You are the product. It's a particularly dark facet of the "free" programs and services on the web, and despite calls for greater transparency, it's clear that the practice continues, even if in the background. The folks at Motherboard and PCMag have just published an investigation based on leaked documents from an Avast subsidiary called Jumpshot. The documents confirm the sale of data collected by the Avast antivirus, including searches, clicks, and online purchases, but if there's anything as worrying as this extraction, it's the list of buyers...
The Investigation: Avast and Jumpshot
Avast officially reports some 435 million active users. The main engine behind that number is its free antivirus, and it's not crazy to imagine the company trying to monetize it. The question is: how far is it willing to go? The first point of conflict arose in October last year, when the creator of the Adblock Plus extension, Wladimir Palant, published on his personal blog that Avast and AVG extensions were collecting a massive amount of data, to such a level that it was possible to reconstruct complete browsing histories and much of the user's behavior on the web.
After an initial block by Firefox, Avast confirmed that it would launch more 'transparent' versions of its extensions... but everything seems to indicate that its definitive move was to move the collection mechanism to the antivirus itself. An investigation published by Motherboard and PCMag, based on leaked documents from the subsidiary Jumpshot (which Avast acquired in 2013), reveals that Avast is selling sensitive information from its users to very high-profile clients, among which stand out Google, Microsoft, Pepsi, IBM, L'Oreal, Condé Nast, and Home Depot.
What Data Is Being Collected and Sold?
Now, it's supposed that data collection in Avast is opt-in, but not a few users ignored the sale of that information to third parties. A more advanced analysis confirms the obtaining of Google searches, locations and GPS coordinates on Google Maps, visits to company profiles on LinkedIn, YouTube videos, and accesses to adult content portals (PornHub, YouPorn). In fact, the terms used on those portals also appear, and even specific videos. This mega-package of data does not include personal identification elements, however, it is not possible to rule out the possibility of de-anonymizing some users.
The commercialization of this data is carried out under different product lines offered by Jumpshot to its clients. One of the most disturbing is called 'All Click Feed', and allows all interested parties to acquire details about the clicks that Jumpshot detects on particular domains, such as Amazon, Walmart, Target, Best Buy or eBay. Even on its Twitter account they talk about "Each search. Each click. Each purchase. On every site.".
Paying a Fortune for Data
And they are paying a real fortune. A New York marketing company, Omnicom Media, paid more than six and a half million dollars for access to data in 2019, 2020 and 2021. What Omnicom received so far are the click feeds in 14 different countries, from the United States to New Zealand. Based on "browsing behavior", the product "deduces" the gender of the user, and their age.
The Anonymization Problem
And so we come to another worrying aspect: Each user history has a "Device ID" assigned permanently. If someone combines enough data, that Device ID could undo any attempt at anonymization. According to Eric Goldman, director of the High Tech Law Institute at Santa Clara University, it is "almost impossible" to anonymize or de-identify data. In short, until a more advanced policy of transparency and privacy comes into effect, we can only recommend the uninstallation of Avast, AVG, and all their associated products.
Sources: Motherboard and PCMag