Google Under Fire for Circumvention of Cookie Settings in Safari for iOS to Track Users
To get around Safari's default blocking, Google exploited a loophole in the browser's privacy settings. While Safari does block most tracking, it makes an exception for websites with which a person interacts in some way—for instance, by filling out a form. So Google added coding to some of its ads that made Safari think that a person was submitting an invisible form to Google. Safari would then let Google install a cookie on the phone or computer.
The cookie that Google installed on the computer was temporary; it expired in 12 to 24 hours. But it could sometimes result in extensive tracking of Safari users. This is because of a technical quirk in Safari that allows companies to easily add more cookies to a user's computer once the company has installed at least one cookie.
Google halted the practice once it was contacted by The Wall Street Journal about it, but has tried to downplay the impact of the issue.
In a statement, Google said: "The Journal mischaracterizes what happened and why. We used known Safari functionality to provide features that signed-in Google users had enabled. It's important to stress that these advertising cookies do not collect personal information."
In a companion blog post, The Wall Street Journal notes that the loophole that had permitted Google to bypass Safari's privacy protections has been closed in WebKit, the open source engine behind Safari, with the change having been made by two Google engineers. Consequently, Apple could and appears to be preparing to bring that fix to the public version of Safari.An Apple spokesman said: “We are aware that some third parties are circumventing Safari’s privacy features and we are working to put a stop to it.”
An update to the software that underlies Safari has closed the loophole that allows cookies to be set after the automatic submission of invisible forms. Future public versions of Safari could incorporate that update. The people who handled the proposed change, according to software documents: two engineers at Google.
Top Rated Comments
(View all):rolleyes:
The really shocking thing is that very smart people within the company noted this loophole and designed the workaround. Did their ethical light-bulbs never go on? Can the government subpoena email records to see how high up the company people knew about this evil act?
Google exploits it.
Google fixes it (both on their end, and in Webkit project source)
Sounds like it really was purely unintentional. It's such a short lived behavior, they can't really get anything significant out of it.
Non-issue, only newsworthy because it's mildly interesting.
Yup, I "unintentionally" write lines of code all the time that exploit loopholes that benefit me.
[ Read All Comments ]

Accessory maker Moshi has released a new ultra-thin plastic shell protective case for the 11" and 13" MacBook Air models. This type of plastic case tends to be especially popular among...
Blizzard Entertainment said this week that it sold more than 3.5 million copies of Diablo III on launch day, setting the record for fastest-selling PC game. The company also sold 1.2 million copies...
Hard drive maker Seagate has announced it will purchase data storage device maker LaCie for roughly $186 million.
The company plans to buy the controlling stake owned by Philippe Spruch,...
Intuit has upgraded the iOS app for its Mint personal finance tool with two new "most-requested" features that should keep users from ever having to go to the Mint.com website. Until now,...