ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Online business Toolkit

US Government Web tracking under scrutiny

Declan McCullagh and Anne Broache CNET News.com

Published: 05 Jan 2006 15:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...set up ColdFusion on our Web server, we set the software to its default value," said William Alberque, a spokesman for the Defense Threat Reduction Agency. "The default value, as you saw, creates individual session cookies that can last on your computer for either 30 years or until you delete them." (ColdFusion is Adobe's Web development software.)

Not all monitoring of Web visitors is prohibited. The 2003 directive provides an exception for federal agencies that have a "compelling need," clearly disclose the tracking and have approval from the agency head. In addition, the directive does not apply to state government Web sites, court Web sites or sites created by members of Congress.

The perils of third-party cookies
Probably the most intrusive type of tracking comes from third-party cookies set by commercial vendors. Such cookies permit correlation of visits to thousands of Web sites. A visitor to the Pentagon's Web site could be identified as the same person who stopped by Hilton.com and HRBlock.com — because both of those companies are WebTrends customers.

For its part, WebTrends says it does not correlate that information. "There are companies that tried to do that in the past and got a lot of bad public exposure," said Brent Hieggelke, WebTrends' vice-president of corporate marketing.

"We do not track cross-site traffic," Hieggelke said. "We do not offer any services that let you understand cross-domain traffic at unrelated sites at all."

Privacy advocates tend to be wary of such third-party cookies, however, warning that a change in company management or ownership could result in a policy shift, or that a security breach would expose Web browsing habits.

"If WebTrends has the ability to link the White House visit to the commercial site visit, then that does look like persistent tracking," said Swire, the Ohio law professor. "It would be useful to have a third-party audit of that."

Statcounter.com is another Web-statistics program, used by the Commerce Department and the Energy Department, which also sets third-party cookies.

The company says it does not correlate information from multiple Internet sites. "We do not sell any information to third parties," said its US representative. "All we're interested in gathering is information that can tell [a Webmaster] what area the visitor comes from, what they looked at, what they went back to, data that shows how their sites are used."

During the Clinton administration, the White House's Office of Management and Budget published initial guidelines for federal Web sites in June 1999. That 10-page document gave federal agencies three months to post "clearly labelled and easily accessed" privacy ...

For more, click here... 

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
268 out of 479 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments