Recommended Posts

Hi,

 

I've searched the web but can't find a topic similar enough nor a forum exactly tailored to this topic, so I hope it is OK to ask here.

 

Early this morning I was looking at furniture on Sears regular and Outlet websites.  I came back later to see an email that was time stamped 6:01am from Sears with the subject "? We've got a surprise! Thanks for looking

Welcome, and may I say, well done for taking the time to post correctly.

As for the email, I have no idea on how they could do that without any input from you.

Was the information you recieved in almost exact relation to what you were browsing?

Were you signed into a browser at the time?

UPDATE

 

I know I posted only minutes ago, but I just zoomed in to look closer at the incredibly fine print at the bottom of the Sears spam email.  (I just got fitted for multifocal lenses and it is a bear getting used to focusing on small type right now).  Anyhow, here is the privacy disclosure link to the company that seems to be proudly responsible for this apparent email stealing technology (I hope the link is OK to post as it is general and freely available):

 

http://privacy.criteoemail.com/us/privacy-policy.html

 

 

I don't know how they could extract my email from just the related cookies but I assume there may be a way it is encoded into other tracking info from sites where I may have stored my email address or communicated through a web form.  This is scary.  I'm afraid to use their opt-out button.  Will research further.

 

Any experience or opinions with this BS?  Thanks!

Welcome, and may I say, well done for taking the time to post correctly.

As for the email, I have no idea on how they could do that without any input from you.

Was the information you recieved in almost exact relation to what you were browsing?

Were you signed into a browser at the time?

Hi, thanks for the reply.  I've also updated my post which probably explains 'what' is happening, but not 'how'.

 

It appears to be a fairly legitimate looking spam email from Sears, and it includes an inset sofa image, one that I was looking at.  In of itself the ad inset is not surprising, though the email "knowledge" is, and scary as well.  As I tried to describe, this is an email address that is not linked to any type of Gmail or similar cross-linking or social site/plugin/etc.  I was using IE and do have Google as my home page, and do have a Gmail address that may have been logged in (I don't always log out of Gmail, it is just a throwaway account) but at any rate they emailed my primary paid email address that is not linked to anything like what you suggest.

Does your browser support/have do not track enabled? If not it's possible it could have been extracted from a tracking cookie.

Thanks for the reply.  This is a new install on a "write zeroed" HDD, so I am still tweaking everything.  I started immediately with AV and anti malware running constant protection.  I just went into IE options and set 3rd party cookies to 'Prompt' so I can see what comes up.  Unfortunately I had them enabled before this.  AFAIK, "do not track" in IE is only accomplished by restricting cookies.  I could certainly be wrong.

Does your browser support/have do not track enabled? If not it's possible it could have been extracted from a tracking cookie.

DNT is a bit of a useless feature since the whole ignoring IE's option debacle and not many sites even paying attention to it anyway.

Get noscript and disable scripts from running on sites that could things like this, although they'd still know that you looked at items (cookies) they wouldn't get anything like google analytics, and you can browse in private mode to bypass that too.

I get these from newegg or Amazon at times. I'll be browsing. And a few hours later I'll get an email with things similar to what I was browsing.

I get it in my Facebook stream all the time. I'm thinking about writing a program to auto-clear cookies from my caches after each browser closing.

The only plausible explanation I can think of if you weren't logged in is that they already have a browser fingerprint record of your computer (See: https://amiunique.org/ or https://panopticlick.eff.org/

 

Since you said it was a "new W7 installation" rather than a new PC, I'm assuming you just reformatted, in which case your browser fingerprint wouldn't really change as far as I know.

  • Like 1

The only plausible explanation I can think of if you weren't logged in is that they already have a browser fingerprint record of your computer (See: https://amiunique.org/ or https://panopticlick.eff.org/

 

Since you said it was a "new W7 installation" rather than a new PC, I'm assuming you just reformatted, in which case your browser fingerprint wouldn't really change as far as I know.

