Recommended Posts

Hi,

 

I've searched the web but can't find a topic similar enough nor a forum exactly tailored to this topic, so I hope it is OK to ask here.

 

Early this morning I was looking at furniture on Sears regular and Outlet websites.  I came back later to see an email that was time stamped 6:01am from Sears with the subject "? We've got a surprise! Thanks for looking

Welcome, and may I say, well done for taking the time to post correctly.

As for the email, I have no idea on how they could do that without any input from you.

Was the information you recieved in almost exact relation to what you were browsing?

Were you signed into a browser at the time?

UPDATE

 

I know I posted only minutes ago, but I just zoomed in to look closer at the incredibly fine print at the bottom of the Sears spam email.  (I just got fitted for multifocal lenses and it is a bear getting used to focusing on small type right now).  Anyhow, here is the privacy disclosure link to the company that seems to be proudly responsible for this apparent email stealing technology (I hope the link is OK to post as it is general and freely available):

 

http://privacy.criteoemail.com/us/privacy-policy.html

 

 

I don't know how they could extract my email from just the related cookies but I assume there may be a way it is encoded into other tracking info from sites where I may have stored my email address or communicated through a web form.  This is scary.  I'm afraid to use their opt-out button.  Will research further.

 

Any experience or opinions with this BS?  Thanks!

Welcome, and may I say, well done for taking the time to post correctly.

As for the email, I have no idea on how they could do that without any input from you.

Was the information you recieved in almost exact relation to what you were browsing?

Were you signed into a browser at the time?

Hi, thanks for the reply.  I've also updated my post which probably explains 'what' is happening, but not 'how'.

 

It appears to be a fairly legitimate looking spam email from Sears, and it includes an inset sofa image, one that I was looking at.  In of itself the ad inset is not surprising, though the email "knowledge" is, and scary as well.  As I tried to describe, this is an email address that is not linked to any type of Gmail or similar cross-linking or social site/plugin/etc.  I was using IE and do have Google as my home page, and do have a Gmail address that may have been logged in (I don't always log out of Gmail, it is just a throwaway account) but at any rate they emailed my primary paid email address that is not linked to anything like what you suggest.

Does your browser support/have do not track enabled? If not it's possible it could have been extracted from a tracking cookie.

Thanks for the reply.  This is a new install on a "write zeroed" HDD, so I am still tweaking everything.  I started immediately with AV and anti malware running constant protection.  I just went into IE options and set 3rd party cookies to 'Prompt' so I can see what comes up.  Unfortunately I had them enabled before this.  AFAIK, "do not track" in IE is only accomplished by restricting cookies.  I could certainly be wrong.

Does your browser support/have do not track enabled? If not it's possible it could have been extracted from a tracking cookie.

DNT is a bit of a useless feature since the whole ignoring IE's option debacle and not many sites even paying attention to it anyway.

Get noscript and disable scripts from running on sites that could things like this, although they'd still know that you looked at items (cookies) they wouldn't get anything like google analytics, and you can browse in private mode to bypass that too.

I get these from newegg or Amazon at times. I'll be browsing. And a few hours later I'll get an email with things similar to what I was browsing.

I get it in my Facebook stream all the time. I'm thinking about writing a program to auto-clear cookies from my caches after each browser closing.

The only plausible explanation I can think of if you weren't logged in is that they already have a browser fingerprint record of your computer (See: https://amiunique.org/ or https://panopticlick.eff.org/

 

Since you said it was a "new W7 installation" rather than a new PC, I'm assuming you just reformatted, in which case your browser fingerprint wouldn't really change as far as I know.

  • Like 1

The only plausible explanation I can think of if you weren't logged in is that they already have a browser fingerprint record of your computer (See: https://amiunique.org/ or https://panopticlick.eff.org/

 

Since you said it was a "new W7 installation" rather than a new PC, I'm assuming you just reformatted, in which case your browser fingerprint wouldn't really change as far as I know.

Thank you, that seems plausible.  I believe that XP installs used to look at unique features like hardware MAC addresses, and saved a code that was generated from all of that data, which became the basis for approving a reinstall on the same machine.  I experimented with that in the early 2000's by necessity, changing out failed hardware devices and reformatting, and never had it fail to certify the copy of XP automatically.  They might have programmed some wiggle room into it.

 

Yes, it was a clean re-installation of W7 Pro on an existing machine, as I recently fell victim to a ransomeware attack.  I cleaned up the virus and restored my files from backups but to be safe felt it was worth the extra effort to reformat and reinstall.  Now I am paranoid about security since I don't even know how I got the ransomware in the first place.  I don't open unknown files or browse seedy sites.  Thanks again for the idea and links about unique browser detection.

