Feeds

Google illegally divulges user searches, suit claims

HTTP referrer headers: SEO's best friend

Secure remote control for conventional and virtual desktops

Attorneys on Monday accused Google of intentionally divulging millions of users' search queries to third parties in violation of federal law and its own terms of service.

The complaint, filed in federal court in San Jose, California, challenges Google's longstanding practice of including search terms in HTTP referrer headers, which are easily readable by websites that users click on. It claims Google has repeatedly experimented with systems that keep search terms private but has has never rolled them out because it has a vested interest in sharing the information with third parties, including search engine optimization services.

“Over protests from privacy advocates, however, Google has consistently and intentionally designed its services to ensure that user search queries, which often contain highly-sensitive and personally-identifiable information ('PII'), are routinely transferred to marketers, data brokers, and sold and resold to countless other third parties,” the complaint alleges.

The lawsuit goes on to say that Google can cross reference search terms with data held by DoubleClick, which in 2007, the search behemoth agreed to buy for $3.1bln in cash. Combined with a user's IP address and additional information from services including Google Analytics, third parties can connect “the dots of 'anonymous' data” to link queries to a specific individual, a phenomenon known as “reidentification,” the complaint states.

That's precisely what happened in 2006 when AOL released more than 20 million search queries that supposedly had been anonymized. The company soon discovered that many of the 658,000 AOL users in the dataset could be identified making highly personal searches. User data Netflix publicly released to help improve its movie rating system has faced similar problems.

Monday's lawsuit claims that on numerous occasions, Google has experimented with systems that don't share search queries with third-party websites. In November 2008, for instance, the company started testing a method for delivering results that used advanced AJAX technologies. The new system prevented browsers from passing along the search terms to websites, a change that outraged many web masters, who are always eager to know precisely how visitors find their sites.

Google quickly issued a public statement that said: “At this time only a small percentage of users will see this experiment. It is not our intention to disrupt referrer tracking, and we are continuing to iterate on this project and are actively working towards a solution.”

Google soon ended the test, and though similar experiments have since been launched on a limited basis, the complaint alleges.

The lawsuit alleges that the practice violates its own terms of service, which promise that personal information will be shared only with a user's consent. The complaint also claims it runs afoul of the federal Electronic Communications Privacy Act, and a variety of California state laws. The complaint (PDF), which was filed on behalf of a Google user named Paloma Gaos of San Francisco County, seeks class-action status so others can be represented as well.

A Google spokesman declined to comment because, he said, the company has not yet received a copy of the complaint. ®

Beginner's guide to SSL certificates

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.