Privacy leakage on the Internet
|
|
|
- Garry Chapman
- 10 years ago
- Views:
Transcription
1 Privacy leakage on the Internet Balachander Krishnamurthy AT&T Labs Research Joint work with Craig E. Wills, AT&T Labs Research 1
2 Talk outline 1. Privacy footprint: a longitudinal study report 2. Personally identifiable information leakage in Online Social Networks 3. Some IETF mumbling AT&T Labs Research 2
3 July , New Yorker, Peter Steiner s cartoon Sadly, this cartoon is out of date. AT&T Labs Research 3
4 Internet and Web Privacy Security is about keeping unwanted traffic from entering our network Privacy is about keeping wanted information from leaving our network Privacy is thus the dual of security Privacy can be examined at user-, organizational-, ISP-level Higher awareness due to e-commerce, new demographics (e.g., children) identity theft, and Online Social Networks. AT&T Labs Research 4
5 Should we care about privacy? Depends on the information disseminated, ability to combine external data, what data collectors might do with it We need to know what information is being diffused, who is tracking it, and how Goal is to allow standard network activity while preserving desired privacy AT&T Labs Research 5
6 Privacy footprint Various daily interactions on the Web (commerce, , search...): Sites use many techniques to track users (1x1 pixel Web bugs, tracking cookies, JavaScript) Aggregators track across sites (dclk, googlesyndication, tacoda) Privacy footprint: measure of dissemination of user-related information across unrelated sites AT&T Labs Research 6
7 First-party vs. Third-Party nodes Connections between first-party visible (servers explicitly visited) and hidden third-party (visited as by-product) nodes Visible Nodes Hidden Nodes online.wsj.com a248.e.akamai.net i.a.cnn.net m.2mdn.net m.doubleclick.net cnn.122.2o7.net americanexpress.122.2o7.net dowjones.122.2o7.net g images.amazon.com AT&T Labs Research 7
8 Third parties 1. Ad Networks: First-party sites (publishers) arrange with ad networks to place ads on their pages via images or javascript code. E.g., Google s Adsense (googlesyndication.com, doubleclick.net), AOL (advertising.com, tacoda.net), Yahoo!(yieldmanager.net) 2. Analytics companies: measure traffic, characterize users by downloading a JavaScript file and send back information in a URL. E.g., google-analytics.com (urchin.js), 2o7.net (Omniture), atdmt.com (Microsoft/aquantive), quantserve.com (Quantcast) 3. CDNs: Serve images, rarely JavaScript. e.g., akamai.net, yimg.com Privacy leaks to all of them. AT&T Labs Research 8
9 Mechanics of our data collection Visible nodes: Popular 1200 Web sites in dozen Alexa categories Extracted hidden nodes corresponding to each visible node via a Firefox extension that fetches objects and records request/response Tests of popular Web sites in 68 countries and 19 languages. Examined cookies, JavaScript, identifying URLs (those with? = &) Narrowed examination to consumer and fiduciary sites: subset of sites that raise more privacy concerns. Study carried out nine times over a five year period: Oct 05, April/Oct 06, Feb/Sep 08, March/June/Sept 09, March 10 AT&T Labs Research 9
10 Node association Two visible nodes are associated if accessing them results in accessing the same hidden node. Association can be due to several reasons: 1. server: Identical server name ( 2. domain: Aggregated by merging hidden nodes with same 2nd-level domain names. E.g. cnn.112.2o7.net and dowjones.112.2o7.net 3. adns: Aggregated by merging hidden nodes that share the same ADNS (authoritative DNS server). e.g. doubleclick.net and ebayobjects.com have the same ADNS. (try dig... NS) AT&T Labs Research 10
11 Cleaning up domain association DNS for third-party servers may be provided by sites like ultradns.net CDNs are increasingly used to serve content for third party servers (e.g., JavaScript or images with cookies) We check ADNS of 3d-party and 1st-party servers if they differ and the ADNS server is not that of a known CDN or DNS service, we use the 3d-party server as the domain e.g. pixel.quantserve.com s ADNS is akamai, so root domain is quantserve.com, but w88.go.com s root domain is omniture.com (based on its ADNS). Root domain: identifies the root cause of the origin for each server AT&T Labs Research 11
12 Association: Common hidden node between two visible nodes CCDF of number of other visible nodes associated with each visible node CCDF of Visible Nodes alledge-root alledge-domain alledge-server Number of Associated Visible Nodes X-axis: Single visible node s maximal association: ( Server: 813 (75%), Domain: 850 (78%), ADNS: 885 (81%) of 1086 nodes. Y-axis: Degree of association: 87% server, 91% domain, 94% ADNS 75% of all visible nodes are associated with over 100 visible nodes AT&T Labs Research 12
13 Cumulative count of unique associated visible nodes Some visible nodes are associated via more than one hidden node. E.g., ( online.wsj.com) with (doubleclick.net, 2o7.net) domains Top-10 associated ADNS nodes connected to 78.5% of visible nodes doubleclick.net, google-analytics.com, 2mdn.net, quantserve.com, scorecardresearch.com, atdmt.com, omniture.com, googlesyndication.com, yieldmanager.com,2o7.net Merging holding companies: Google, Omniture, MSFT, Yahoo, etc. OK to focus on these. AT&T Labs Research 13
14 Hidden Nodes in 68 countries (older data) Hidden nodes appearing in at least 20% of Per-Country Top-10 Lists Number of Appearances Hidden in Country Top-10 Node Hidden Node List (%) google-analytics.com 61 (90%) yahoo.com 58 (85%) yimg.com 47 (69%) googlesyndication.com 44 (65%) doubleclick.net 39 (57%) 2o7.net 31 (46%) atdmt.com 24 (35%) 2mdn.net 22 (32%) statcounter.com 15 (22%) imrworldwide.com 14 (21%) adbrite.com 14 (21%) Google is thus present in 90% of countries top-10 lists. AT&T Labs Research 14
15 Hidden Nodes in 19 languages Top-100 Lists (older data) French, Italian, Portugese, Spanish, English, German, Dutch, Greek, Danish, Norwegian, Finnish, Swedish, Arabic, Turkish, Czech, Russian, Korean, Japanese, Chinese. Weighted average of three footprint metrics: visible nodes association range from 76% to 92%. AT&T Labs Research 15
