Online Advertising and Hidden Hazards to Consumer Security and Data Privacy
Total Page:16
File Type:pdf, Size:1020Kb
S. Hrg. 113–407 ONLINE ADVERTISING AND HIDDEN HAZARDS TO CONSUMER SECURITY AND DATA PRIVACY HEARING BEFORE THE PERMANENT SUBCOMMITTEE ON INVESTIGATIONS OF THE COMMITTEE ON HOMELAND SECURITY AND GOVERNMENTAL AFFAIRS UNITED STATES SENATE ONE HUNDRED THIRTEENTH CONGRESS SECOND SESSION MAY 15, 2014 Available via the World Wide Web: http://www.fdsys.gov Printed for the use of the Committee on Homeland Security and Governmental Affairs ( U.S. GOVERNMENT PRINTING OFFICE 89–686 PDF WASHINGTON : 2014 For sale by the Superintendent of Documents, U.S. Government Printing Office Internet: bookstore.gpo.gov Phone: toll free (866) 512–1800; DC area (202) 512–1800 Fax: (202) 512–2104 Mail: Stop IDCC, Washington, DC 20402–0001 COMMITTEE ON HOMELAND SECURITY AND GOVERNMENTAL AFFAIRS THOMAS R. CARPER, Delaware Chairman CARL LEVIN, Michigan TOM COBURN, Oklahoma MARK L. PRYOR, Arkansas JOHN MCCAIN, Arizona MARY L. LANDRIEU, Louisiana RON JOHNSON, Wisconsin CLAIRE MCCASKILL, Missouri ROB PORTMAN, Ohio JON TESTER, Montana RAND PAUL, Kentucky MARK BEGICH, Alaska MICHAEL B. ENZI, Wyoming TAMMY BALDWIN, Wisconsin KELLY AYOTTE, New Hampshire HEIDI HEITKAMP, North Dakota RICHARD J. KESSLER, Staff Director KEITH B. ASHDOWN, Minority Staff Director LAURA W. KILBRIDE, Chief Clerk LAUREN M. CORCORAN, Hearing Clerk PERMANENT SUBCOMMITTEE ON INVESTIGATIONS CARL LEVIN, Michigan Chairman MARK L. PRYOR, Arkansas JOHN MCCAIN, Arizona MARY L. LANDRIEU, Louisiana RON JOHNSON, Wisconsin CLAIRE MCCASKILL, Missouri ROB PORTMAN, Ohio JON TESTER, Montana RAND PAUL, Kentucky TAMMY BALDWIN, Wisconsin KELLY AYOTTE, New Hampshire HEIDI HEITKAMP, North Dakota ELISE J. BEAN, Staff Director and Chief Counsel DANIEL J. GOSHORN, Counsel HENRY J. KERNER, Minority Staff Director and Chief Counsel JACK THORLIN, Counsel to the Minority BRAD M. PATOUT, Senior Advisor to the Minority SCOTT WITTMANN, Research Assistant to the Minority MARY D. ROBERTSON, Chief Clerk (II) C O N T E N T S Opening statements: Page Senator Levin .................................................................................................... 1 Senator McCain ................................................................................................ 1 Senator Johnson ............................................................................................... 22 Senator McCaskill ............................................................................................ 26 Senator Portman .............................................................................................. 30 Prepared statements: Senator Levin .................................................................................................... 47 Senator McCain ................................................................................................ 49 WITNESSES THURSDAY, MAY 15, 2014 Alex Stamos, Vice President of Information Security, and Chief Information Security Officer, Yahoo! Inc., Sunnydale, California ......................................... 7 George F. Salem, Senior Product Manager, Google Inc., Mountain View, Cali- fornia ..................................................................................................................... 10 Craig D. Spiezle, Executive Director, Founder, and President, Online Trust Alliance, Washington, DC .................................................................................... 12 Maneesha Mithal, Associate Director, Division of Privacy and Identity Protec- tion, Federal Trade Commission, Washington, DC ........................................... 35 Luigi ‘‘Lou’’ Mastria, Executive Director, Digital Advertising Alliance, New York, New York .................................................................................................... 37 ALPHABETICAL LIST OF WITNESSES Mastria, Luigi ‘‘Lou’’: Testimony .......................................................................................................... 37 Prepared statement .......................................................................................... 94 Mithal, Maneesha: Testimony .......................................................................................................... 35 Prepared statement .......................................................................................... 79 Salem, George F.: Testimony .......................................................................................................... 10 Prepared statement .......................................................................................... 59 Spiezle, Craig D.: Testimony .......................................................................................................... 