WOT (Web Of Trust) privacy scandal

https://rejzor.wordpress.com/2016/11/02/web-of-trust-wot-privacy-scandal/

I’m not going to copy all the data here, you can read it on my blog with all the external original links and news. WOT is quite popular here if I remember correctly and I thought people will be interested in reading this…

I’ve now turned to avast! Online Security as primary rating tool. I really miss saving of existing ratings and comments with avast!, but it has other goodies and at least avast! team is more open when privacy concerns are raised.

Personally I have never used WOT, Avast rating or any other rating tool, except for testing.
As I don’t think user ratings/opinions add anything significant to a good configured security setup.

Greetz, Red.

Almost no user has a clue what he is talking about when it comes to security and things like that.
And since comments are not checked for accuracy, you can say they are worthless.

Maybe so, but I found it to be interesting resource. Individual comments maybe didn’t mean much, but you could often see a trend and then form your own opinion.

I too used it, not as a slavishly following its rankings, but as guidance.

But that has now ended.

Hi RejZor,

Big thing with WOT canvas fingerprinting and selling your profile to the highest bidder.
Is not Ghostery just doing the same and loads of others. Difference they are upfront about it.

Only sin for WOT was they forgot to mention it in their eula. (vanished from their 2011 add-on edition).

Who was there first and no-one reacted? Wasn’t that and isn’t that Big Data-slurper nr. 1, Google,
and who moans about Facebook’s ridiculous ‘polycor’ censorship? Too big to fail?
(without any rules nor even trying to defend their policies).

I know there is a big Russian userbase out there on WOT, and isn’t that again the “Big Evil Empire” now?

polonus

RejZor is right however about the 100% insecure tracking there.
100% of the trackers on this site could be protecting you from NSA snooping. Tell mywot.com to fix it.

Identifiers | All Trackers
Insecure Identifiers
Unique IDs about your web browsing habits have been insecurely sent to third parties.

6142544 api.mywot.com

And for my.WOT your also dependant on CloudFlare security (a service that I cannot and won’t trust fully with e2e):
Unique IDs about your web browsing habits have been securely sent to third parties.

wXw.mywot.com authid
d00b1cddd5a06799XXXXXXXXXXf85dd281476740859 cdnjs.cloudflare.com __cfduid (anonymized by me - pol)

And the canvas fingerprinting: CanvasFingerprintBlock
Blocked 1 potential HTML canvas fingerprinting attempt on this page
Prevented a script on -https://www.mywot.com from capturing the following 32px × 32px canvas (via toDataURL):

And just as I thought, here they are shown to be security dilletants, a meagre F-Status ::slight_smile:
Re: https://sritest.io/#report/a25ada39-6bff-4513-8b6c-eca48f5096e6

Scripts 2 issues
Tag Result

Missing SRI hash Missing SRI hash

Stylesheets 2 issues
Tag Result

Missing SRI hash Missing SRI hash

And almost ashamed to present these mediocre results F-I-C-I-X with a few A’s in between:
https://observatory.mozilla.org/analyze.html?host=www.mywot.com

RejZoR, the facts are in your favor, man. It’s a drama, I have to admit… :cry:

polonus (volunteer website security analyst and website error-hunter)

More here… (German only)
https://mobilsicher.de/hintergrund/datenhandel-aufgedeckt
https://mobilsicher.de/hintergrund/die-spur-der-daten

Hi Asyn,

WOT has now been catched almost red-handedly to do this. But Mike Kuketz says Ghostery is probably into this too and they are known to even ask their extension user permission to do this on installing the extension.
I see that it is a wide-spread issue on mobile platforms, think of AdMob and MoPub collecting location information and device or mobile network information, seems all Avast apps are AdMob driven now.

So I wonder how many of our Google Chrome extension api’s are “kosher” or “hallal” in this respect.
There is a lot of temptation out there for developers and owners of extensions and it is all about big money.

Again the controversy around WOT never went away and was there from the start.
Read: https://forums.malwarebytes.org/topic/107753-web-of-trust-trusted/

It is the api that is spying on you too. Just install Nirsoft’s WebCookieSniffer and you get an api.mywot.com cookie with authid, a session id cookie and like Kuketz told a language cookie, and all of them are user identifiable. So first thing that happens when I start WebCookieSniffer is an api.mywot.com cookie is being set for all of my existing browsing session.
This is much as what Kuketz describes in a nutshell.

