Avast 與 Jumpshot 販賣使用者瀏覽記錄與行為


報導可以看 PCMag 的「The Cost of Avast's Free Antivirus: Companies Can Spy on Your Clicks」與 Motherboard (VICE) 的「Leaked Documents Expose the Secretive Market for Your Web Browsing Data」這兩篇,大綱先把重點列出來了,Avast 在賣使用者的瀏覽記錄與行為:

Avast is harvesting users' browser histories on the pretext that the data has been 'de-identified,' thus protecting your privacy. But the data, which is being sold to third parties, can be linked back to people's real identities, exposing every click and search they've made.

Avast 利用免費的防毒軟體,蒐集使用者的瀏覽記錄與行為,然後透過 Jumpshot 這家子公司販賣出去:

The Avast division charged with selling the data is Jumpshot, a company subsidiary that's been offering access to user traffic from 100 million devices, including PCs and phones.


Who else might have access to Jumpshot's data remains unclear. The company's website says it's worked with other brands, including IBM, Microsoft, and Google. However, Microsoft said it has no current relationship with Jumpshot. IBM, on the other hand, has "no record" of being a client of either Avast or Jumpshot. Google did not respond to a request for comment.

Microsoft 說「現在沒有關係」,IBM 說「沒有 client 的記錄」,Google 則是不回應。


For instance, a single click can theoretically look like this:

Device ID: abc123x Date: 2019/12/01 Hour Minute Second: 12:03:05 Domain: Amazon.com Product: Apple iPad Pro 10.5 - 2017 Model - 256GB, Rose Gold Behavior: Add to Cart

At first glance, the click looks harmless. You can't pin it to an exact user. That is, unless you're Amazon.com, which could easily figure out which Amazon user bought an iPad Pro at 12:03:05 on Dec. 1, 2019. Suddenly, device ID: 123abcx is a known user. And whatever else Jumpshot has on 123abcx's activity—from other e-commerce purchases to Google searches—is no longer anonymous.

所以,如果 Google 手上有這個資料,就可以交叉比對自家的記錄,然後得到使用者完整的記錄。

在消息一公開後沒多久後,Avast 就宣佈關閉 Jumpshot,感覺連被抓包後的反應動作都超流暢,一臉就是排練過:「A message from Avast CEO Ondrej Vlcek」。

看了一下,Avast 旗下還有 AVG,還有個 VPN 服務...

對 Linux「友善」的主機板廠商... XD

Slashdot 上看到「Ask Slashdot: Linux-Friendly Motherboard Manufacturers?」這篇,第一個 comment 通常是最犀利的 comment... XDDD

I heard the Raspberry Pi is very Linux compatible, in fact it doesn't even run Windows.

然後下面滿滿都在討論 Raspberry Pi... XDDD


前天回到家發現電腦是關的,本來以為是停電,但同樣接在 UPS 上的 Mac Mini 卻好好的,打開電腦一進 Ubuntu 就發現 Psensor 在警告過熱,看了一下說明,是 CPU 過熱... 以為是假警報,結果過沒多久就自己關機了 XD

(圖複製自 Psensor 官網)

拆開電腦發現 CPU 風扇卡榫掛了,CPU 風扇無法貼住... 第一個想法是自己買來換,查了一下看起來是不貴,但想到要好幾天才能用就懶...

後來想了一下,先查一下官網資料。華碩M4A87TD/USB3 主機板保固三年,我是 2010 年買的,所以還在保固內... 而光華的維修中心星期六白天有開,應該是,就星期六睡飽過去...。

(圖複製自 ASUS 官網)

我自己看損壞的狀況,應該是四個螺絲拆下來,換個底座再鎖上去就好了,所以應該是拿給他之後去吃個飯,然後回來收個工本費就可以收工... 不過在現場交件的時候直接請我等兩分鐘馬上拿 (不收工本費),害我愣了一下...

拿回家接上後把散熱膏弄一弄就繼續快樂的服役了... XD