Do you have a common name/email?

Have you been into a store? and maybe used their Wifi? Then gone home and used your Wifi? AdvertisingID....

Install Ghostery, Its amazing how many calls to third party API's Trackers and Beacons you get stopped

 

I highly recommend this to anyone.

 

https://www.ghostery.com/en/

 

Its a strange scary old world we live in. 

The only plausible explanation I can think of if you weren't logged in is that they already have a browser fingerprint record of your computer (See: https://amiunique.org/ or https://panopticlick.eff.org/

 

Since you said it was a "new W7 installation" rather than a new PC, I'm assuming you just reformatted, in which case your browser fingerprint wouldn't really change as far as I know.

That's a bit of nonsense really, if it's a fresh install the fingerprint data will show: timezone, IE version, screen resolution, additional software installed (none), language, cookies (none) - what you're trying to say is that the owner of a large domain can take that information and match it up to one user, well no, there will be at a bare minimum 10,000 visitors to the site with the exact same configuration and therefore 'browser fingerprint'.

The most likely scenario is the site was logged into or something from a third party site, then the cookie with/without javascript was used to get finer details and the background email system fired off an email to the account holder.

Do you have a common name/email?

Have you been into a store? and maybe used their Wifi? Then gone home and used your Wifi? AdvertisingID....

Install Ghostery, Its amazing how many calls to third party API's Trackers and Beacons you get stopped

 

I highly recommend this to anyone.

 

https://www.ghostery.com/en/

 

Its a strange scary old world we live in. 

Not common, no.  I don't use public wifi, at least I haven't in a long time.  Thanks for the link, I'll check Ghostery out.

That's a bit of nonsense really, if it's a fresh install the fingerprint data will show: timezone, IE version, screen resolution, additional software installed (none), language, cookies (none) - what you're trying to say is that the owner of a large domain can take that information and match it up to one user, well no, there will be at a bare minimum 10,000 visitors to the site with the exact same configuration and therefore 'browser fingerprint'.

The most likely scenario is the site was logged into or something from a third party site, then the cookie with/without javascript was used to get finer details and the background email system fired off an email to the account holder.

I'm not saying you're wrong, but did you visit the sites I linked? Even if you do a clean install, you're highly likely going to install all the same plugins/software and configure everything the same way. OP did say that it was a "one week old installation" so he would already have everything installed.

I get it in my Facebook stream all the time. I'm thinking about writing a program to auto-clear cookies from my caches after each browser closing.

Why?  All 3 major browsers Firefox, Chrome and even IE have this option already built in.

 

Here is settings in firefox that allow you to clear you cookies when you close your browser, delete them on close, etc.  Both chrome and IE also have settings like this - just showing firefox because that is browser I use 99% of the time.

 

post-14624-0-03497100-1437430261.png

Why?  All 3 major browsers Firefox, Chrome and even IE have this option already built in.

 

Here is settings in firefox that allow you to clear you cookies when you close your browser, delete them on close, etc.  Both chrome and IE also have settings like this - just showing firefox because that is browser I use 99% of the time.

 

attachicon.gifclearcookies.png

You know, I'm one of those standard guppies when it comes to browsers. It works, so I don't mess with it. I never knew FF had this option. Now, to find it on Chrome!

