View Single Post
Old 30-05-2008, 11:10   #7575
Dephormation
Inactive
 
Join Date: Apr 2008
Location: Bristol
Services: Aquiss.net and loving it. No more Virgin Media, no more Virgin Phone, no more Virgin Mobile.
Posts: 629
Dephormation is a name known to allDephormation is a name known to allDephormation is a name known to allDephormation is a name known to allDephormation is a name known to allDephormation is a name known to allDephormation is a name known to allDephormation is a name known to all
Re: Virgin Media Phorm Webwise Adverts [Updated: See Post No. 1, 77, 102 & 797]

*CONFIRMED*

The btcom.userName/btcom.dateVisited/btcom.isLoggedIn are 'domain cookies' that will be sent to any *.bt.com web site... including webwise.bt.com and www.webwise.bt.com... revealing your email address to Phorm (simply by browsing the pages on webwise.bt.com/ www.webwise.bt.com).

I've asked Rob to do an additional test; I suspect btcom.userName cookie remains set even if you have logged out of bt.com... If so, this would make your email address almost unconditionally available to third parties such as Phorm if you have ever logged in to BT.com.

And presumeably it has been leaking email addresses for months.
Dephormation is offline