Categories: Mobile AppsMobility

Web Of Trust Browser Add-On Withdrawn By Mozilla After Privacy Violation

An investigation has uncovered a serious breach of privacy by Web of Trust (WoT), a Finnish firm that specialises in a browser add-on for secure web browsing.

The findings have already prompted Mozilla to remove the WoT add-on from its store. Following that, the firm voluntarily removed the WoT add-on from all other platforms, including the Chrome and Opera store.

Hand In Cookie Jar

Web of Trust (WoT) is essentially a website review and reputation service that since 2007 has been helping people make informed decisions about whether to trust a website or not.

It has been downloaded over 140 million times, and is a popular browser add-on for Firefox, Google Chrome, Opera and Internet Explorer. It uses a crowdsourcing approach to rate websites based on trustworthiness and child safety.

But the German TV channel NDR discovered some worrying privacy issues with WoT.

Firstly it seems that WoT has been collecting the browsing history of its millions of users and has been selling this data to third parties.

Secondly, and even worse, it seems the firm did not properly anonymise the data it collects on its users, which potentially allows others to expose the identity of the users and all their personal details.

This is in direct violation of WoT’s own privacy policy.

That policy does admit that the firm collects the user’s IP address, geo-location, the type of device, operating system, and browser, as well as the date and time, web addresses, and browser usage. But it said that this data in stored in a  “non-identifiable” format.

However the NDR investigation found it was very easy to link the anonymised data to its individual users.

For example, the investigators, using the sample data from just 50 WoT users, were able to identify a raft of high personal information including the account name, mailing address, shopping habits, travel plans, possible illnesses, sexual preferences, drug consumption, confidential company information, ongoing police investigations, and finally the entire browser surfing activity including all the websites visited.

Policy Overhaul

WoT has promised a ‘complete overhaul’ of its data cleaning process, but only for those users whose data it uses.

“We take our obligations to you very seriously,” it said in a statement. “While we deployed great effort to remove any data that could be used to identify individual users, it appears that in some cases such identification remained possible, albeit for what may be a very small number of WOT users.”

The firm said it was now reviewing its privacy policy to determine which changes need to be made; and will give users the ability to opt out from the data stored in its database.

It said those people who opt to continue to allow WoT to use their browsing data, “we will implement a complete overhaul of our data ‘cleaning’ process, to optimize our data anonymisation and aggregation objectives to minimise any risk of exposure for our users”.

“We will spend the coming weeks making the changes to WOT which will ensure we are back on the right track,” it added.

It now remains up to WoT users to decide whether to trust the firm, or uninstall the add-on completely.

Mozilla last week also disabled an API in Firefox over concerns it could be used to track users. It said it had disabled the ability of websites to access the Battery Status API in Firefox 52, after warnings from security researchers that the feature could allow the user to be tracked.

Think you know all about online privacy? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

US Awards $6.4bn To Samsung For Expanded Texas Chip Production

US awards $6.5bn to Samsung Electronics under Chips Act as it seeks to expand domestic…

8 hours ago

Tesla Cuts More Than 10 Percent Of Workforce

Tesla lays off more than 10 percent of staff worldwide amidst slower growth, tougher competition…

14 hours ago

Huawei Building Massive Chip R&D Centre In Shanghai

Huawei now developing own chip manufacturing technology as it seeks ways around increasing US restrictions

20 hours ago

Deepfakes: More Than Skin Deep Security

As deepfake technology continues to blur the lines between reality and deception, businesses and individuals…

20 hours ago

Huawei To Sell Laptop With Latest Intel Core Ultra AI Chip

US-sanctioned Huawei to sell MateBook Pro X model powered by latest Intel Core Ultra 9…

21 hours ago

OpenAI Fires Two Researchers Over Information Leaks

OpenAI fires two researchers for leaking information in first known shake-up since Sam Altman briefly…

21 hours ago