Skip to main content

2015 | OriginalPaper | Buchkapitel

Purchase Details Leaked to PayPal

verfasst von : Sören Preibusch, Thomas Peetz, Gunes Acar, Bettina Berendt

Erschienen in: Financial Cryptography and Data Security

Verlag: Springer Berlin Heidelberg

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

We describe a new form of online tracking: explicit, yet unnecessary leakage of personal information and detailed shopping habits from online merchants to payment providers. In contrast to Web tracking, online shops make it impossible for their customers to avoid this proliferation of their data. We record and analyse leakage patterns for N = 881 US Web shops sampled from Web users’ actual online purchase sessions. More than half of the sites shared product names and details with PayPal, allowing the payment provider to build up comprehensive consumption profiles across the sites consumers buy from, subscribe to, or donate to. In addition, PayPal forwards customers’ shopping details to Omniture, a third-party data aggregator with an even larger tracking reach. Leakage to PayPal is commonplace across product categories and includes details of medication or sex toys. We provide recommendations for merchants.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
3.
Zurück zum Zitat OECD: The OECD Privacy Framework (2013) OECD: The OECD Privacy Framework (2013)
4.
Zurück zum Zitat European Commission: Proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (2012) European Commission: Proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (2012)
6.
Zurück zum Zitat Bonneau, J., Preibusch, S.: The privacy jungle: on the market for data protection in social networks. In: Eighth Workshop on the Economics of Information Security (WEIS) (2009) Bonneau, J., Preibusch, S.: The privacy jungle: on the market for data protection in social networks. In: Eighth Workshop on the Economics of Information Security (WEIS) (2009)
7.
Zurück zum Zitat Bonneau, J., Preibusch, S.: The password thicket: technical and market failures in human authentication on the web. In: Ninth Workshop on the Economics of Information Security (WEIS) (2010) Bonneau, J., Preibusch, S.: The password thicket: technical and market failures in human authentication on the web. In: Ninth Workshop on the Economics of Information Security (WEIS) (2010)
8.
Zurück zum Zitat Preibusch, S., Bonneau, J.: The privacy landscape: product differentiation on data collection. In: Schneier, B. (ed.) Economics of Information Security and Privacy III, pp. 263–283. Springer, New York (2013)CrossRef Preibusch, S., Bonneau, J.: The privacy landscape: product differentiation on data collection. In: Schneier, B. (ed.) Economics of Information Security and Privacy III, pp. 263–283. Springer, New York (2013)CrossRef
9.
Zurück zum Zitat Krishnamurthy, B., Wills, C. E.: On the leakage of personally identifiable information via online social networks. In: Proceedings of the 2nd ACM Workshop on Online Social Networks (WOSN) (2009) Krishnamurthy, B., Wills, C. E.: On the leakage of personally identifiable information via online social networks. In: Proceedings of the 2nd ACM Workshop on Online Social Networks (WOSN) (2009)
10.
Zurück zum Zitat Soltani, A., Canty, S., Mayo, Q., Thomas, L., Hoofnagle, C.J.: Flash Cookies and Privacy. In: Intelligent Information Privacy Management, Papers from the 2010 AAAI Spring Symposium, Technical report SS-10–05 (2010) Soltani, A., Canty, S., Mayo, Q., Thomas, L., Hoofnagle, C.J.: Flash Cookies and Privacy. In: Intelligent Information Privacy Management, Papers from the 2010 AAAI Spring Symposium, Technical report SS-10–05 (2010)
11.
