7 ms·
Skype and Microsoft man-in-the-middle chats to give targeted ads
TL;DR: I sent a friend a link to Kotaku that had the word pizza, and a Dominos ad showed up magically at the top of my browser. I disabled my settings not knowing these are enabled by default.
Long version:
Today I was surfing Kotaku for kicks and started laughing as I was skipping through the YouTube video / article about using a Red Baron Pizza Coupon that was 17 years old. (Link: http://kotaku.com/man-uses-17-year-old-coupon-for-frozen-pizza-bundled-wi-1539878046).
I thought it was great, so I decided to use Skype to pass the word around. No more than 2 seconds after sending the link out I had a nice "Order Dominos Now!" ad at the top of my screen.
FYI: Skype and Microsoft enable targeted ads by DEFAULT. I don't mind having ads be presented to me from past traffic/links/urls/etc. However, I thought it was really uncool that they are man-in-the-middling my chats to give me "a better ad experience" by parsing/mining all my chats.
Link how to disable: https://support.skype.com/en/faq/FA140/how-do-i-manage-my-privacy-settings-in-skype-for-windows-desktop
As always Buyer Beware, and if you don't pay for the product - you ARE the product.
Happy Sunday!
-Phrasz
- blibble 13y agoI personally wouldn't mind, but then Microsoft comes out with crap like this: http://www.scroogled.com/mail http://www.scroogled.com/mail
- phrasz 13y ago"...at the top of my browser." == "top of my Skype Window." To avoid any confusion: they were NOT in my web browsers.
- ryanbrunner 13y agoAt the end of the day, it doesn't even really matter that much. The fact that it appeared in the Skype window doesn't indicate that the targeting of that ad was determined solely by your Skype history. If you visited a site mentioning pizza, and later saw a pizza ad, normal everyday web targeting is a far more likely explanation than Skype secretly violating it's privacy policy as a routine matter of business.
- zeeed 13y agoNot that disabling the setting would keep them from reading or mining your chats though. All that happens is that now you don't get reminded of it anymore.
- devx 13y agoSkype has been MITM'ing chats and even other https links for a long time: http://arstechnica.com/security/2013/05/think-your-skype-messages-get-end-to-end-encryption-think-again/ http://arstechnica.com/security/2013/05/think-your-skype-mes... https://www.eff.org/deeplinks/2013/07/why-doesnt-skype-include-stronger-protections-against-eavesdropping https://www.eff.org/deeplinks/2013/07/why-doesnt-skype-inclu...
- rlu 13y agoI didn't know this but I'm not outraged. How is this different in your view from targeted ads in gmail? You say "I don't mind having ads be presented to me from past traffic" ... why? How does that offend you less? I understand the difference from a technical perspective, but from an "end user that cares about privacy" perspective it seems the same to me. FWIW even with this off, I think Skype will still MITM you to check to make sure URLs you link aren't spammy. Messenger did that ages ago and Facebook does it too (try IMing someone a porn website for example). Not sure what Hangout/gmail's behavior is here. Btw it seems funny to me to use the term "MITM you". It's a chat service. It has servers that route IM and do other things. Of course it's going to be in the middle of you and your friend. Now, if you're upset that one of the many things they do while your IM is in the cloud is see if they can serve an ad for it, then fine. But any chat service that isn't p2p will "MITM you" - that's the entire point.
- MichaelGG 13y agoWell before, Skype was somewhat P2P and supposed to have end-to-end encryption. Obviously they could backdoor it on demand, but in general there was an expectation that, barring a legal order, your chats went were encrypted to their target. (Since Skype has no key exchange UI, obviously these keys are easily tampered with by the Skype service.)
- hexasquid 13y agohmm. skyproogled.
- bobbles 13y agoRelevant Futurama Quote: "Leela: Didn't you have ads in the 21st century?" "Fry: Well sure, but not in our dreams. Only on TV and radio, and in magazines, and movies, and at ball games... and on buses and milk cartons and t-shirts, and bananas and written on the sky. But not in dreams, no siree."
- brownbat 13y agoI'm not shocked either, but it is an annoying reminder that the market will not tolerate end to end encryption. You can't discover someone's marketing preferences if all their habits and speech look like random noise. For some software producers, security is a bug, not a feature.
- gcb0 13y ago> was browsing a site with ads. > saw content X on that site > other sites showed me ads with X kid, this is just targeted advertisement.
- Houshalter 13y agoSkype is a separate application.