It is not unique as all extensions in Google Chrome are worked that way going first to https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js.
This is so for instance with DrWeb’s URL checker .

There DrWEb is not involved,Google does this and whenever Google cannot do this,
the extensions are not allowed to be on their platform and are thrown out because of some dreamt-up violation of terms.

So actually we have to get accustomed to this situation going on behind our backs all of the time,
and that there is no escape from this really

Now poor fanboyish WOT is being put into the hall of shame, when almost all and every Google or firefox extension/add-on,
for that matter is into this game in one way or another.

Sad, but it is the situation we have, we can no longer get away from this behavior
or are being asked to fill out CloudFlare captcha’s all the time working tor or orbot to prove wer’e human sheeplings,
as RejZoR always so aptly classifies us as human beings.

polonus

Don’t tell me your still crying about a lack of privacy ???
Remember, there isn’t any privacy.

Hi bob3160,

You are so right there, bob3160.

Again there is more to it, than we might think at first hand.
But we really should make people aware.

These extensions are a marvellous way of drawing you further into the so-called “Internet Bubble”, like Pokemon Go etc.

With this “Internet Bubble” we mean that, whenever you expose yourself to services that get more and more of your profile,
you risk being more and more “fenced in” by your Internet surfing history and habits.

Google for instance knows exactly how to do this.
They turned it into a real science, and the final conclusion should be that anyone profits from it -but you, as you are the product.
You make think otherwise. You are wrong again.

By getting to know more and more specifics about your Internet profile, they will more and more confront you with what you already think about yourself.

More and more of your own preferences and likings are “mirrored back” to you to get you hooked into that tunnel vision of yourself further.

And so you may loose sight on what is outside, and that may just be what they want you to do.
That way you only pay attention to issues, that they want you to watch out for,
and you might miss what they do not want you to see.

Try to use a search engine that does not profile you like Duch duck go.
Send an old-fashioned card again once in a while.
Read an online e-book.
Oh, … and turn that screen resolution somewhat down at night in the bedroom,
you may sleep better!

polonus

Web of Trust (WOT) Add-on taken down by Google and Mozilla after reports of selling Users browsing history
http://techdows.com/2016/11/web-of-trust-add-on-removed.html

It’s still available for Mobile devices. Wonder if that also sells your browsing history ???

I wouldn’t take a chance Bob. :wink:

My recommendation is to remove it if you have it. Not to consider it if it’s not currently installed.
http://bob3160.blogspot.com/2016/11/11-3-2016-wot-web-of-trust-not-so.html

Way to go Bob. Good advice.

This is a total fiasco. I am still using WOT, but I blocked data collecting server by adding this to My Filters in uBlock Origin :
52.5.242.93
52.205.103.6
52.73.240.213
52.44.121.119
107.21.18.47
107.21.49.33
prod-mywo-mywotpop-175cqrplyb0n9-2133581242.us-east-1.elb.amazonaws.com

Maybe I am wrong and by blocking this addresses I am actually doing nothing at all.

Personally, when you have to start going to these degrees to stop something like this you really have to consider why you should keep it. Not to mention, what is to stop them adding more IPs, it could be a constantly moving target.

Also as has been mentioned Google and Mozilla have taken down the WOT add-on.

My idea is to disable the add-on/extension in the browser as long as we haven’t heard anything from the alleged perpetrators.
It is a shame my alter-alias has a Silver Membership there (now I am not gonna tell his name).

@ Asyn: “Wer einmal lügt, dem glaubt man nicht, und wenn er auch die Wahrheit spricht.
Das gilt jetzt auch und vor allem für WOT.”

Mozilla now made the WOT add-on unavailable for downloads:
-https://addons.mozilla.org/en-US/firefox/addon/wot-safe-browsing-tool/
You will get a no- found.

