Testing lab publicly rebukes security products' privacy policies
Full article655 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Many software security products like anti-malware programs come with privacy policies that would make a peeping Tom blush, according to an analysis by an independent third-party testing laboratory.
Many software security products, like anti-malware programs, come with privacy policies that are anything but private, according to an analysis by an independent third-party testing laboratory.
“In almost every privacy policy examined, the manufacturers presume a vast number of access rights to data that should not be necessary for using a security software application,” concludes the analysis published last week by the AV-Test Institute.
The AV-Test Institute, a Magdeburg, Germany-based company that evaluates computer security products, analyzed the English-language privacy policies for 26 security products from major manufacturers including Avast, AVG, ESET, F-Secure, Fortinet, Kaspersky, McAfee/Intel Security, Symantec and Trend Micro.
Most of the policies said the manufacturer would collect user data including name, email address, phone numbers and bank or payment card details. The analysis states that while this information might be useful for marketing purposes “they are hardly necessary for using the [security] programs.”
Some products’ policies, however, went a great deal further than that — asserting rights over biometric data, as well as the user’s gender, occupation, race and sexual orientation.
Andreas Marx, the institute’s CEO, told Cyberscoop he didn’t want to share “individual details” of which policy asserted which rights over user data because “this was only the first part of our research.”
“Some manufacturers are working on improving their data protection/privacy policies at the moment, based on our feedback,” he wrote in an email. “Besides this, we expect some technical changes in certain products, too,” again as a result of their feedback to manufacturers.
Two of the products lacked a privacy policy of any kind and most were written with impenetrable jargon, the institute’s analysis found.
“The policies were barely comprehensible for normal users,” notes the analysis, adding their average length was 12 pages. “Long sentences and lots of technical terms make it even more difficult to understand what are already very long texts.”
Fifteen manufacturers required access to users’ browser history and six to users’ search queries. Five asserted the right to sift email content and two to full accessibility of the users’ personal address books. “One manufacturer even claimed the right to publish [social media] entries on behalf of users,” while others want to be involved in chat sessions, or access chat history.
The institute’s testers made no effort to discover what information the programs actually collected, states the analysis. “Determining whether this data is actually collected was not a substantive aim of this examination,” it says, adding that it will address these issues in follow up research and communication with manufacturers.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/testing-lab-publicly-rebukes-security-products-privacy-policies/