16 Privacy footprint: longitudinal study Footprint shows the number and diversity of 3d-party sites visited as a result of a user visiting first party sites. We examine the penetration of the top 3d-party domains that aggregate information about user s movements on the Web Multiple 3d-parties may track users on a given first-party site and so this is examined as well Finally, we examine the role of economic acquisitions of aggregator companies that buy others and increase their tracking ability AT&T Labs Research 16
17 Top 3d-party domains over time First-Party Server Extent (%) top-10 doubleclick.net google-analytics.com 2mdn.net quantserve.com scorecardresearch.com atdmt.com 0 Oct 05 Apr 06 Oct 06 Feb 08 Sep 08 Sep 09 Mar 10 Time Epochs Combined impact of the top-10 domains: up from 40% to nearly 80%. AT&T Labs Research 17
18 Manner of tracking Initially just 3d-party cookies, but now through 1st-party cookies and JavaScript. We examined traces of requested objects, cookies and JavaScript downloaded. Four categories of 3d-party domains: 1. Only set 3d-party cookies, no JS (dclk, atdmt, 2o7.net) 2. Use JS with state saved in 1st-party cookies (google-analytics: urchin.js examines 1st-party cookies, forces retrieval via an identifying URL to send information to 3d-party server) 3. Both 3d-party cookies and JS to set 1st-party cookies (quantserve) 4. 3d-party cookies and JS not used to set 1st-party cookies but instead serve ad URLs with tracking information (adbrite, adbureau) AT&T Labs Research 18
19 Situation grimmer in the face of acquisitions Family Acquired Date AOL advertising.com Jun 04 tacoda.net, adsonar.com Jul 07/Dec 07 Doubleclick falkag.net Mar 06 Google youtube.com ($1.65B) Oct 06 doubleclick.net ($3.1B) Mar 07 feedburner.com,admobs.com ($750M) Jun 07/Nov 09 Microsoft aquantive.com (atdmt.com, $6B) May 07 Omniture offermatica.com Sep 07 visual sciences (hitbox.com, $0.4B) Oct 07 Valueclick mediaplex.com Oct 01 fastclick.net Sep 05 Yahoo overture.com ($1.6B) Dec 03 yieldmanager.com, adrevolver.com Apr 07/Oct 07 Adobe Omniture ($1.8B) Sept 09 AT&T Labs Research 19
20 Family 1: Growth of Google Family First-Party Server Extent (%) 70 overlap feedburner 60 doubleclick youtube google-analytics 50 googlesyndication google* Google Family *includes google.com, googleadservices.com and google*.com 10 0 Oct 05 Apr 06 Oct 06 Feb 08 Sep 08 Mar 09 Time Epochs Jun 09 Sep 09 Mar 10 Sep 09 Google family reach: over 70% highest among all third parties by far. AT&T Labs Research 20
21 Family 2: Growth of the Adobe (ne Omniture) Family First-Party Server Extent (%) 70 overlap hitbox 60 offermatica omniture* Omniture Family *includes omniture.com and 2o7.net 10 0 Oct 05 Apr 06 Oct 06 Feb 08 Sep 08 Mar 09 Jun 09 Sep 09 Mar 10 Time Epochs Primarily 2o7.net domain and then acquisitions reach of over 30% Adobe acquired Omniture in September 09 AT&T Labs Research 21
22 Family 3: Reach of the Microsoft Family First-Party Server Extent (%) overlap aquantive^ adbureau microsoft* Microsoft Family ^includes atdmt.com *includes msads.com, msn.com, msft.net and live.com 0 Oct 05 Apr 06 Oct 06 Feb 08Sep 08Mar 09 Jun 09 Sep 09Mar 10 Time Epochs Reach of over 25% in Sep 09, growth from buying Aquantive (atdmt.com). Other families: Yahoo: 22%, AOL: 14% in Sep 09 AT&T Labs Research 22
23 Top-10 Family Growth First-Party Server Extent (%) top-10 Google Omniture quantserve.com Microsoft scorecardresearch.com Yahoo AOL 0 Oct 05 Apr 06 Oct 06 Feb 08 Sep 08 Sep 09 Mar 10 Time Epochs Extent of top-10 families cross 84% in Mar 10 AT&T Labs Research 23
24 Depth of Tracking has also increased Users are being tracked by two or more third-party entities. In Oct 05, 24% of 1200 popular Web sites contained more than one of the top-10 3d-party domains. In Sep 08 this figure had risen to 52% (34% with more than two 3d-parties). It is not enough just to block a single tracking entity. AT&T Labs Research 24
25 Consumer sites Examined 127 consumer sites longitudinal privacy leakage. E.g., apple, blockbuster, buy, ebay, expedia, gap, hilton, ikea, kayak, netflix... Steadily increasing node associations: Oct 05: 58%, Oct 06: 66%, Feb 08: 74%, Sep 09: 80, Mar 10: 84.1% Top aggregator families: google, omniture, yahoo, microsoft, aol, coremetrics, quantserve AT&T Labs Research 25
26 Top-10 3d-party families in Consumer sites over time First-Party Server Extent (%) top-10 Google Omniture Microsoft Yahoo AOL coremetrics.com 0 Oct 05 Apr 06 Oct 06 Feb 08 Sep 08 Sep 09 Mar 10 Time Epochs Top-10 domains account for over 84%. Google family is largest since 08. AT&T Labs Research 26
27 Top-10 3d-Party families in Fiduciary sites over time 81 sites in 9 categories: credit financial insurance medical mortgage shopping subscription travel utility First-Party Server Extent (%) top-10 Google Omniture Microsoft Yahoo AOL revsci.net 0 May 06Oct 06 Time Epochs Oct 08 Sep 09 Mar 10 Top-10 families account for over 70%. AT&T Labs Research 27
28 Growth of Hidden Third-Party Content 70 First-Party Server Extent (%) FirstPartyCookies FirstPartyJS HiddenThirdPartyObj 0 Oct 05 Apr 06 Oct 06 Feb 08 Sep 08 Sep 09 Mar 10 Time Epochs 3d-party aggregators are using 1st-party cookies to track users via 3d-party JavaScript - 70%. Can t reject all 1st-party cookies.. 3d-party JavaScript served by 1st-party server: cannot auto block - over 30%. 20% have 3d-party objects hidden in seemingly 1st-party servers (Omniture s JS on abc.go.com: ident URL for w88.go.com, ADNS shows it is in Omniture) AT&T Labs Research 28
29 Privacy protection measures Currently one can disable cookies and JavaScript execution, filter ads, and block images. Not directly available today, but possible to filter all third-party objects, remove JavaScript content, filter requests with identifying URLs or objects from top aggregation servers. Page rendering may break Best techniques: no3obj, no3js, noaggregators Worst technique: noimg (See our SOUPS07 paper for details) Proxies can also help in obscuring users to some extent. rates browser configuratiions AT&T Labs Research 29
