Feeds

Google illegally divulges user searches, suit claims

HTTP referrer headers: SEO's best friend

Top three mobile application threats

Attorneys on Monday accused Google of intentionally divulging millions of users' search queries to third parties in violation of federal law and its own terms of service.

The complaint, filed in federal court in San Jose, California, challenges Google's longstanding practice of including search terms in HTTP referrer headers, which are easily readable by websites that users click on. It claims Google has repeatedly experimented with systems that keep search terms private but has has never rolled them out because it has a vested interest in sharing the information with third parties, including search engine optimization services.

“Over protests from privacy advocates, however, Google has consistently and intentionally designed its services to ensure that user search queries, which often contain highly-sensitive and personally-identifiable information ('PII'), are routinely transferred to marketers, data brokers, and sold and resold to countless other third parties,” the complaint alleges.

The lawsuit goes on to say that Google can cross reference search terms with data held by DoubleClick, which in 2007, the search behemoth agreed to buy for $3.1bln in cash. Combined with a user's IP address and additional information from services including Google Analytics, third parties can connect “the dots of 'anonymous' data” to link queries to a specific individual, a phenomenon known as “reidentification,” the complaint states.

That's precisely what happened in 2006 when AOL released more than 20 million search queries that supposedly had been anonymized. The company soon discovered that many of the 658,000 AOL users in the dataset could be identified making highly personal searches. User data Netflix publicly released to help improve its movie rating system has faced similar problems.

Monday's lawsuit claims that on numerous occasions, Google has experimented with systems that don't share search queries with third-party websites. In November 2008, for instance, the company started testing a method for delivering results that used advanced AJAX technologies. The new system prevented browsers from passing along the search terms to websites, a change that outraged many web masters, who are always eager to know precisely how visitors find their sites.

Google quickly issued a public statement that said: “At this time only a small percentage of users will see this experiment. It is not our intention to disrupt referrer tracking, and we are continuing to iterate on this project and are actively working towards a solution.”

Google soon ended the test, and though similar experiments have since been launched on a limited basis, the complaint alleges.

The lawsuit alleges that the practice violates its own terms of service, which promise that personal information will be shared only with a user's consent. The complaint also claims it runs afoul of the federal Electronic Communications Privacy Act, and a variety of California state laws. The complaint (PDF), which was filed on behalf of a Google user named Paloma Gaos of San Francisco County, seeks class-action status so others can be represented as well.

A Google spokesman declined to comment because, he said, the company has not yet received a copy of the complaint. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
Oracle working on at least 13 Heartbleed fixes
Big Red's cloud is safe and Oracle Linux 6 has been patched, but Java has some issues
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.