Thank you, that seems plausible.  I believe that XP installs used to look at unique features like hardware MAC addresses, and saved a code that was generated from all of that data, which became the basis for approving a reinstall on the same machine.  I experimented with that in the early 2000's by necessity, changing out failed hardware devices and reformatting, and never had it fail to certify the copy of XP automatically.  They might have programmed some wiggle room into it.

 

Yes, it was a clean re-installation of W7 Pro on an existing machine, as I recently fell victim to a ransomeware attack.  I cleaned up the virus and restored my files from backups but to be safe felt it was worth the extra effort to reformat and reinstall.  Now I am paranoid about security since I don't even know how I got the ransomware in the first place.  I don't open unknown files or browse seedy sites.  Thanks again for the idea and links about unique browser detection.

Do you have a common name/email?

Have you been into a store? and maybe used their Wifi? Then gone home and used your Wifi? AdvertisingID....

Install Ghostery, Its amazing how many calls to third party API's Trackers and Beacons you get stopped

 

I highly recommend this to anyone.

 

https://www.ghostery.com/en/

 

Its a strange scary old world we live in. 

The only plausible explanation I can think of if you weren't logged in is that they already have a browser fingerprint record of your computer (See: https://amiunique.org/ or https://panopticlick.eff.org/

 

Since you said it was a "new W7 installation" rather than a new PC, I'm assuming you just reformatted, in which case your browser fingerprint wouldn't really change as far as I know.

That's a bit of nonsense really, if it's a fresh install the fingerprint data will show: timezone, IE version, screen resolution, additional software installed (none), language, cookies (none) - what you're trying to say is that the owner of a large domain can take that information and match it up to one user, well no, there will be at a bare minimum 10,000 visitors to the site with the exact same configuration and therefore 'browser fingerprint'.

The most likely scenario is the site was logged into or something from a third party site, then the cookie with/without javascript was used to get finer details and the background email system fired off an email to the account holder.

Do you have a common name/email?

Have you been into a store? and maybe used their Wifi? Then gone home and used your Wifi? AdvertisingID....

Install Ghostery, Its amazing how many calls to third party API's Trackers and Beacons you get stopped

 

I highly recommend this to anyone.

 

https://www.ghostery.com/en/

 

Its a strange scary old world we live in. 

Not common, no.  I don't use public wifi, at least I haven't in a long time.  Thanks for the link, I'll check Ghostery out.

That's a bit of nonsense really, if it's a fresh install the fingerprint data will show: timezone, IE version, screen resolution, additional software installed (none), language, cookies (none) - what you're trying to say is that the owner of a large domain can take that information and match it up to one user, well no, there will be at a bare minimum 10,000 visitors to the site with the exact same configuration and therefore 'browser fingerprint'.

The most likely scenario is the site was logged into or something from a third party site, then the cookie with/without javascript was used to get finer details and the background email system fired off an email to the account holder.

I'm not saying you're wrong, but did you visit the sites I linked? Even if you do a clean install, you're highly likely going to install all the same plugins/software and configure everything the same way. OP did say that it was a "one week old installation" so he would already have everything installed.

I get it in my Facebook stream all the time. I'm thinking about writing a program to auto-clear cookies from my caches after each browser closing.

Why?  All 3 major browsers Firefox, Chrome and even IE have this option already built in.

 

Here is settings in firefox that allow you to clear you cookies when you close your browser, delete them on close, etc.  Both chrome and IE also have settings like this - just showing firefox because that is browser I use 99% of the time.

 

post-14624-0-03497100-1437430261.png

Why?  All 3 major browsers Firefox, Chrome and even IE have this option already built in.

 

Here is settings in firefox that allow you to clear you cookies when you close your browser, delete them on close, etc.  Both chrome and IE also have settings like this - just showing firefox because that is browser I use 99% of the time.