30 Some recent external developments: IE IE 8.0 s InPrivate Filtering (nee InPrivate Browsing), lets users block downloading of content that appear on a specific number of websites Such a line of sight blocking targets specific.js files being downloaded when user visits different sites. On average 41% of 3rd-party domains accessed are in the top-10 domain set and half of these set cookies. AT&T Labs Research 30
31 Privacy policies/leakage/default profiling cuil.com s simple privacy policy Chrome: URL completion (Suggest) leaks any URLs to Google by default Switch to Iron? (Client-ID, Timestamp, Suggest, Error Reporting, RLZ-Tracking, Updater, URL-Tracker) Google toolbar on by default on every Dell sold Specific Media (175M individual profiles) /08/29/AR _2.html AT&T Labs Research 31
32 Part 2: Leakage of PII in OSNs Lots of vague talk about user and privacy loss until now. Aggregators: We only know IP address, no PII about user is ever recorded. Executive Excerpt from June 2008 article by Saul Hansell, NYT Google is quick to point out that some of these systems are not connected to each other. And most of the information it gets is not what is generally considered to be personally identifiable, like a name or address. google-tests-using-your-search-data-to-tailor-ads-to-you Well, they certainly have the opportunity to do so... AT&T Labs Research 32
33 Personally Identifiable Information OMB memorandum Safeguarding Against and Responding to the Breach of Personally Identifiable Information Information which can be used to distinguish or trace an individual s identity. e.g., name, social security number, biometric records. Alone or when combined with other personal or identifying information Linked or linkable to a specific individual. e.g. date and place of birth, mother s maiden name,... AT&T Labs Research 33
34 Longer list of what constitutes PII 1. Name (full name, maiden name, mother s maiden name) 2. Personal ID number (e.g., SSN), address (street/ ), telephone numbers 3. Personal characteristics (photo of face, X-ray, fingerprint, biometric image: retina scan, voice signature, facial geometry) 4. Asset information (IP or MAC address, persistent static ID that consistently links to a particular person or a small, well-defined group 5. Information identifying personally owned property (vehicle registration/vin) 6. Linked/linkable information to any of the above: date/place of birth, race, religion, activities, or employment/medical/education/financial information Well-known result in linking pieces of PII: most Americans (87%) can be uniquely identified from a birth date, zip code, and gender (Sweeney) AT&T Labs Research 34
35 Pieces of PII in OSNs Users are specifically asked for these as part of their OSN profile 1. Name (first and last) 2. Location (city and zip code), address (street/ ) 3. Telephone numbers 4. Photos (both personal and collections) 5. Linkable: gender, birthday, age, birth year, schools, employer, friends, activities Not all profile elements are filled in by users; entries may be false. We did not parse contents of OSN users pages. 12 OSNs studied: Bebo, Digg, Facebook, Friendster, Hi5, Imeem, LinkedIn, LiveJournal, MySpace, Orkut, Twitter and Xanga. AT&T Labs Research 35
36 Degree of availability of PII (to OSN users) in 12 OSNs Always Available Unavailable Always Piece of PII Available by default by default Unavailable Personal Photo Location Gender Name Friends Activities Photo Set Age/Birth Year Schools Employer Birthday Zip Code Address Phone Number Street Address Entries are counts of OSNs; columns go from bad to good wrt privacy concerns. AT&T Labs Research 36
37 Source of leakage OSNs assign unique IDs for their users that may be displayed as part of URL when user navigates around the OSN If the ID stays within the OSN, it is not a problem However, ID is leaked to multiple outsiders, including 3d-party aggregators The ID, in conjunction with the aggregator s tracking cookie leads to the actual privacy leakage The same tracking cookie is sent to the aggregator when the user visits other sites that trigger connections to the aggregator AT&T Labs Research 37
38 Simple illustration Website (non OSN) OSN Aggregator Aggregator agg.cookie User 4 5 OSN.id agg.cookie Aggregator knows who went to (or may go to) non-osn sites as well AT&T Labs Research 38
39 Typical sequence of actions to trigger leakage Purely internal actions within an OSN e.g., user clicks on a list of friends. Action that results in an ad being downloaded from an aggregator site Clicking on an ad Different actions result in OSN ID leakage in different ways. AT&T Labs Research 39
40 Technical manners of leakage At least four broad categories of leakage OSN identifier (pointer to PII) via HTTP headers OSN identifier through external applications Specific pieces of PII Linkages across OSNs and non-osns AT&T Labs Research 40
41 Category 1: OSN ID leakage via HTTP headers 1. via Referer (sic) header (9 of 12 OSNs), problem noted in RFC 1945, May 96 GET /link/click?lid= HTTP/1.1 Host: clickserve.dartsearch.net Referer: 2. via Request-URI (5 of 12 OSNs) GET /utm.gif?...&utmp=utmhn=twitter.com&utmp=/profile/jdoe... Host: Referer: 3. via Cookie (2 of 12 OSNs) GET...g= Host: z.digg.com Referer: Cookie: s sq=... Users can potentially block 1 and 3, but not 2 easily AT&T Labs Research 41
42 Category 2: OSN ID leakage via external applications OSNs warn users that their information will be given to external applications. These in turn use ads and can hand out user s ID to aggregators. The direct source of leakage here are external applications that run on non-osn servers. 1. Via Referer Header (MySpace external application ilike ) GET /TLC/... Host: view.atdmt.com Referer: Cookie: AA002= /789;...// AT&T Labs Research 42
43 OSN ID leakage via external applications (contd.) 2. Via Request-URI (Facebook external application ilike ) GET /...&utmhn= auto playlist search?name=springsteen&..fb_sig_user= &.. Host: Referer: artistname/q=springsteen 3. Via Request-URI and Cookie (Facebook external application: Kickmania!) GET /track/?...&fb sig time= &fb_sig_user= &.. Host: adtracker.socialmedia.com Referer: ass/... Cookie: fbuserid= ;...=blog.socialmedia.com..cookname=anon; cookid= ; AT&T Labs Research 43