Zurück zum Zitat Ayenson, M., Wambach, D.J., Soltani, A., Good, N., Hoofnagle, C.J.: Flash cookies and privacy II: now with HTML5 and ETag respawning, SSRN (2011) Ayenson, M., Wambach, D.J., Soltani, A., Good, N., Hoofnagle, C.J.: Flash cookies and privacy II: now with HTML5 and ETag respawning, SSRN (2011)
12.
Zurück zum Zitat Acar, G., Eubank, C., Englehardt, S., Juarez, M., Narayanan, A., Diaz, C.: The web never forgets: persistent tracking mechanisms in the wild. In: Proceedings of CCS 2014 (2014) Acar, G., Eubank, C., Englehardt, S., Juarez, M., Narayanan, A., Diaz, C.: The web never forgets: persistent tracking mechanisms in the wild. In: Proceedings of CCS 2014 (2014)
13.
Zurück zum Zitat Eckersley, P.: How unique is your web browser? In: Atallah, M.J., Hopper, N.J. (eds.) PETS 2010. LNCS, vol. 6205, pp. 1–18. Springer, Heidelberg (2010)CrossRef Eckersley, P.: How unique is your web browser? In: Atallah, M.J., Hopper, N.J. (eds.) PETS 2010. LNCS, vol. 6205, pp. 1–18. Springer, Heidelberg (2010)CrossRef
14.
Zurück zum Zitat Acar, G., Juarez, M., Nikiforakis, N., Diaz, C., Gürses, S., Piessens, F., P, B.: FPDetective: Dusting the web for fingerprinters. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communications Security (2013) Acar, G., Juarez, M., Nikiforakis, N., Diaz, C., Gürses, S., Piessens, F., P, B.: FPDetective: Dusting the web for fingerprinters. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communications Security (2013)
15.
Zurück zum Zitat Tsai, J.Y., Egelman, S., Cranor, L., Acquisti, A.: The effect of online privacy information on purchasing behavior: an experimental study. Inf. Syst. Res. 22(2), 254–268 (2011)CrossRef Tsai, J.Y., Egelman, S., Cranor, L., Acquisti, A.: The effect of online privacy information on purchasing behavior: an experimental study. Inf. Syst. Res. 22(2), 254–268 (2011)CrossRef
16.
Zurück zum Zitat Jentzsch, N., Preibusch S., Harasser, A.: Study on monetising privacy. An economic model for pricing personal information European Network and information Security Agency (ENISA) (2012) Jentzsch, N., Preibusch S., Harasser, A.: Study on monetising privacy. An economic model for pricing personal information European Network and information Security Agency (ENISA) (2012)
17.
Zurück zum Zitat Preibusch, S., Kübler, D., Beresford, A.R.: Price versus privacy: an experiment into the competitive advantage of collecting less personal information. Electron. Commer. Res. 13(4), 423–455 (2013)CrossRef Preibusch, S., Kübler, D., Beresford, A.R.: Price versus privacy: an experiment into the competitive advantage of collecting less personal information. Electron. Commer. Res. 13(4), 423–455 (2013)CrossRef
24.
Zurück zum Zitat Dempster, A.P., Laird, N.M., Rubin, D.B.: Maximum likelihood from incomplete data via the EM algorithm. J. Roy. Stat. Soc.: Ser. B (Methodol.) 39(1), 1–38 (1977)MathSciNetMATH Dempster, A.P., Laird, N.M., Rubin, D.B.: Maximum likelihood from incomplete data via the EM algorithm. J. Roy. Stat. Soc.: Ser. B (Methodol.) 39(1), 1–38 (1977)MathSciNetMATH
28.
Zurück zum Zitat Krishnamurthy, B., Wills, C.: Privacy diffusion on the web: a longitudinal perspective. In: Proceedings of the 18th International Conference on World Wide Web (WWW) (2009) Krishnamurthy, B., Wills, C.: Privacy diffusion on the web: a longitudinal perspective. In: Proceedings of the 18th International Conference on World Wide Web (WWW) (2009)
Metadaten
Titel
Purchase Details Leaked to PayPal
verfasst von
Sören Preibusch
Thomas Peetz
Gunes Acar
Bettina Berendt
Copyright-Jahr
2015
Verlag
Springer Berlin Heidelberg
DOI
https://doi.org/10.1007/978-3-662-47854-7_13

Premium Partner