Slashdot Mirror


Market Research Company Secretly Installs Spyware

An anonymous reader writes "Forbes reports that two security experts are raising new questions about comScore, claiming that company's tracking software is being installed without consent on an unknown number of computers. The widely-used online research company takes screenshots of every Web page viewed by its 1 million participants, even transactions completed in secure sessions, like shopping or online checking. ComScore then aggregates the information into market analysis for its clients, which include such large companies as Ford Motor, Microsoft and The New York Times Co." From the article: "'[The] software is sneaking onto users' computers without the user agreeing to receive it,' says Harvard University researcher Ben Edelman, who documented at least ten unauthorized comScore downloads. Eric Howes, director of malware research at antivirus company Sunbelt Software, and his researchers separately observed hundreds of unauthorized comScore downloads in a three-month period this fall."

2 of 206 comments (clear)

  1. Re:Screenshots? by interiot · · Score: 5, Informative

    From TFA:

    While ordinarily an HTTPS connection would simply pass through a proxy securely, in this case MarketScore also installs a new root certificate in your browser so that it can decrypt all intercepted SSL connections (a "man-in-the-middle" attack) without triggering a security warning from the browser. In normal operation, browsers would complain if a site certificate doesn't match the domain of the URL, but the new root certificate tells the browser to trust ComScore's site certificate for any URL.
  2. Client List by phantomcircuit · · Score: 5, Informative
    Corporations supporting comScore's actions
    • AOL
    • Best Buy
    • Borders
    • CareerBuilder.com
    • Clear Channel Communications
    • Columbia House
    • Digitas
    • Discover Financial Services
    • Eli Lilly and Company
    • Expedia
    • ESPN
    • Ford Motor Company
    • General Mills
    • Google
    • HP Home & Home Office Store
    • Hyatt Corporation
    • Interpublic Group
    • iVillage
    • Johnson and Johnson
    • Knight Ridder Digital
    • Mattel
    • Medscape (Web MD)
    • Mercado Libre
    • Microsoft
    • Monster Worldwide
    • NASDAQ
    • NAVTEQ
    • Nestlé USA
    • The Newspaper Association of America
    • New York Times Digital
    • Office Depot
    • OMD Digital
    • Orbitz
    • Pepsi
    • Procter and Gamble
    • Starcom IP
    • Terra Networks
    • Ticketmaster, LLC
    • T-Mobile
    • Tribune Interactive
    • Verizon
    • Viacom International
    • Washington Mutual
    • Yahoo!
    Retrieved from http://www.comscore.com/about/clients.asp