This topic is now closed to further replies.
  • Posts

    • Onkyo Dolby Atmos AV receivers are really solid deals by Sayan Sen Recently we covered great deals on several soundbar models from the likes of Sony, JBL, Samsung and others for really good prices (the lowest in several months). Aside from that we also reported on the Edifier S3000MKII, a hi-fi two-way bookshelf monitor that's available for only $800. Today we bring a list of AV receivers from Onkyo that are available at great prices including the Onkyo NR7100, RZ30, and 8470 (purchase links under the specs table down below). The Onkyo TX-NR7100 and Onkyo TX-RZ30 are both 9.2-channel AV receivers designed for immersive home theater setups but they occupy slightly different tiers within Onkyo’s lineup with the RZ30 positioned as the more advanced model. The TX-NR7100 is a THX Certified 9.2-channel receiver offering up to 100 W per channel (8 ohms, 2 channels driven). It supports Dolby Atmos, DTS:X, and IMAX Enhanced formats, with flexible configurations such as 5.1.4 or 7.1.2 speaker layouts. A key highlight is its built-in Dirac Live Room Correction which should help optimize sound based on your room and its acoustics. In comparison, both models share several core capabilities though the RZ30 is geared toward enthusiasts seeking more precise calibration and system flexibility, while the NR7100 is positioned as a slightly more accessible, value-focused option with strong all-round performance. The technical specs of the RZ30 and NR7100 9.2 AVRs are given in the table below: Specification Onkyo TX-RZ30 Onkyo TX-NR7100 Power Output (FTC, 2ch driven) ~100 W/ch (8Ω, 20Hz–20kHz, 0.08% THD) 100 W/ch (8Ω, 20Hz–20kHz, 0.08% THD) Dynamic / Peak Power 9 × 170 W (6Ω, 1kHz, 1% THD, 1ch driven) 220 W/ch (6Ω, 1kHz, 10% THD, 1ch driven) Frequency Response 5 Hz – 100 kHz (+1/-3 dB) 10 Hz – 100 kHz (+1/-3 dB) THD 0.08% 0.08% Room Correction Dirac Live (full bandwidth) Dirac Live (with AccuReflex support) Immersive Audio Dolby Atmos, DTS:X, IMAX Enhanced Dolby Atmos, DTS:X, IMAX Enhanced Speaker Layout Support Up to 7.2.2 / 5.2.4 / 9.2 processing Up to 7.2.4 / 5.2.4 / 9.2 processing HDMI Inputs / Outputs 6 inputs / 2 outputs (eARC) 6 inputs / 2 outputs (Main + Sub/Zone 2) HDMI 2.1 Support 8K/60, 4K/120, VRR, ALLM, QFT, DSC, eARC 8K/60, 4K/120, VRR, ALLM, QFT, DSC, eARC Video Formats HDR10+, Dolby Vision, HDCP 2.3 HDR10+, Dolby Vision, HDCP 2.3 Streaming / Network Wi-Fi, AirPlay 2, Chromecast, Bluetooth, DTS Play-Fi Wi-Fi, AirPlay 2, Chromecast, Bluetooth, DTS Play-Fi Get them at the links below: Onkyo TX-RZ30 9.2-Channel AV Receiver: $797.00 (Sold and shipped by Electronic Expo) Onkyo TX-NR7100 9.2-Channel AV Receiver: $699.00 (Sold and shipped by Adorma) Onkyo TX-8470 2 Ch Stereo Receiver: $449.00 (Sold and Shipped by Adorma) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links or authorized dealer links (at the time of article publishing); ensure that you purchase from such links only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • A different thing with Russia. When you say is it better, depends on things. It is better that we don't have the E.U making rules and laws that have nothing to do with them. Is the trading part better? No, that is really mucked up, but then we knew that was going to happen and we would have make agreements, like we do with other parts of the world. Freedom of movement is certainly better, but could be improved, we still need more control over our borders. do you live in the U.K?
    • So what am I quoting from them? I never listened to what Farage or his cronies said. I wanted the U.K to leave the E.u years before the referendum and it had nothing to do with Farage and his cronies. So what country do you live in? Did we work much better together? We were always at logger heads with the E.U because we disagreed with them so much. Maggie was always on at them. I would have thought the E.U was glad to get rid of us as we stopped the integration or made it a two tier. Now without us they can integrate more. I would not have voted out if it was just a trading block and we can still work together on somethings.
    • MPC-BE 1.9.0 by Razvan Serea Media Player Classic - BE is a free and open source audio and video player for Windows. Media Player Classic - BE is based on the original "Media Player Classic" project (Gabest) and "Media Player Classic Home Cinema" project (Casimir666), contains additional features and bug fixes. The BE mod (Black Edition Mod) is a skinned version of Media Player Classic Home Cinema, much better looking than the plain old MPC. MPC-BE 1.9.0 changelog: Splitters Fixed crashes in some situations. AudioSplitter Added support for the RF64 format. Fixed reading of channel layout for some WavPack files. Added support for ID3 tags for Wave64 files. Unknown Wave64 chunks are now ignored. AviSplitter Added support for 'y408' video. Improved support for 'HEVC' video. FLVSplitter Added support for VVC video. MP4Splitter Improved handling of corrupted files. MatroskaSplitter Expanded support for V_UNCOMPRESSED video codecs. Fixed support for frame rotation (ProjectionPoseRoll). Improved support for "V_MS/VFW/FOURCC / HEVC". MpcDvdVideoDecoder Fixed conversion to YUY2. Fixed display of menus for some DVD-Videos. RoQVideoDecoder Output in NV12 and YV12 formats is allowed. Full range is used. MPC Video Decoder RGB32 format will be