies on the browsers of site's visitors to track a user's clicks and path through the Web. They can also make note of things like what the visitor buys and where the visitor goes once they leave."

Ray Everett, Keynote's director of privacy services, says it all reflects a "'wild West' mentality" and that "aggressive tracking companies" could be placing website publishers in a difficult position and even exposing them to legal risk. But he points out the "burden of policing third-party trackers falls squarely on the shoulders of website publishers" because they are clearly responsible for their content and brand reputation.

Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security.

Read more about wide area network in Network World's Wide Area Network section.

Comments

Windows Phone

1

Hello there! Would you mind if I share your blog with my facebook group?
There's a lot of folks that I think would really enjoy your content. Please let me know. Thank you

Windows Phone

2

Hello there! Would you mind if I share your blog with my facebook group?
There's a lot of folks that I think would really enjoy your content. Please let me know. Thank you

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Email Malware Protection System

The FireEye Email Malware Protection System (MPS) secures against spear phishing email attacks that bypass anti-spam and reputation-based technologies.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.