WOT users brought angry reactions up at the WOT forum:
-https://www.mywot.com/en/forum/70396--virus-spyware-do-not-install-uninstall-as-soon-as-possible
It now even spilled over to Wikipedia: It’s now mentioned in Wikipedia:
hxxps://en.wikipedia.org/wiki/WOT_Services#Privacy_issues
This is the server (someone has beaten me to it):

Name: -prod-mywo-mywotpop-175cqrplyb0n9-2133581242.us-east-1.elb.amazonaws dot com
Addresses: 52.5.242.93
52.205.103.6
52.73.240.213
52.44.121.119
107.21.18.47
107.21.49.33
Aliases: -secure dot mywot dot com

I saw the wot api cookie disappear suddenly to-day -

The WOT reaction: https://www.mywot.com/en/forum/70476-user-update-from-wot

WOT extension also vanished from the Google Webstore.
My advice try Webutation: chrome-extension://nfclfmabiojpommfcalfdgjjeaahnjbj/html/options.html

Look ups: http://www.webutation.net/

Yesterday I checked on WOT: Good, I had this being blocked for me on WOT: https://dev.visualwebsiteoptimizer.com/j.php?aXXXXXX&u=https%3A%2F%2Fwww.mywot.com%2F&r=0.XXXXXXXXXXXXXXX

Revealing also the results here: http://www.cookiechecker.nl/check-cookies.php?url=www.mywot.com%2F&cache=false
Retirable jQyery: -https://www.mywot.com/
Detected libraries:
jquery - 1.7.1 : (active1) -https://www.mywot.com/
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
(active) - the library was also found to be active by running code
1 vulnerable library detected

And what to think about this external link: http://www.domxssscanner.com/scan?url=https%3A%2F%2Fcdnjs.cloudflare.com%2Fajax%2Flibs%2Fbxslider%2F4.2.5%2Fjquery.bxslider.min.js
working out through -counter.yadro.ru/hit;bgcheck2?r"+

And we should also analyze here, external link: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fconnect.facebook.net%2Fen_US%2Fsdk.js

And they are also into canvas fingerprinting profiling: CanvasFingerprintBlock
Blocked 1 potential HTML canvas fingerprinting attempt on this page
Prevented a script on -https://www.mywot.com from capturing the following 32px × 32px canvas (via toDataURL):

Finally a track the tracker result report: -https://tools.digitalmethods.net/beta/trackerTracker/?jobid=581a5e2512477&json=result&view=renderHtmlTable (analytics, trackers & widgets).

polonus (volunteer website security analyst and website error-hunter)

P.S. In hindsight: https://wyrdwolf.wordpress.com/2015/08/04/how-web-of-trust-can-ruin-your-credibility/

From the WOT privacy policy "SHARING DATA WITH THIRD PARTIES

We do not share any Personal Information collected from you with third parties or any of our partners except in the following events:

Law Requirement: we will share your information, solely to the extent needed to comply with any applicable law, regulation, legal process or governmental request (i.e., to comply with courts injunction, comply with tax authorities, etc.)
Policy Enforcement: we will share your information, solely to the extent needed to enforce our policies (including our policies and agreements), including investigations of potential violations thereof, including without limitations, investigate, detect, prevent, or take action regarding illegal activities or other wrongdoing, suspected fraud or security issues;
Company’s Rights: we will share your information, solely to the extent needed to establish or exercise our rights to defend against legal claims;
Third Party Rights: we will share your information, solely to the extent needed to prevent harm to the rights, property or safety of us, our users, yourself or any third party; or (vi) for the purpose of collaborating with law enforcement agencies or in case we find it necessary in order to enforce intellectual property or other legal rights.
Affiliated Companies: We may share your data with our parent company, any subsidiaries, joint ventures, or other companies under common control (“Affiliated Companies”) solely if and when applicable or necessary for the purposes described in this Privacy Policy.
Corporate Transaction: We may share Information, including Personal Information, in the event of a corporate transaction (e.g. sale of a substantial part of our business, merger, consolidation or asset sale). In the event of the above, our Affiliated Companies or acquiring company will assume the rights and obligations as described in this Privacy Policy.
If we combine Personal Information with Non-Personal Information, the combined information will be treated as Personal Information for as long as it remains combined."

After reading Asyn’s relpy (#11) I’m removing WOT from Firefox, Chrome and Vivaldi.