44 Category 3: Direct leakage of specific pieces of PII 1. Age and gender via Request-URI GET /show?gender=m&age=29&country=us&language=en... Host: ads.sixapart.com Referer: 2. Age, gender, zipcode and via Request-URI and Cookie GET /st?ad type=iframe&age=29&gender=m&e=&zip=11301&... Host: ad.hi5.com Referer: Cookie: LoginInfo=M A US 0 11;Userid= ; =jdoe@ .com The hi5 example is in clear contravention of their own privacy policy as of October 1, 2009 AT&T Labs Research 44
45 Category 4: Linkages across OSNs and non-osns A user on two different OSNs may leak ID and thus be linked across OSNs A user moving through list of friends may leak friends OSN id and thus aggregator could know some of the friends. A user visiting an external non-osn Web site could have their action linked with their OSN PII (see example below) Example of third-party cookie for non-osn server: GET /pagead/ads?client=ca-primedia-premium js&... Host: googleads.g.doubleclick.net Referer: Cookie: id=2015bdfb9ec t= et=730 cs=7aepmsks The same Cookie is sent to doubleclick.net when the user is on a OSN and the OSN ID is leaked. AT&T Labs Research 45
46 What can aggregators do with PII Tracking cookie from any other site is trivially linkable with OSN user Visits to non-osn websites in the past and future can be linked with the information Searches are identifiable potentially with a person assuming OSN ID is not falsified Note that aggregators may have contractual agreements not to exploit data that they may have access to as a result of actions by users on OSNs. AT&T Labs Research 46
47 Protection against leakage Users: block Referer header and third-party Cookie headers, filter for all OSNs URI s with appropriate ID syntax (latter is problematic) Aggregators: could ignore PII related information... OSNs: strip ID from all headers, internally remap IDs AT&T Labs Research 47
48 What about mobile OSNs? Ongoing study Studied 20 popular mosns Similar problems with additional issues: location, presence, connections to traditional OSNs Device unique ID leaking, privacy settings on mosns and connected traditional OSNs (FB, Twitter) are often different AT&T Labs Research 48
49 Recent examples of other uses of OSN information Several legal cases settled with information from Facebook: Arrest in Pennsylvania: Jonathan Parker, 19, of Fort Loudoun, Pa on 8/28/09, while committing a daytime burglary checked his FB status on the computer of the house he broke into and left himself logged in. Arrest in Mexico: 10/14/09 Maxi Sopo, a 26-year-old criminal (bank fraud in Seattle) hiding in Cancun updated his Facebook status to say having a good time and also made the elementary error of friending a former justice department official - faces 30 years - without access to FB. Exoneration in Harlem: Rodney Bradford 11:49 a.m. 10/17/09: wherer my i hop from a computer at an apt at 71 W 118th St. Arrested/exonerated when FB confirmed status update time. AT&T Labs Research 49
50 Unknown author s cartoon AT&T Labs Research 50
51 IETF and privacy Privacy is not an entirely new concept to IETF Multiple efforts related to privacy; e.g., Geopriv, identity management Broadly three efforts in IM: OAUTH, OpenID, SAML all dealing with managing and protecting a user s identity. RFC 4505 SASL Simple Authentication and Security Layer - - an application framework to generalize authentication. Related recent drafts discuss how identity providers may log information about relying parties (issue of tracking visits, potential collusion between different RPs). Possibility of a privacy consideration section in relevant IDs/RFCs? (sure, says mnot, for httpbis, if i write it..) AT&T Labs Research 51
52 Some recent IETF discussions re privacy Two topics: Blue sheet retention retaining list of attendees at IETF meetings that might result in subpoenas (realization that IETF has no privacy policy). Should old blue sheets be destroyed? Scott Bradner refers to list of attendee requirement from RFC lore. Controversy over use of RFID tag reader as an experiment in addition to blue sheets. Usual issues: opt-in vs. opt-out (most recently seen in Buzz) Ongoing discussion - no final conlusions reached yet Thanks to Allison Mankin and Lucy Lynch for their valuable pointers. Thanks to Hannes Tschofenig and unnamed colleague for comments on slides. AT&T Labs Research 52
53 Summary An overview of privacy leakage Specific look at leakage on popular OSNs Strong concern about concentration of significant amounts of information in a few hands Things not necessarily getting better in newer technologies IETF might want to start a discussion on the privacy issue AT&T Labs Research 53
How To Find Out If Pii Is Leaked Via Anosn (For A Free Download)
On the Leakage of Personally Identifiable Information Via Online Social Networks Balachander Krishnamurthy AT&T Labs Research Florham Park, NJ USA [email protected] Craig E. Wills Worcester Polytechnic
Privacy leakage vs. Protection measures: the growing disconnect
Privacy leakage vs. Protection measures: the growing disconnect Balachander Krishnamurthy (AT&T Labs Research) Konstantin Naryshkin (Worcester Polytechnic Institute) Craig E. Wills (Worcester Polytechnic
3 Approach. 3.1 Web Site Overview
A Personalized Approach to Web Privacy Awareness, Attitudes and Actions Craig E. Wills and Mihajlo Zeljkovic Computer Science Department Worcester Polytechnic Institute Worcester, MA USA Abstract Purpose
Web Beacons Guidelines for Notice and Choice
Web Beacons Guidelines for Notice and Choice The following statement was developed by a coalition of companies 1 in an effort to guide the appropriate use of Web Beacons. 2 The coalition is made up of
Live Office. Personal Archive User Guide
Live Office Personal Archive User Guide Document Revision: 14 Feb 2012 Personal Archive User Guide Personal Archive gives you an unlimited mailbox and helps you quickly and easily access your archived
Personal Archive User Guide
Personal Archive User Guide Personal Archive gives you an unlimited mailbox and helps you quickly and easily access your archived email directly from Microsoft Outlook or Lotus Notes. Since Personal Archive