- gcb0 13y agoskype is showing ads from some network. the network scanned public content for the site visited previously. nobody is reading any skype messages. user is just paranoid.
- MichaelGG 13y agoSkype has it's Skype Cookies thing, which I believe enables a tracking ID across applications. (Otherwise I'm not sure why Skype would have a cookies setting inside its app.)
- Rizz 13y agoSo? The user's IP address matches his web traffic, no reason why they couldn't send pizza ads to him that way. Remember Microsoft is a Gawker advertising partner (which runs Kotaku), they're even listed first in the list of partners, so no doubt visiting Kotaku will give some of your info to Microsoft, which they can then use to target ads in their ad network. That's how advertising on the internet works. Every visit to an ad supported website means your information is shared with dozens if not hundreds of advertising partners and partners of partners. Edit: I just checked that video page. For me it connects to at least 11 different parties: Facebook + its CDN Youtube + its CDN Google Analytics t.skimresources.com/api.track.php Gawker advertising API Gawker CDN Twitter imrworldwide.com quantserve.com chartbeat.net scorecardresearch.com criteo.com doubleclick.net And your ISP, your DNS service provider, your router manufacturer (yes, some routers intercept traffic and certainly redirect failed dns requests, but might also inject or track other stuff), and of course all running software and browser toolbars/scripts/addins can also know what you visit. And that's just directly, on the background each of those is more than likely to send your information to other advertising partners.
- TempleOSV2 13y agoGod sees everything. Is there a white man I can talk to?
- tsuraan 13y ago> if you don't pay for the product - you ARE the product I paid full price for my XBox 360, within the first year or so of its release. It had a simple and clean interface, pretty much enough to play games and search for/demo/sometimes buy new games. Since then, the UI has gone through various terrible iterations, including full-screen ads for Bing and Zune, and embedded ads for other (non-MS, even non-XBox) products within the main landing page. Even if you do pay for the product, you probably are the product.
- garrettgrimsley 13y agoSame deal with T-Mobile, they have opt-out marketing that you can't disable through the text messaging.
- garrettgrimsley 13y agoEven more upsetting are all of the marketing emails that I receive in my student inbox.
- faddotio 13y agoExactly right, and people here seem to ignore that in favor of convenient ideological screeds. Look at the EULA of what you pay for. It's amazing how little you're entitled to. Even if you paid for it~~~~~
- MichaelGG 13y agoIt may be as you say, or it could just be sharing ads between sites and systems (maybe Skype tracks URLs you click). It's also quite possible that on Sunday around lunchtime, Domino's ran an ad for pizza and you just noticed the coincidence.
- ig1 13y agoThis just speculation with close to zero evidence. It could be coincidence, it could be real-time retargeting based on web traffic, etc. Dominos buys lots of online advertising so the chances of someone seeing a dominos ad straight after talking about Pizza are very high just by pure randomness. If you read the details of the privacy setting it's about Microsoft targeting based upon profile demographics (gender and age). Skype are pretty specific about what they use to target and the reasons they process your messages in their legal docs: http://www.skype.com/en/legal/privacy http://www.skype.com/en/legal/privacy So let's not jump to conclusions without actual evidence.
- camus2 13y agoim.imo used to do skype over https... I'm still looking for a good skype alternative, with video, with secure communications. Cant find a good software.:(
- stal 13y agoTox.IM Is the Open Source Skype REplacement!
- gesman 13y agoI like that statement, so true: "If you don't pay for the product - you ARE the product" I'd add that even if you pay for product - you're still the product. If you don't like being the product, stop using the product :)
- wdr1 13y agoScroogled!
- guiambros 13y agoNo reason for any surprise or conspiracy theories. 1. You visited a site that had "pizza" all over it 2. The page drops SIXTEEN cookies, including all popular ad networks: Criteo, Vizu, SkimLinks, Quantcast, and Google's DoubleClick. 3. For the next couple of hours (or whatever duration specified by Domino's media agency), pizza ads will follow you everywhere. While Skype may be parsing your chat to detect keywords, this would be complicated and potentially against their ToS. Using your browsing behavior is simpler, and a lot more precise. If you're worried about privacy, you should protect your browser in the first place. Start by forcing the Do-Not-Track option, then install Ad Block, and opt-out from all ad tracking networks [1]. Or simply use Incognito mode. Companies can still use IP and browser fingerprinting to uniquely identify you, but that's more work and not portable across ad networks. Not worth the effort for them, just to target a bunch of HN-ers. [1] http://www.networkadvertising.org/choices/ http://www.networkadvertising.org/choices/