Web beacon explained

A web beacon[1] is a technique used on web pages and email to unobtrusively (usually invisibly) allow checking that a user has accessed some content.[2] Web beacons are typically used by third parties to monitor the activity of users at a website for the purpose of web analytics or page tagging.[3] They can also be used for email tracking.[4] When implemented using JavaScript, they may be called JavaScript tags.[5] Web beacons are unseen HTML elements that track a webpage views. Upon the user revisiting the webpage, these beacons are connected to cookies established by the server, facilitating undisclosed user tracking.[6]

Using such beacons, companies and organizations can track the online behavior of web users. At first, the companies doing such tracking were mainly advertisers or web analytics companies; later social media sites also started to use such tracking techniques, for instance through the use of buttons that act as tracking beacons.

In 2017, W3C published a candidate specification for an interface that web developers can use to create web beacons.[7]

Overview

A web beacon is any of several techniques used to track who is visiting a web page. They can also be used to see if an email was read or forwarded or if a web page was copied to another website.[8]

The first web beacons were small digital image files that were embedded in a web page or email. The image could be as small as a single pixel (a "tracking pixel") and could have the same colour as the background, or be completely transparent.[9] When a user opens the page or email where such an image is embedded, they might not see the image, but their web browser or email reader automatically downloads the image, requiring the user's computer to send a request to the host company's server, where the source image is stored. This request provides identifying information about the computer, allowing the host to keep track of the user.

This basic technique has been developed further so that many types of elements can be used as beacons. Currently, these can include visible elements such as graphics, banners, or buttons, but also non-pictorial HTML elements such as the frame, style, script, input link, embed, object, etc., of an email or web page.

The identifying information provided by the user's computer typically includes its IP address, the time the request was made, the type of web browser or email reader that made the request, and the existence of cookies previously sent by the host server. The host server can store all of this information, and associate it with a session identifier or tracking token that uniquely marks the interaction.

Use by companies

See also: Facebook beacon. Once a company can identify a particular user, the company can then track that user's behavior across multiple interactions with different websites or web servers. As an example, consider a company that owns a network of websites. This company could store all of its images on one particular server, but store the other contents of its web pages on a variety of other servers. For instance, each server could be specific to a given website, and could even be located in a different city. But the company could use web beacons requesting data from its one image server to count and recognize individual users who visit different websites. Rather than gathering statistics and managing cookies for each server independently, the company can analyze all this data together, and track the behavior of individual users across all the different websites, assembling a profile of each user as they navigate through these different environments.

Email tracking

See main article: Spy pixel. Web beacons embedded in emails have greater privacy implications than beacons embedded in web pages. Through the use of an embedded beacon, the sender of an email – or even a third party – can record the same sort of information as an advertiser on a website, namely the time that the email was read, the IP address of the computer that was used to read the email (or the IP address of the proxy server that the reader went through), the type of software used to read the email, and the existence of any cookies previously sent. In this way, the sender – or a third party – can gather detailed information about when and where each particular recipient reads their email. Every subsequent time the email message is displayed, the same information can be sent again to the sender or third party.

"Return-receipt-to" (RRT) email headers can also trigger sending of information and these may be seen as another form of a web beacon.[10]

Web beacons are used by email marketers, spammers, and phishers to verify that an email is read. Using this system, they can send similar emails to a large number of addresses and then check which ones are valid. Valid in this case means that the address is actually in use, that the email has made it past spam filters, and that the content of the email is actually viewed.

To some extent, this kind of email tracking can be prevented by configuring the email reader software to avoid accessing remote images.

One way to neutralize such email tracking is to disconnect from the Internet after downloading email but before reading the downloaded messages. (Note that this assumes one is using an email reader that resides on one's own computer and downloads the emails from the email server to one's own computer.) In that case, messages containing beacons will not be able to trigger requests to the beacons' host servers, and the tracking will be prevented. But one would then have to delete any messages suspected of containing beacons or risk having the beacons activate again once the computer is reconnected to the Internet.

Web beacons can also be filtered out at the server level so that they never reach the end-user.