1. The information we collect and how we collect it.
PRIVACY POLICY AND YOUR PRIVACY RIGHTS CountySportsZone.com aggregates, reports, and publishes high school sports information for jurisdictions across the state of Maryland. In this Privacy Policy, Affiliates
Central Application Tracking System (CATS) Privacy Impact Assessment (PIA) Version 1.0. April 28, 2013
Central Application Tracking System (CATS) Privacy Impact Assessment (PIA) Version 1.0 April 28, 2013 Prepared by: Office of the Comptroller of the Currency (OCC) Security & Compliance Services (SCS) DOCUMENT
Use of Web Measurement and Customization Technologies
Use of Web Measurement and Customization Technologies Office of Management and Budget (OMB) Memorandum 10-22 (M-10-22), Guidance for Online Use of Web Measurement and Customization Technologies, authorizes
MyReports Recommended Browser Settings MYR-200a
MyReports Recommended Browser Settings MYR-200a Note: If you have installed an additional Tool Bar on your browser, such as Yahoo Tool Bar or Google Tool Bar, be sure that it is also configured to allow
Basheer Al-Duwairi Jordan University of Science & Technology
Basheer Al-Duwairi Jordan University of Science & Technology Outline Examples of using network measurements /monitoring Example 1: fast flux detection Example 2: DDoS mitigation as a service Future trends
Instructions for Configuring Your Browser Settings and Online Security FAQ s. ios8 Settings for iphone and ipad app
Instructions for Configuring Your Browser Settings and Online Security FAQ s ios8 Settings for iphone and ipad app General Settings The following browser settings and plug-ins are required to properly
CAPTURING THE VALUE OF UNSTRUCTURED DATA: INTRODUCTION TO TEXT MINING
CAPTURING THE VALUE OF UNSTRUCTURED DATA: INTRODUCTION TO TEXT MINING Mary-Elizabeth ( M-E ) Eddlestone Principal Systems Engineer, Analytics SAS Customer Loyalty, SAS Institute, Inc. Is there valuable
Concur Travel & Expense
Concur Travel & Expense Supported Configurations Client Version Contents Supported Configurations... 1 Section 1: About Concur Travel & Expense... 1 Section 2: Read This First... 1 Browser Settings General...
Web Tracking for You. Gregory Fleischer
Web Tracking for You Gregory Fleischer 1 INTRODUCTION 2 Me Gregory Fleischer Senior Security Consultant at FishNet Security 3 Disclaimer Why do you hate? 4 Reasons For Tracking TradiFonal reasons for tracking
Cisco Unified Presence Server 1.0
Cisco Unified Presence Server 1.0 The Cisco Unified Presence Server is a critical component for delivering the full value of a Cisco Unified Communications environment. It collects information about a
FitCause Privacy Policy
FitCause Privacy Policy EFFECTIVE DATE: June 19, 2013 FuelGooder Inc. d/b/a FitCause ( FitCause ) values your privacy. FitCause is a social fundraising platform empowering individuals to turn their exercising
Liquid OS X User Guide
Basic Use To use Liquid on selected text: Liquid OS X User Guide Select the text CMD-shift-2 Now Liquid appears with your selected text inserted, ready for you to choose a command. Choose a command by
`````````````````SIRE QUICK START GUIDE
`````````````````SIRE QUICK START GUIDE Table of Contents Table of Contents 2 Introduction 3 Set-up 4 Getting Started 5 Set-up Your Backup Profile 6 Custom Backup 7 Launch Your Backup 9 Main Screen 10
SSL EXPLAINED SSL EXPLAINED
1 Table of Contents Introduction... 3 What is SSL?... 4 How does SSL work?... 7 Google & SSL... 11 SSL/TLS... 13 Web Filtering SSL... 14 About Lightspeed Systems... 26 2 Introduction SSL is a challenge
Adaptive Business Management Systems Privacy Policy
Adaptive Business Management Systems Privacy Policy Updated policy: Effective on July 01, 2013 This privacy statement describes how Adaptive Business Management Systems collects and uses the personal information
The mobile opportunity: How to capture upwards of 200% in lost traffic
June 2014 BrightEdge Mobile Share Report The mobile opportunity: How to capture upwards of 200% in lost traffic You ve likely heard that mobile website optimization is the next frontier, and you ve probably
ITP 140 Mobile Technologies. Mobile Topics
ITP 140 Mobile Technologies Mobile Topics Topics Analytics APIs RESTful Facebook Twitter Google Cloud Web Hosting 2 Reach We need users! The number of users who try our apps Retention The number of users
AUSTRALIAN ONLINE LANDSCAPE REVIEW MAY 2013
AUSTRALIAN ONLINE LANDSCAPE REVIEW MAY 2013 SIGNIFICANT ENHANCEMENTS TO NIELSEN ONLINE RATINGS HYBRID DATA Summary: May data represents a trend break versus prior months across all metrics for Online Ratings
Leveraging Facebook to build your ecommerce Business. #ecomsa
Leveraging Facebook to build your ecommerce Business #ecomsa Reach all of the people who matter to you at scale High-quality reach mostly people are on mobile 11M+ monthly active people ZA 11M mobile
Privacy Policy/Your California Privacy Rights Last Updated: May 28, 2015 Introduction
Privacy Policy/Your California Privacy Rights Last Updated: May 28, 2015 Introduction Welcome! TripleFirrre, LLC, dba Just Seconds Apart knows that safeguarding your privacy is serious business. Your privacy
Your Privacy Center. Online Privacy Statement. About the Information We Collect
Your Privacy Center Your privacy is our priority. At Discover, our actions and decisions are guided by our mission to help people achieve a brighter financial future. And when it comes to your privacy,
WHAT DOES CREDIT ONE BANK, N.A. DO WITH YOUR PERSONAL INFORMATION?
