Major U.S. media sites hit with lawsuit

Emily Banks 0 Tallied Votes 485 Views Share

A number of the nation's biggest media sites were hit with a lawsuit last week, claiming that they are violating federal eavesdropping and hacking laws by using "zombie cookies."

The technology, created by Quantcast, allows sites to use Adobe's Flash player to reproduce tracking files, even after a user has deleted them, according to ZDNet . The class action suit names ABC, ESPN, Hulu, MTV, MySpace and NBC as defendants, as well as Quantcast.

The lawsuit calls Internet users "fish in a fishbowl," completely exposed to Web sites' all-encompassing and wholesale collection of data, which could then be bought and sold.

"Defendants have used those cookies and other surreptitious datacollection methods to secretly intercept and access computer users’ personal data and web browsing habits and have transmitted this information to Defendants for their own commercial benefit," the suit states.

And, according to the suit, this is a common practice.

"We found that top 100 websites are using Flash cookies to 'respawn,' or recreate deleted HTTP cookies. This means that privacy-sensitive consumers who 'toss' their HTTP cookies to prevent tracking or remain anonymous are still being uniquely identified online by advertising companies. Few websites disclose their use of Flash in privacy policies," the lawsuit states, citing a .

The lawsuit goes on to outline the Web sites' privacy practices, but the plaintiffs claim those documents are too vague and require college level reading skills to comprehend, leaving the average user unaware of the "zombie cookies."

"Defendants’ privacy documents provide a false privacy protection by implying some level of protection for the user. Defendants’ privacy documents intentionally are sufficiently vague so as to refrain from fully disclosing information to its users about what information is collected by the website, its associated entities, how the information is used and the purposes for the collection and use of this information; negating that its users are provided informed and meaningful online consent to these practices," the suit states.

The defendants claim these cookies depleted their computers' memory, caused unwanted CPU activity and disk usage and caused instability issues.

The suit was filed July 23 in the U.S. District Court's Central District of California.

Photo by walknboston on Flickr. Used under Creative Commons License.

Dani AI

Generated

As reported, this thread flagged the 2010 “zombie cookie” problem — good catch. Short update and practical context so this page stays useful years later.

The litigation that followed the Berkeley research did not end with widespread direct payouts to users; the tracking vendors (Quantcast and Clearspring) agreed to a settlement that funded privacy groups and included promises to stop respawning deleted browser cookies. Publishers named in the suits were largely released under the settlement. (wired.com)

How it worked then, and why it matters now: the technique relied on Flash Local Shared Objects (LSOs) and other out-of-browser storage that ordinary cookie-clearing did not touch. Adobe’s Flash Player has since been retired (end of life December 31, 2020), so that specific vector is effectively gone from modern browsers — but the core lesson remains: any storage outside normal cookie controls can be abused. Standards bodies now warn spec authors to avoid mechanisms that create “permanent” identifiers. (adobe.com)

Tracking evolved. Researchers and demonstrators showed how multiple storage vectors (the so-called “evercookie”) and browser fingerprinting let trackers re-identify users even after cookie deletion. Those techniques pushed attention toward blocking and detection tools as well as into law and policy. (samy.pl)

Practical takeaways (for both site owners and readers who thanked the OP like , and ): marketers and developers should stop using any respawning tricks, give short plain-English privacy notices, implement consent flows that satisfy current laws (GDPR/CCPA/CPRA), and prefer privacy-preserving analytics or aggregated server-side measurement. Regulators now expect clearer consent and data-minimization. Users who want to reduce tracking can run tracker blockers (for example Privacy Badger) or privacy-focused browsers (Tor) and keep plugins and extensions up to date. (eur-lex.europa.eu)

If deeper technical or legal detail is needed (case filings, settlement text, implementation checklists), those can be added below — this note simply records the key outcome and what to watch for today.

jokesarcade1 0 Newbie Poster

Thanks for sharing this knowledge, it was not in my knowledge that US law hits a lot of media sites. :-/

shahzebkhan -3 Newbie Poster

thanks for that lovely information...

seowright 0 Newbie Poster

wledge, it was not in my knowledge that US law hits a lot of media sites. :-/

Thanks a lot for this informative post.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.