12 Prepared statement with attachments ........................................................... 67 Stamos, Alex: Testimony .......................................................................................................... 7 Prepared statement .......................................................................................... 55 APPENDIX Report by the Permanent Subcommittee entitled ‘‘Online Advertising and Hidden Hazards to Consumer Security and Data Privacy.’’ ............................. 106 EXHIBIT LIST 1. Increase Display Malvertising, chart prepared by RiskIQ ............................ 162 2. Proliferation & Impact, chart prepared by Online Trust Alliance ............... 163 3. Third-Party Website Calls on TDBank.com, chart prepared by the Per- manent Subcommittee on Investigations’ Minority Staff, Source: TDBank.com, Disconnect Private Browsing. .................................................. 164 (III) IV Page 4. Third-Party Website Calls on TMZ.com, chart prepared by the Permanent Subcommittee on Investigations’ Minority Staff, Source: TMZ.com, Dis- connect Private Browsing. ................................................................................ 165 5. Comparison of Third-Party Website Calls, chart prepared by the Perma- nent Subcommittee on Investigations’ Minority Staff, Source: TDBank.com, TMZ.com, Disconnect Private Browsing. ................................ 166 6. Good Money Gone Bad, Digital Thieves and the Hijacking of the Online Ad Business, A Report on the Profitability of Ad-Support Content Theft, February 2014, report prepared by the Digital Citizens Alliance ................ 167 7. a. Responses of Maneesha Mithal, Federal Trade Commission, to supple- mental questions for the record from Senator Carl Levin ....................... 196 b. Responses of Maneesha Mithal, Federal Trade Commission, to supple- mental questions for the record from Senator John McCain .................. 198 c. Responses of Maneesha Mithal, Federal Trade Commission, to supple- mental questions for the record from Senator Ron Johnson .................... 201 d. Responses of Maneesha Mithal, Federal Trade Commission, to supple- mental questions for the record from Senator Kelly Ayotte .................... 202 8. Responses of George Salem, Google, Inc., to supplemental questions for the record from Senator Ron Johmson ........................................................... 207 9. Responses of Alex Stamos, Yahoo! Inc., to supplemental questions for the record from Senator Ron Johnson ............................................................ 208 10. Responses of Craig Spiezle, Online Trust Alliance, to supplemental ques- tions for the record from Senator Ron Johnson ............................................. 210 ONLINE ADVERTISING AND HIDDEN HAZARDS TO CONSUMER SECURITY AND DATA PRIVACY THURSDAY, MAY 15, 2014 U.S. SENATE, PERMANENT SUBCOMMITTEE ON INVESTIGATIONS, OF THE COMMITTEE ON HOMELAND SECURITY AND GOVERNMENTAL AFFAIRS, Washington, DC. The Subcommittee met, pursuant to notice, at 9:32 a.m., in room SD–342, Dirksen Senate Office Building, Hon. Carl Levin, Chair- man of the Subcommittee, presiding. Present: Senators Levin, McCaskill, McCain, Johnson, and Portman. Staff present: Daniel J. Goshorn, Counsel; Mary D. Robertson, Chief Clerk; Henry J. Kerner, Staff Director and Chief Counsel to the Minority; Jack Thorlin, Counsel to the Minority; Brad M. Patout, Senior Advisor to the Minority; Scott Wittmann, Research Assistant to the Minority; Samira Ahmed, Law Clerk; Rebecca Pskowski, Law Clerk; Kyle Brosnan, Law Clerk to the Minority; Nick Choate (Sen. McCaskill); Brooke Erickson and Mike Howell (Sen. Johnson); and Derek Lyons (Sen. Portman). OPENING STATEMENT OF SENATOR LEVIN Senator LEVIN. Good morning, everybody. For almost a year, the Permanent Subcommittee on Investigations has been investigating hidden hazards to consumers’ data privacy and security that re- sults from online advertising. Our Subcommittee operates in a very bipartisan way, and our practices and our rules provide that the Ranking Minority Member may initiate an inquiry, and our tradi- tion is for both sides of the aisle to work on investigations together, and our staffs work very closely together. This investigation was initiated and led by Senator McCain, so I would like to call on him to give his opening statement first, after which I will add a few additional remarks. But first I would like to commend Senator McCain for his leadership and his staff for their very hard work in addressing the facts and issues that are the subject of today’s hearing. Senator McCain. OPENING STATEMENT OF SENATOR McCAIN Senator MCCAIN. Thank you, Mr. Chairman. I appreciate you and your staff’s cooperation in conducting this important bipartisan investigation, which has been the hallmark of our relationship to- (1) 2 gether