M-112997 Rev 07/2015 FACTS Why? What? How? WHAT DOES CREDIT ONE BANK, N.A. DO WITH YOUR PERSONAL INFORMATION? Financial companies choose how they share your personal information. Federal law gives consumers
An Insight into Cookie Security
An Insight into Cookie Security Today most websites and web based applications use cookies. Cookies are primarily used by the web server to track an authenticated user or other user specific details. This
WompMobile Technical FAQ
WompMobile Technical FAQ What are the technical benefits of WompMobile? The mobile site has the same exact URL as the desktop website. The mobile site automatically and instantly syncs with the desktop
Zep Inc.: Global Online Privacy Notice
Zep Inc.: Global Online Privacy Notice Effective Date: March 26, 2015 We at Zep Inc., along with our affiliates (collectively, Zep ), respect your concerns about privacy. This Global Online Privacy Notice
Web Mail Guide... Error! Bookmark not defined. 1 Introduction to Web Mail... 4. 2 Your Web Mail Home Page... 5. 3 Using the Inbox...
Powered by Table of Contents Web Mail Guide... Error! Bookmark not defined. 1 Introduction to Web Mail... 4 1.1 Requirements... 4 1.2 Recommendations for using Web Mail... 4 1.3 Accessing your Web Mail...
Kerio Connect. Kerio Connect Client. Kerio Technologies
Kerio Connect Kerio Connect Client Kerio Technologies 2015 Kerio Technologies s.r.o. Contents Kerio Connect Client.......................................................... 10 Kerio Connect Client.....................................................
Google Analytics for Robust Website Analytics. Deepika Verma, Depanwita Seal, Atul Pandey
1 Google Analytics for Robust Website Analytics Deepika Verma, Depanwita Seal, Atul Pandey 2 Table of Contents I. INTRODUCTION...3 II. Method for obtaining data for web analysis...3 III. Types of metrics
HTTPS Inspection with Cisco CWS
White Paper HTTPS Inspection with Cisco CWS What is HTTPS? Hyper Text Transfer Protocol Secure (HTTPS) is a secure version of the Hyper Text Transfer Protocol (HTTP). It is a combination of HTTP and a
EBSCOhost User Guide Searching. Basic, Advanced & Visual Searching, Result List, Article Details, Additional Features. support.ebsco.
EBSCOhost User Guide Searching Basic, Advanced & Visual Searching, Result List, Article Details, Additional Features Table of Contents What is EBSCOhost... 3 System Requirements... 3 Inside this User Guide...
Vyve Broadband Website Privacy Policy. What Information About Me Is Collected and Stored?
Vyve Broadband Website Privacy Policy Effective: July 31, 2015 Vyve Broadband ( Vyve, we, us, our ) is committed to letting you know how we will collect and use your information. This Website Privacy Policy
ON24 MOBILE WEBCASTING USER GUIDE AND FAQ FEBRUARY 2015
FEBRUARY 2015 MOBILE ATTENDEE GUIDE ON24 s Mobile Webcasting console allows you to bring your webcast directly to your audience, regardless of location. Users on mobile devices can register, attend, and
Frequently Asked Questions for the USA TODAY e-newspaper
Frequently Asked Questions for the USA TODAY e-newspaper Navigating the USA TODAY e-newspaper A look at the toolbar Toolbar Functions, Buttons, and Descriptions The tab marked Contents will take the e-reader
OAuth Web Authorization Protocol Barry Leiba
www.computer.org/internet computing OAuth Web Authorization Protocol Barry Leiba Vol. 16, No. 1 January/February, 2012 This material is presented to ensure timely dissemination of scholarly and technical
Privacy Policy. If you have questions or complaints regarding our Privacy Policy or practices, please see Contact Us. Introduction
Privacy Policy This Privacy Policy will be effective from September 1 st, 2014. Please read Pelican Technologies Privacy Policy before using Pelican Technologies services because it will tell you how we
WEBSITE AND MARKETING REPORT. Prepared for www.triadinstallations.com
WEBSITE AND MARKETING REPORT Prepared for www.triadinstallations.com December 17, 2015 www.triadinstallations.com SEO ISSUES FOUND ON YOUR SITE (DECEMBER 15, 2015) This report shows the SEO issues that,
Regain Your Privacy on the Internet
Regain Your Privacy on the Internet by Boris Loza, PhD, CISSP from SafePatrol Solutions Inc. You'd probably be surprised if you knew what information about yourself is available on the Internet! Do you
Operating Instructions Driver Installation Guide
Operating Instructions Driver Installation Guide For safe and correct use, be sure to read the Safety Information in "Read This First" before using the machine. TABLE OF CONTENTS 1. Introduction Before
Manual. Netumo NETUMO HELP MANUAL WWW.NETUMO.COM. Copyright Netumo 2014 All Rights Reserved
Manual Netumo NETUMO HELP MANUAL WWW.NETUMO.COM Copyright Netumo 2014 All Rights Reserved Table of Contents 1 Introduction... 0 2 Creating an Account... 0 2.1 Additional services Login... 1 3 Adding a
A PRESENTATION BY RITESH GUPTA
A PRESENTATION BY RITESH GUPTA WEB ANALYTICS next 2 Deep Dive 01 into Web Analytics Web Analytics < 3 Digital Analytics / Measurability Caution: The addictive adrenaline of analzying website data, interpreting
`````````````````SIRE USER GUIDE
`````````````````SIRE USER GUIDE Table of Contents INTRODUCTION 3 SYSTEM REQUIREMENTS 4 RUNNING SANDISK BACKUP 5 Setup Your First Backup 6 Create Your Backup 7 Custom Backup 8 Dmailer Online 10 Launch
Domain Name Abuse Detection. Liming Wang
Domain Name Abuse Detection Liming Wang Outline 1 Domain Name Abuse Work Overview 2 Anti-phishing Research Work 3 Chinese Domain Similarity Detection 4 Other Abuse detection ti 5 System Information 2 Why?