output as a top-down bitmap by default. Added support for the "IID_MediaSideDataDOVIMetadataV2" interface. Removed support for the deprecated "IID_MediaSideDataDOVIMetadata" interface. Fixed retrieving the name of the video adapter when using NVDEC. Fixed crashes in some situations. MPC Video Converter Added support for AYUV video format. MpcAudioRenderer Improved input format validation. Optimized retrieval of supported formats for exclusive mode. Added the "Keep audio device active when paused" setting. Fixed crashes and freezes in various situations. Subtitles Added the ability to open the properties of an external subtitle renderer in the "Subtitles" settings panel. Fixed external subtitle connections for VSFilter. Fixed a crash when rendering PGS/SUP subtitles when using AVX2. YouTube Improved support for yt-dlp. The built-in YouTube parser is no longer used. Player The HTTP read strategy has been changed. If the playlist contains one entry, more key combinations can be used to control the player (jump through chapters, adjust volume). Improved support for reading ASX playlists. The translation of the MediaInfo report for Chinese, Korean and Japanese has been removed. Added blocking of 32-bit filter "PICVideo Lossless JPEG Decompressor" (pvljpg20.dll), because it crashes. Added blocking of the system filter "AVI Decompressor", which will eliminate the crash of VFW codecs. Fixed a rare crash when using the "/slave" key. Fixed a crash when getting a list of fonts for OSD. Added the ability to load an external audio file using hotkeys. Fixed opening a network path starting with \?\UNC. The "Determine duration when adding" playlist setting now works for YouTube video URLs. The "Online media services" settings panel has been redesigned. Added a "Merge files using FFmpeg" option to the file saving dialog. This option is activated when playing multiple streams obtained using yt-dlp. Added loading of local .dpl playlists ("DAUMPLAYLIST"). Fixed a hang when the user closes the player during the URL opening process. Various interface fixes. Installer Updated MPC Video Renderer 0.10.5. Updated MPC Script Source 0.2.17. Added MPC Image Source 0.3.6. Translations Updated Japanese translation (by tsubasanouta). Updated Chinese (Traditional) and Dutch translation (by beter). Updated Romanian translation (by Andrei Miloiu). Updated Hungarian translation (by mickey). Updated Turkish translation (by cmhrky). Updated German translation (by Klaus1189). Updated Chinese (Simplified) translation (by wushantao). Updated Italian translation (by mapi68). Updated Korean translation (by Hackjjang). Updated Chinese (Traditional) (by udfbe). Updated libraries dav1d 1.5.3-6-g04b69f9; ffmpeg n8.2-dev-1857-g4653e68aab; libpng git-v1.6.55-9-g7d52a8087; Little-CMS git-lcms2.18-26-gf739cda; MediaInfo git-v26.05-38-g702c9b7fd; ZenLib git-v0.4.41-91-g073f297; zlib 1.3.2. Download: MPC-BE 64-bit | Portable MPC-BE 64-bit | ~20.0 MB (Open Source) Download: MPC-BE 32-bit | Portable MPC-BE 32-bit Link: Media Player Classic - BE Home Page Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Apple reportedly looks to blacklisted Chinese memory chips as RAM prices climb by Karthik Mudaliar Image via Apple Apple is reportedly trying to get a clearance from the Trump administration to buy memory from ChangXin Memory Technologies (CXMT) to get some relief from soaring DRAM prices. As per a report by the Financial Times, Apple approached the Commerce Department more than a month ago and also spoke to other officials and allies in Washington. For starters, CXMT is a company that's already been placed on the Pentagon's list of Chinese military companies. The Chinese company is the country's top DRAM maker. For Apple, the timing is certainly awkward but not surprising. Tim Cook had recently warned that Apple would have to raise prices because AI companies are buying up large amounts of memory for data centers, and just like that, Apple raised MacBook and iPad prices. Micron also recently revealed that customers have committed billions of dollars to secure memory supply years in advance, which shows us how aggressive securing infrastructure has become. This gives suppliers such as Samsung, SK Hynix, and Micron more leverage, while pushing hardware makers to look for alternatives. CXMT is one of those alternatives, but not the simplest one. Apple has spent many years trying to diversify parts of its supply chain away from China, especially for final assembly, while still depending heavily on Chinese manufacturing and suppliers. Even domestic brands from China are moving towards CXMT and YMTC instead of relying on Samsung, Micron, and SK Hynix. For Apple, though, it would invite more scrutiny than local Chinese companies. For now, this is more like a lobbying effort rather than a confirmed supply deal. There's no official statement from either of the parties. What is clearer, though, is the pressure behind such a request. AI demand has certainly made hardware a bottleneck, and companies are trying everything they can to bring things back to normal, even if that means making politically sensitive choices. Source: Financial Times
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      498
    2. 2
      +Edouard
      227
    3. 3
      PsYcHoKiLLa
      149
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      70
  • Tell a friend

    Love Neowin? Tell a friend!