One Of The World's Largest Web Tracking Companies Leaks Tons Of Personal Info From An Unsecured Server

from the so-happy-to-have-contributed-to-the-leak-by-using-the-internet dept

Advertisers want to know everything about you. So do sites that buy ad inventory and allow middlemen to let their trackers run free, tracing people from site to site, following them into their email inboxes, and tracking them across platforms and devices if need be.

BlueKai, owned by Oracle, deploys these pervasive trackers, sinking its hooks into a reported 1% of the world's internet traffic. BlueKai is the kind of clever no one really respects. It's more along the lines of "devious." But it is very, very effective.

BlueKai relies on vacuuming up a never-ending supply of data from a variety of sources to understand trends to deliver the most precise ads to a person’s interests.

[...]

BlueKai… uses more covert tactics like allowing websites to embed invisible pixel-sized images to collect information about you as soon as you open the page — hardware, operating system, browser and any information about the network connection.

[...]

BlueKai can also tie your mobile web browsing habits to your desktop activity, allowing it to follow you across the internet no matter which device you use.

All the information BlueKai grabs has to go somewhere so it can be packaged and sold to marketers. Considering how much data BlueKai is able to obtain about the average internet user, you'd think it would place a premium on keeping this data secure -- if not for the security of unsuspecting trackees, then to prevent its valuable stash from falling into a competitor's hands.

Unfortunately for a whole lot of internet users, BlueKai doesn't seem to believe this information -- or the people who generated it -- is worth protecting.

[F]or a time, that web tracking data was spilling out onto the open internet because a server was left unsecured and without a password, exposing billions of records for anyone to find.

Security researcher Anurag Sen found the database and reported his finding to Oracle through an intermediary — Roi Carthy, chief executive at cybersecurity firm Hudson Rock and former TechCrunch reporter.

TechCrunch reviewed the data shared by Sen and found names, home addresses, email addresses and other identifiable data in the database. The data also revealed sensitive users’ web browsing activity — from purchases to newsletter unsubscribes.

Oracle's response was to blame "two companies" for "not properly configuring their services." The two companies have not been named. Whoever these companies are, they collect data on a wide range of activities. TechCrunch examined the exposed data and found extensive records tied to individuals -- an astonishing pool of data that even indicated if a tracked person's device was in need of a software update. That's on top of the wealth of purchase and internet history that linked people to purchases, web searches, and other activity. Sitting in with everything else was personally identifiable info like addresses, phone numbers, and email addresses.

Very few people want all of this information in the hands of marketers. (BlueKai says it strips identifiable info before handing it over to its ad-serving customers.) And they definitely don't want it in the hands of people even more nefarious than ordained spyware pushers like BlueKai. The company has created a one-stop shop for phishers, stalkers, and identity thieves. And then it left the door unlocked for an undetermined amount of time.

Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

Filed Under: cookies, data leak, personal info, privacy, security, tracking
Companies: bluekai, oracle


Reader Comments

Subscribe: RSS

View by: Time | Thread


  1. icon
    tom (profile), 23 Jun 2020 @ 9:01am

    The investigation will likely find that the 'Two Companies' have few assets subject to tort recovery and the contracts between the companies and Oracle and others clearly put all financial responsibility on the 'Two Companies'.

    Wouldn't be surprised if said contracts are being printed off now and back dated by a fully activated Oracle legal staff.


Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here



Subscribe to the Techdirt Daily newsletter




Comment Options:

  • Use markdown. Use plain text.
  • Make this the First Word or Last Word. No thanks. (get credits or sign in to see balance)    
  • Remember name/email/url (set a cookie)

Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

Introducing the new Techdirt Insider Chat, now hosted on Discord. If you are an Insider with a membership that includes the chat feature and have not yet been invited to join us on Discord, please reach out here.

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.