Configuration Manual English version
Configuration Manual English version Frama F-Link Configuration Manual (EN) All rights reserved. Frama Group. The right to make changes in this Installation Guide is reserved. Frama Ltd also reserves the
Application Detection
The following topics describe Firepower System application detection : Overview:, page 1 Custom Application Detectors, page 7 Viewing or Downloading Detector Details, page 15 Sorting the Detector List,
Stanford Computer Security Lab. TrackBack Spam: Abuse and Prevention. Elie Bursztein, Peifung E. Lam, John C. Mitchell Stanford University
Abuse and Prevention Stanford University Stanford Computer Security Lab TrackBack Spam: Introduction Many users nowadays post information on cloud computing sites Sites sometimes need to link to each other
Full and detailed technical cookies disclosure
Full and detailed technical cookies disclosure Website audited: http://www.visa.co.uk/ Audit date: 2016-01-07 Auditor: Cookie Reports Limited http://www.cookiereports.com/ This document is provided to
Elo Touch Solutions Privacy Policy
Elo Touch Solutions Privacy Policy Your privacy is very important to us. At Elo Touch Solutions, Inc. ( Elo, we or us which includes any of our worldwide direct and indirect subsidiaries), we recognize
Facebook Smart Card FB 121211_1800
Facebook Smart Card FB 121211_1800 Social Networks - Do s and Don ts Only establish and maintain connections with people you know and trust. Review your connections often. Assume that ANYONE can see any
WHAT INFORMATION IS COLLECTED AT MOTOROLA.COM.VN AND/OR MOTOROLA.VN AND HOW IS IT PROCESSED AND USED?
MOTOROLA PRIVACY POLICY This Privacy Statement ( Policy ) is subject to change at Motorola s discretion. If we decide to change this Policy, we will post the amended Policy on this website so you will
Analysis One Code Desc. Transaction Amount. Fiscal Period
Analysis One Code Desc Transaction Amount Fiscal Period 57.63 Oct-12 12.13 Oct-12-38.90 Oct-12-773.00 Oct-12-800.00 Oct-12-187.00 Oct-12-82.00 Oct-12-82.00 Oct-12-110.00 Oct-12-1115.25 Oct-12-71.00 Oct-12-41.00
Web Analytics Definitions Approved August 16, 2007
Web Analytics Definitions Approved August 16, 2007 Web Analytics Association 2300 M Street, Suite 800 Washington DC 20037 [email protected] 1-800-349-1070 Licensed under a Creative
GSA s Digital Analytics Program and FTC
Federal Trade Commission Privacy Impact Assessment Google Analytics Through GSA s Digital Analytics Program June 2014 1 SECTION 1.0 SPECIFIC PURPOSE OF THE FTC S PARTICIPATION IN GSA s DIGITAL ANALYTICS
FLASH DELIVERY SERVICE
Privacy Policy FLASH DELIVERY SERVICE is Committed to Protecting Your Privacy Protecting our customers' privacy is an important priority at FLASH DELIVERY SERVICE and we are committed to maintaining strong
COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*
COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) 2 Fixed Rates Variable Rates FIXED RATES OF THE PAST 25 YEARS AVERAGE RESIDENTIAL MORTGAGE LENDING RATE - 5 YEAR* (Per cent) Year Jan Feb Mar Apr May Jun
COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*
COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) 2 Fixed Rates Variable Rates FIXED RATES OF THE PAST 25 YEARS AVERAGE RESIDENTIAL MORTGAGE LENDING RATE - 5 YEAR* (Per cent) Year Jan Feb Mar Apr May Jun
Simplicity Itself. User Guide
Simplicity Itself User Guide TekEx 2013 Contents WELCOME... 3 TEKEX OVERVIEW... 3 DOWNLOAD OUTLOOK... 4 CONFIGURE OUTLOOK... 5 CONFIGURE MAC EMAIL CLIENT... 10 SMARTPHONE SETUP... 12 IPHONE SETUP... 12
Novell Filr. Mobile Client
Novell Filr Mobile Client 0 Table of Contents Quick Start 3 Supported Mobile Devices 3 Supported Languages 4 File Viewing Support 4 FILES THAT CANNOT BE VIEWED IN THE FILR APP 4 FILES THAT GIVE A WARNING
SMART Bridgit software
Specifications SMART Bridgit software Version 4.5 Product description SMART Bridgit conferencing software is a cost-effective client/server application that lets you easily schedule meetings and connect,
leveraging your Microsoft
Kanban Task Manager for SharePoint Manual Table of contents 1 INTRODUCTION... 3 1.1 LANGUAGES... 4 1.2 REQUIREMENTS... 4 2 INSTALLATION OF KANBAN TASK MANAGER... 4 2.1 INTRODUCTION... 4 2.2 INSTALL AND
ivms-4500 HD (Android) Mobile Client Software User Manual (V3.4)
ivms-4500 HD (Android) Mobile Client Software User Manual (V3.4) UD.6L0202D1597A01 Thank you for purchasing our product. This manual applies to ivms-4500 HD (Android) mobile client software; please read
Social Application Guide
Social Application Guide Version 2.2.0 Mar 2015 This document is intent to use for our following Magento Extensions Or any other cases it might help. Copyright 2015 LitExtension.com. All Rights Reserved
DESTINATION MELBOURNE PRIVACY POLICY
DESTINATION MELBOURNE PRIVACY POLICY 2 Destination Melbourne Privacy Policy Statement Regarding Privacy Policy Destination Melbourne Limited recognises the importance of protecting the privacy of personally
