Raw Chili · @rawchili
14 followers · 655 posts · Server mstdn.social
Raw Chili · @rawchili
12 followers · 299 posts · Server mstdn.social
Raw Chili · @rawchili
6 followers · 223 posts · Server mstdn.social
Raw Chili · @rawchili
4 followers · 124 posts · Server mstdn.social
Raw Chili · @rawchili
2 followers · 65 posts · Server mstdn.social
Adriano Pitteri · @Pitteri
72 followers · 700 posts · Server framapiaf.org
Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

While Avast is planning to shut down Jumpshot, there is an ongoing investigation into their practices. I wonder how this will go, according to Avast they are fully compliant...

uoou.cz/en/vismo/dokumenty2.as

#gdpr #avast #Jumpshot #privacy

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Even this limited sample contains lots of names, email addresses and even home addresses of Avast users. Jumpshot customers could have easily deanonymized the users the data belongs to, and some probably did.

#avast #Jumpshot #privacy

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

I got my hands on a sample of Jumpshot data. My analysis confirms what everybody already suspected: Avast failed anonymizing the data they sold, leaving plenty of personal data untouched.

palant.de/2020/02/18/insights-

#avast #Jumpshot #privacy

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Received an press release via email, apparently they are shutting down. Which is the right consequence if you look at their stock price. The reason is of course that "some users questioned our mission" which is as close to "we messed up" as it will probably get.

#avast #Jumpshot

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

There is a considerable body of evidence suggesting that was selling data of users without any aggregation, despite Avast claiming the opposite. And their anonymization approach is inherently incomplete. palant.de/2020/01/27/avasts-br

#Jumpshot #avast

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

keeps stating that any data shared with was "de-identified." Experts have been skeptical (in fact, I found a four years old quote from @gcluley on the matter) and I now found quite a bit of info suggesting that they were right.

palant.de/2020/01/27/avasts-br

#avast #Jumpshot #privacy

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Unfortunately, further communication here is muddying the waters. It now seems that doesn't give up on sharing data with after all, merely making it an opt-in thing for users of the free antivirus app. Still a lot better than before but not the same thing.

#avast #Jumpshot

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

And of course nothing changes about selling this data via . Because, and that is 's official position, all the data is anonymized (or do they mean pseudonymized?) so this is absolutely unproblematic. 🙈🙉🙊

#Jumpshot #avast

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Oh, and while you are at it, could you take care of Avast SafePrice browsing extension as well? It has the same code, it's also transferring the entire browsing history to uib.ff.avast.com - to be sold for "consumer analytics" via .

#Jumpshot

Last updated 5 years ago