Privacy Disclosure

in
Subscribe to Privacy Disclosure 5 posts, 2 voices



Jefferson Scher Script's Author
FirefoxWindows

You probably realize this, but just in case you didn't, every time you contact a web server, it stores information about your request. This disclosure describes the information stored by my web server in relation to this script, and what I do with it.

The following information is current as of July 16, 2011.

File Retrieval and Logging
The screen shots in the main ("About") page for this script, the PDF capture of that page, and the updater script are hosted on my web site. Every time one of those files is retrieved, the web server records certain data in its log, including: the file requested; the date and time; the referring page (not applicable to the updater) and browser identification string sent with your request; and the IP address associated with your connection to my web server.

(A browser identification string looks more or less like this: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:5.0) Gecko/20100101 Firefox/5.0. As you can see, it usually shows your browser and operating system. In some cases, it could list add-ons as well.)

After installation, and during day-to-day use of the script, no information is sent to my web site. The next time you are likely to interact with my web site is when you return to the script's main page and view updated images, or when you install an update and get an updated updater. (When checking on the availability of updates, the updater requests information from userscripts.org, not from my server.)

Use and Storage of Log Information
Currently, this log information is not used for anything other than to try to estimate the number of actual installations (the number on this site appears to be inflated). However, I am interested in learning where the script has been installed globally. This would involve submitting the IP addresses to an analytics site/service that researches their location down to the country or region. I have no interest in identifying individuals or companies, and in most cases that would not be possible based solely on an IP address.

Currently, the log information is stored indefinitely. However, I eventually will start to discard older information over time.

Feel free to post questions.

 
Jefferson Scher Script's Author
FirefoxWindows

For many web sites, you may not mind at all if their know your IP address because you have an account there and you are logged in. They know a lot about you. However, in some cases, it may be embarrassing if the usage is tracked to you, or in politically repressive States, it may be a matter of life or death.

What You Can Do If You Want To Disguise Your IP Address
There are a number of products and services designed to disguise your actual IP address. These include commercial/paid and open source/volunteer products and services (e.g., Anonymizer and Tor). If you do not want web site operators to know your geographic location, you can subscribe to one of these services. I have not reviewed any of them myself and can't make any personal recommendations.

Two cautions: Whoever you choose will know all of your browsing habits, and in some places, your government may be monitoring who connects with these services. Please use your best judgment!

 
Rebecca Mene... Scriptwright
FirefoxWindows

I'm impressed by the up-front disclosure!

Have you considered logging only the statistical data, and throwing away the IPs after processing, or at least anonymizing down to either a hard-coded /16 mask, or else the assigned netblock? (Assigned would require lots of whois traffic, I assume.)

Obviously, this wouldn't help at all if a law enforcement agency invited themselves into your server's location--or just into the server, what with warrants being pesky and all--and got the code modified back to the current state... but at least it would be protection up to that point.

("Give us your logs from January through June!" "Uh... sure. I don't think they'll be very useful, mind.")

 
Jefferson Scher Script's Author
FirefoxWindows

Hi Rebecca, thank you for reading this topic. I think most people aren't paying any attention.

I still haven't gotten around to using the IP address data yet. Or throwing any away that has accumulated since adding the auto-update in March.

I think it's more likely that my hard disk will die than that law enforcement will want the data, but you never know, right?

 
Rebecca Mene... Scriptwright
FirefoxWindows

I do infosec work. Not formally, for the most part--but, yes, I pay attention. It's nice to see someone else who does, too. :)

And, yes, it seems unlikely anyone will ever actually think to go looking for the data, it being extremely obscure compared to, say, wanting to subpoena some Facebook records. Then again, the quiet voice in my head is pointing back to the article about WoW server logs being used in a murder trial, and how it wasn't that long ago at all people got this funny look when you said you'd met your SO "online", as if those people weren't supposed to be real. :)

...still, it's probably not worth worrying about at this point. They'll subpoena *Google*, first. ;)