ivms-4500 HD (ios) Mobile Client Software User Manual (V3.4)
ivms-4500 HD (ios) Mobile Client Software User Manual (V3.4) UD.6L0202D1587A01 Thank you for purchasing our product. This manual applies to ivms-4500 HD (ios) mobile client software; please read it carefully
Privacy Policy and Notice of Information Practices
Privacy Policy and Notice of Information Practices Effective Date: April 27, 2015 BioMarin Pharmaceutical Inc. ("BioMarin") respects the privacy of visitors to its websites and online services and values
Internet Advertising Glossary Internet Advertising Glossary
Internet Advertising Glossary Internet Advertising Glossary The Council Advertising Network bring the benefits of national web advertising to your local community. With more and more members joining the
Privacy Policy Last Updated September 10, 2015
Privacy Policy Last Updated September 10, 2015 Tanger Properties Limited Partnership d/b/a Tanger Outlets or Tanger Outlet Centers ("Tanger," "we" or us ), which includes affiliated companies owned or
1. Important Information
We at ViewPoint (ViewPoint Government Solutions, Inc. and our affiliates) are committed to protecting your privacy. This Privacy Policy applies to both our websites (Websites), including www.viewpointcloud.com,
A Practical Attack to De Anonymize Social Network Users
A Practical Attack to De Anonymize Social Network Users Gilbert Wondracek () Thorsten Holz () Engin Kirda (Institute Eurecom) Christopher Kruegel (UC Santa Barbara) http://iseclab.org 1 Attack Overview
Case 2:08-cv-02463-ABC-E Document 1-4 Filed 04/15/2008 Page 1 of 138. Exhibit 8
Case 2:08-cv-02463-ABC-E Document 1-4 Filed 04/15/2008 Page 1 of 138 Exhibit 8 Case 2:08-cv-02463-ABC-E Document 1-4 Filed 04/15/2008 Page 2 of 138 Domain Name: CELLULARVERISON.COM Updated Date: 12-dec-2007
SAP Cloud Identity Service Document Version: 1.0 2014-09-01. SAP Cloud Identity Service
Document Version: 1.0 2014-09-01 Content 1....4 1.1 Release s....4 1.2 Product Overview....8 Product Details.... 9 Supported Browser Versions....10 Supported Languages....12 1.3 Getting Started....13 1.4
Echo Backup Software. Quick Start Guide
Echo Backup Software Quick Start Guide INTRODUCTION Whether you re a business professional on the road, a student doing homework at a friend s house, or someone simply using a laptop in a café, it s important
Internet Explorer Security Settings. Help Sheet. Client Services. Version 4 Definitive 21 July 2009
Internet Explorer Security Settings Help Sheet Client Services Contents About this document 2 Audience... 2 Scope... 2 Related documentation... 2 Adding Præmium to your list of trusted sites 3 Pop up blocker
If you have any questions about our privacy practices, please refer to the end of this privacy policy for information on how to contact us.
c4m Privacy Policy Last Modified: July 20, 2015 Colbette II Ltd., Block 1, 195-197 Old Nicosia-Limassol Road, Dali Industrial Zone, Cyprus 2540 (hereinafter "c4m", Colbette we", "our" or "us") is always
New Features SMART Sync 2009. Collaboration Feature Improvements
P L E A S E T H I N K B E F O R E Y O U P R I N T New Features SMART Sync 2009 SMART Sync (formerly SynchronEyes ) is easy-to-use classroom management software that allows teachers to monitor and control
QUICK FEATURE GUIDE OF SNAPPII'S ULTRAFAST CODELESS PLATFORM
QUICK FEATURE GUIDE OF SNAPPII'S ULTRAFAST CODELESS PLATFORM (* Click on the screenshots to enlarge) TABLE OF CONTENTS 1. Visually Develop Mobile Applications 2. Build Apps for Any Android or ios Device
CSC2231: Akamai. http://www.cs.toronto.edu/~stefan/courses/csc2231/05au. Stefan Saroiu Department of Computer Science University of Toronto
CSC2231: Akamai http://www.cs.toronto.edu/~stefan/courses/csc2231/05au Stefan Saroiu Department of Computer Science University of Toronto Administrivia Project proposals due today!!! No lecture on Monday:
Facebook - Twitter - Google +1 all in one plugin for Joomla enable "Twitter button", "Google +1
Facebook - Twitter - Google +1 all in one plugin for Joomla enable "Twitter button", "Google +1 button ", Facebook " Like button ", the Facebook " Share This button ", the Facebook " Comment Box ", the
Scheduling Software User s Guide
Scheduling Software User s Guide Revision 1.12 Copyright notice VisualTime is a trademark of Visualtime Corporation. Microsoft Outlook, Active Directory, SQL Server and Exchange are trademarks of Microsoft
Virto Pivot View for Microsoft SharePoint Release 4.2.1. User and Installation Guide
Virto Pivot View for Microsoft SharePoint Release 4.2.1 User and Installation Guide 2 Table of Contents SYSTEM/DEVELOPER REQUIREMENTS... 4 OPERATING SYSTEM... 4 SERVER... 4 BROWSER... 4 INSTALLATION AND
Google Analytics Health Check Laying the foundations for successful analytics and optimisation
Google Analytics Health Check Laying the foundations for successful analytics and optimisation Google Analytics Property [UA-1234567-1] Domain [Client URL] Date of Review MMM YYYY Consultant [Consultant