 

attachicon.gifclearcookies.png

You know, I'm one of those standard guppies when it comes to browsers. It works, so I don't mess with it. I never knew FF had this option. Now, to find it on Chrome!

This topic is now closed to further replies.
  • Posts

    • I was using searxng for about a year , self hosted, but results were starting to timeout and eventually it became unusable so I switched to degoog. Much better for my needs, more polished and add-ons like maps and calculations etc
    • Fake Superman doing the Anti-Trump PR for us, good man !
    • Hello, I am not as familiar with AMD CPUs as I am with Intel's, but as I understand it, that's a mid-range CPU from about three years ago.  I would think it to be fine for everyday casual-type use.  A larger SSD might be better, but with storage prices these days that's a decision that has to be carefully thought about. Regards, Aryeh Goretsky  
    • Ocenaudio 3.19.5 by Razvan Serea  Ocenaudio is a full featured, fast and easy to use audio and music editor. It is the ideal software for people who need to edit and analyze audio files without complications. Ocenaudio also has powerful features that will please more advanced users. To assist ocenaudio development, a powerful toolset of audio editing, analysis and manipulation called Ocen Framework was created. ocenaudio is also based on Qt framework, a well known library for cross-platform development. Cross-platform support ocenaudio is available for all major operating systems: Microsoft Windows, Mac OS X and Linux. Native applications are generated for each platform from a common source, in order to achieve excelent performance and seamless integration with the operating system. All versions of ocenaudio have a uniform set of features and the same graphical interface, so the skills you learn in one platform can be used in the others. VST plugins support Ocenaudio supports VST (Virtual Studio Technology) plugins, giving its users access to numerous effects. Like the native effects, VST effects can use real-time preview to aide configuration. Real-time preview of effects Applying effects such as EQ, gain and filtering is an important part of audio editing. However, it is very tricky to get the desired result by adjusting the controls configuration alone: you must listen the processed audio. To ease the configuration of audio effects, ocenaudio has a real time preview feature: you hear the processed signal while adjusting the controls. The effect configuration window also includes a miniature view of the selected audio signal. You can navigate on this miniature view in the same way as you do on the main interface, selecting parts that interest you and listening to the effect result in real time. Multiselection for delicate editions To speed up complex audio files editing, ocenaudio includes multi-selection. With this amazing tool, you can simultaneously select different portions of an audio file and listen, edit or even apply an effect to them. For example, if you want to normalize only the excerpts of an interview where the interviewee is talking, just select them and apply the effect. Eficient edition of large files With ocenaudio, there is no limit to the length or the quantity of the audio files you can edit. Using an advanced memory management system, the application keeps your files open without wasting any of your computer's memory. Even in files several hours long, common editing operations such as copy, cut or paste happen almost instantly. Fully featured spectrogram Besides offering an incredible waveform view of your audio files, ocenaudio has a powerful and complete spectrogram view. In this view, you can analyze the spectral content of your audio signal with maximum clarity. Advanced users will be surprised to find that the spectrogram settings are applied in real time. The display is updated immediately when altering features such as the number of frequency bands, window type and size and dynamic range of the display. Ocenaudio 3.19.5 changelog: Fixes crashes related to audio devices on Windows (DirectSound and ASIO) Fixes several crashes and memory corruption issues Fixes opening several headerless files at once, which previously dropped all but one Improves batch export by suggesting and remembering the destination folder Fixes accented and non-Latin characters in VST plug-in and compressed-archive file names Adds zstd compression support and updates the archive library Other bug fixes and improvements Download: Ocenaudio 64-bit | Portable | ~40.0 MB (Freeware) Download: Ocenaudio for Linux and Mac OS View: Ocenaudio Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      +Edouard
      204
    3. 3
      PsYcHoKiLLa
      145
    4. 4
      Steven P.
      72
    5. 5
      FloatingFatMan
      68
  • Tell a friend

    Love Neowin? Tell a friend!