EFF Warns of Major Ubuntu Privacy Issue
Users' IP addresses and search terms can be shared with Amazon, Facebook, Vimeo and others.
"The issues that the EFF is raising are related to a feature called Dash in the Ubuntu Unity desktop that is designed to be a central search mechanism for documents, files and other information both on the local machine and online," writes Threatpost's Dennis Fisher. "When a user searches for a given term, the query is sent to a Ubuntu server, and the query also includes your IP address. The search results, depending upon the query, may include products from Amazon related to the search term. This is one of the main things that has drawn the ire of EFF staffers."
"The EFF complains that image data sent back from Amazon to the user's PC is not encrypted, that users have no control over the data stored on Canonical's servers and that the company is vague in its description of what the accumulated data is used for," The H Open reports. "While outgoing queries to Canonical and online shopping providers such as Amazon are sent over HTTPS, the returned product images are sent in clear text, which enables bad actors listening in on the user's network traffic to reconstruct what the user was searching for."
"The outcry prompted a spirited response from Canonical CEO Mark Shuttleworth, who wrote in a blog post that the Amazon integration was just the first step in an expansion designed to make the Dash search engine 'smarter,'" writes Sophos' Paul Roberts. "The Amazon results are just search results -- not ads, Shuttleworth argued. And users can choose not to search Amazon if they want, while future releases will make it easier to opt-out of searching across third party services, he said. 'What we have in 12.10 isn't the full experience, so those who leap to judgement are at maximum risk of having to eat their words later. Chill out,' he wrote."