In November of last year, a report from the German news program Panorama 3 revealed that several browser extensions were selling their users' browsing histories to the highest bidder. Now we have a sequel to that report, presented by journalist Svea Eckert and researcher Andreas Dewes at the latest DEF CON conference in Las Vegas. In simple terms, they managed to accumulate three billion URLs belonging to three million German users—and all they did was create a fake marketing company.

Your Search History Isn't as Anonymous as You Think
Privacy

The Scale of the Problem

"If you don't pay for a service, you are the product." This phrase has been repeated millions of times and translated into dozens of languages. Many have criticized it, but as we learn more about the practices of certain companies, we rediscover its validity. We've said it before: Big Data doesn't feed itself. Data collection, pattern analysis of browsing, telemetry... it all goes in the same direction. And the volume is truly chilling. Imagine for a moment three billion URLs. Entire lives pass through those links, and if someone executes the right maneuvers, they can obtain them without paying a penny.

Your Search History Isn't as Anonymous as You Think
Three billion addresses, three million users, thirty days. Imagine the amount of data being recorded...

How They Got the Data

That's what journalist Svea Eckert and researcher Andreas Dewes demonstrated at the latest DEF CON convention. The first step was to create a fake company that theoretically dedicated itself to marketing. Many images, an impeccable LinkedIn profile for its CEO, and a careers portal to join the team, so convincing that they even received some applications. The company's latest project was an algorithm based on deep learning that could improve product placement, as long as it trained with a large data package. The process turned out to be a bit longer than expected because the "company" was only interested in information from German users, but finally they obtained it for free, courtesy of a broker interested in evaluating the algorithm.

De-anonymization

The worst part is that Dewes managed to "de-anonymize" a good portion of the users. A clear example comes from those who visit Twitter's analytics section: the URL contains the account name, and supposedly only the user can see it, so it automatically identifies them. In the worst case, just ten addresses would be enough to identify someone, and frankly they've already done it. Don't forget that Netflix was sued for a similar situation in 2009 and had to reach a private settlement.

Source: The Guardian