Adobe, Omniture in hot water for snooping on CS3 users

By Koushik Saha on 1.1.08

Filed Under: ,

It all began with a post at UNEASYsilence titled "Lies, Lies and Adobe Spies" which caught on to the fact that Adobe CS3 apps were calling out to a suspiciously-crafted IP address. As it turns out, the IP in question—192.168.112.2O7.net (note the capital O instead of a zero)—is not an IP at all, but rather a domain owned by statistics-tracking firm Omniture.

Criticism and conspiracy theories quickly erupted across the web, calling for an answer from Adobe over what looked like a clear invasion of privacy crafted to look like a typical local IP address. The holidays aren't always the best time to ask a corporation as large as Adobe for an answer on issues like this, but Photoshop Product Manager John Nack came to at least a preliminary rescue. Across a couple of posts at his official Adobe blog, Nack took it upon himself to dig into the matter. According to Nack's investigation, Adobe's CS3 apps call out to Omniture's services to track a few usage statistics across Adobe products. Specifically, only three things are tracked: the news items presented in some apps' welcome screens, Adobe-hosted content loaded in Bridge's implementations of Opera and Flash Player (Bridge is the asset management component of Creative Suite), and Adobe online help systems like forums and the Exchange service, but only upon a user's request.As for the suspicious nature of Omniture's faux-IP URL, Nack is less sure. He also agrees with users' concerns over the matter and says he's doing his best to find out more. It is likely, however, that Omniture is not returning Nack's calls just as it isn't returning Ars Technica's, again probably due to holiday vacations. Other theories postulate that the URL crafting is both a technical and social engineering attempt to fool curious users and firewalls that might use some kind of wild card to allow 192.168.* requests. An underhanded tactic to be sure, but one that would allow Omniture to continue collecting usage statistics from many of Adobe's users.

Source :http://arstechnica.com/

0 comments for this post