Web Browsers White Papers
DoubleClick Opt Out Protocol Failure == Opt In
Overview
A failure to conform to the HTTP protocol specification results in a failure of DoubleClick's opt out mechanism. That is, if you opt out, it's possible that you'll be opted back in behind your back.
Consumer privacy concerns recently forced DoubleClick into supplying consumers with a mechanism to opt out of its tracking machinery. This advisory describes an implementation flaw in DoubleClick's handling of cookies sent from the browser. This defect could result in the consumer being tracked without any knowledge of this activity, contrary to the consumers explicit action of opting out. While testing Netscape 6 Preview Release 1 we discovered aberrant behavior in the DoubleClick opt out mechanism. Following what the DoubleClick server claimed to be a successful opt out, we noticed that the next fetch from a tracked resource would initiate the process of injecting a unique tracking cookie into the browser even though a truly successful opt out should have resulted in an id=OPT_OUT cookie being returned to the server instead.
| Publisher | Interhack Corporation | File Format | HTML & PDF |
|---|---|---|---|
| Date Published | May 2000 | Downloads | 7 |
| Format | White Papers | ||
| Topics | |||