Beacon API

The Beacon API (application programming interface) is a candidate recommendation of the World Wide Web Consortium, the standards organization for the web.[11] It is a standardized API that directs the web client to silently send tracking data back to the server, i.e. without alerting the user and thus disturbing their experience.

Use of this Beacon API enables user tracking and profiling without the end-user's awareness, as it is invisible to them, and without delaying or otherwise interfering with navigation within or away from the site.[12] Support for the Beacon API was introduced into Mozilla's Firefox browser in February 2014[13] and in Google's Chrome browser in November 2014.[14]

External links

Notes and References

  1. Also called web bug, tracking bug, tag, web tag, page tag, tracking pixel, pixel tag, 1×1 GIF, spy pixel, or clear GIF.
  2. Web site: Nearly undetectable tracking device raises concern. January 2, 2002. Stefanie Olsen. CNET News. May 23, 2019. November 7, 2014. https://web.archive.org/web/20141107101823/http://news.cnet.com/2100-1017-243077.html. live.
  3. Web site: The Web Bug FAQ . Richard M. Smith . EFF.org Privacy Archive . November 11, 1999 . July 12, 2012 . June 29, 2012 . https://web.archive.org/web/20120629051001/http://w2.eff.org/Privacy/Marketing/web_bug.html . live .
  4. Web site: Email web bug invisible tracker collects info without permission. mailsbroadcast.com. Richard Lowe Jr And Claudia Arevalo-Lowe. August 22, 2016. December 3, 2017. https://web.archive.org/web/20171203232852/http://www.mailsbroadcast.com/email.bolts.nuts/about.web.bugs.htm. live.
  5. Web site: Negrino, Tom; Smith, Dori. JavaScript para World Wide Web. Pearson Education, 2001. accessed 1 October 2015 . October 1, 2015 . May 12, 2016 . https://web.archive.org/web/20160512003443/http://ejournals.bc.edu/ojs/index.php/ital/article/viewFile/1771/1677 . dead .
  6. Book: Payton, Anne M. . A review of spyware campaigns and strategies to combat them . 2006-09-22 . Proceedings of the 3rd annual conference on Information security curriculum development . https://doi.org/10.1145/1231047.1231077 . InfoSecCD '06 . New York, NY, USA . Association for Computing Machinery . 136–141 . 10.1145/1231047.1231077 . 978-1-59593-437-6.
  7. Web site: Beacon . . W3C Candidate Recommendation . April 13, 2017 . November 7, 2019 . Jatinder Mann; Alois Reitbauer . October 27, 2019 . https://web.archive.org/web/20191027150959/http://www.w3.org/TR/beacon/ . live .
  8. Bouguettaya. A. R. A.. Eltoweissy. M. Y.. 2003. Privacy on the Web: facts, challenges, and solutions. IEEE Security Privacy. 1. 6. 40–49. 10.1109/MSECP.2003.1253567. 1558-4046. March 29, 2021. August 25, 2021. https://web.archive.org/web/20210825173728/https://ieeexplore.ieee.org/document/1253567. live.
  9. Nielsen . Janne . 2021-04-27 . Using mixed methods to study the historical use of web beacons in web tracking . International Journal of Digital Humanities . en . 2 . 1–3 . 65–88 . 10.1007/s42803-021-00033-4 . 233416836 . 2524-7832.
  10. See Internet Engineering Task Force memorandum RFC 4021.
  11. Web site: Beacon W3C Candidate Recommendation 13 April 2017 . July 26, 2017 . March 3, 2021 . https://web.archive.org/web/20210303203846/http://www.w3.org/TR/beacon/ . live .
  12. https://nikcodes.com/2014/12/16/squeezing-the-most-into-the-new-w3c-beacon-api/ Squeezing the Most Into the New W3C Beacon API
  13. https://developer.mozilla.org/en-US/docs/Web/API/Navigator/sendBeacon Navigator.sendBeacon
  14. https://developers.google.com/web/updates/2014/10/Send-beacon-data-in-Chrome-39 Send beacon data in Chrome 39