Update on the issue of ‘supercookies’ used on MSN
In response to recent attention on "supercookies" in the media, we wanted to share more detail on the immediate action we took to address this issue, as well as affirm our commitment to the privacy of our customers. According to researchers, including Jonathan Mayer at Stanford University, "supercookies" are capable of re-creating users' cookies or other identifiers after people deleted regular cookies. Mr. Mayer identified Microsoft as one among others that had this code, and when he brought his findings to our attention we promptly investigated. We determined that the cookie behavior he observed was occurring under certain circumstances as a result of older code that was used only on our own sites, and was already scheduled to be discontinued. We accelerated this process and quickly disabled this code. At no time did this functionality cause Microsoft cookie identifiers or data associated with those identifiers to be shared outside of Microsoft. We are committed to providing choice when it comes to the collection and use of customer information, and we have no plans to develop or deploy any such "supercookie" mechanisms.
Microsoft has strong privacy standards that govern the development and deployment of our products and services. We work hard to build privacy into products, and we also engage with government, industry, academia and public interest groups to develop more effective privacy and data protection measures.
- Mike Hintze, Associate General Counsel, Regulatory Affairs, Microsoft
Comments
Anonymous
August 20, 2011
"we have no plans to develop or deploy any such "supercookie" mechanisms." That's because you already did. I love it how companies get caught doing this redhanded and then spin it as "We are committed to providing choice when it comes to the collection and use of customer information". The doublespeak is palpable. Also, "when he brought his findings to our attention we promptly investigated". Really? A rogue employee implemented this functionality? How many people are being fired over this allegedly unsanctioned violation of users' privacy? What's even worse is that this is par for the course.Anonymous
August 20, 2011
The comment has been removedAnonymous
August 20, 2011
To sum up this post: We're sorry we got caught. Won't happen again...until we get caught again.Anonymous
August 21, 2011
just looking at how ugly, hobbled and dated looking this site is conveys so much that could never be expressed in words. i must exit immediately.Anonymous
August 21, 2011
reasonable company? are you kidding me? they do the bare minimum to protect them from fallout after their shady practises are exposed. this evil snooping has been going on for how long?Anonymous
August 22, 2011
Under the data protection act all information must be made available to the individuals from whom it was collected. Who do I apply to?Anonymous
August 28, 2011
couples cherche femmes ou transexulesAnonymous
September 14, 2011
Still no answer from MS or blog author. Who accepts data access requests at MS please? 22 Aug 2011 1:50 AM my request was made in writing there is a time limit to respond.