1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

McAfee uses web beacons that can be used to track and serve advertising to users

Discussion in 'General Malware And Security' started by Rich M, Mar 18, 2016.

  1. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    McAfee uses web beacons that can be used to track and serve advertising to users
    A test of seven OEM laptops running Windows has shown consistent privacy and security issues, including an interesting revelation that the McAfee Antivirus running on six of them is using web beacons to serve ads and possibly even track users online.

    06ed137fb8062bb0a392b7031c4769bb.png

    The seven laptops – Lenovo Flex 3, Lenovo G50-80 (UK version), HP Envy, HP Stream x360 (Microsoft Signature Edition), HP Stream (UK version), Acer Aspire F15 (UK version), and Dell Inspiron 14 (Canada version) – have been tested by the security research team of Duo Security by simply sniffing the traffic sent from and to them once they have been taken out of the box, plugged in, and connected to a network.

    “The focus of our research was on home systems accessing multiple networks, including public Wi-Fi and the corporate environment. However, this research also impacts corporate enterprises looking to improve both security and privacy settings for Windows 8.1 and Windows 10,” they explained.

    “Within the first few packets on all seven laptops, there were issues. It took awhile to figure them out, as much of the traffic was encrypted and one had to go by server hostname or calling program name, or by reverse-engineering the calling code to find out what was going on,” they pointed out.

    Findings
    Among the other things they found were:

    A pre-installed, trusted eDellRoot root CA certificate with an associated private key, as well as an Atheros Authenticode signing certificate shipped with the Bluetooth software on the Dell Inspiron 14. (This was publicly revealed at the same time that the existence of the eDellRoot certificate on all desktop and laptops shipped by Dell since August 2015 was unearthed by several security researchers and journalists).

    There are many features in Windows 8 and 10 that collect data about the user and laptop, and many privacy settings. “Many of the applications and services connected to these privacy settings start phoning home as soon as the laptop is connected to a network, before you are logged in. For anyone concerned about privacy, it would be ideal to have a chance to opt out – particularly when it’s not obvious that the collection and uploading of data is even happening,” the researchers pointed out.

    Unfortunately, changing privacy settings is not as straightforward as one would hope. In some cases, the user would have to disable a service or create/adjust registry keys – and that’s not something that most users know how to do.

    After Patch Tuesday updates, many of the privacy settings are reset to their default settings, and the user doesn’t get notified of this.

    Default laptop settings (e.g. open ports) and protocols make it easy for an attacker to sniff and redirect the laptop user’s traffic when the device is connected to insecure, open Wi-Fi networks.

    McAfee is using web beacons that can be used to track and serve advertising to users. “In our opinion, this is the only purpose these web bugs serve,” the researchers noted, but pointed out that trusting third party sites and allowing them to load content it not a good security practice.

    The only good news is that all the aforementioned traffic to Microsoft or OEM vendor servers is encrypted by default.

    Mitigation
    “Mitigation [for all of this] is to turn off all of the privacy settings, make some registry settings adjustments, and turn off some services. And as stated, redo everything each time you patch,” the researchers advised. Removing McAfee, setting up Windows Defender, and adjusting firewalls to stop the transmission of data is also a good idea.

    df9172ebe77c265625078db513997b95.jpg

    More details about Duo Labs’ research and instructions on how to perform those mitigations, as well as to configure advanced security settings, can be found in this technical whitepaper.
    https://www.helpnetsecurity.com/2016/03/17/mcafee-web-beacons/
     
  2. IceMan37

    IceMan37 Banned

    Joined:
    Apr 24, 2014
    Messages:
    1,079
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    MSI Z87M-G43
    CPU:
    I5 4690k @ 4.6
    Memory:
    16GB Hyper X 1866
    Hard Drive:
    1TB WD_Blue | 240Gb Sandosk SSD
    Graphics Card:
    eVGA GTX 970 FTW
    Power Supply:
    750W Tt
    Our company uses McAfee and I hate it. It''s a terrible resource hog that at times nearly stops critical functions. An I5 3570 HP workstation will have nearly 95% CPU usage during scans. This news is not good about McAfee getting meta data and using it for ads. So if they will sell out - who won't? I do not like this at all.
     
  3. Rich M

    Rich M Guest

    Joined:
    Dec 24, 2013
    Messages:
    4,580
    Location:
    NE Pa USA
    Operating System:
    Windows 7
    Computer Brand or Motherboard:
    MSI Z97 PC Mate LGA 1150 Intel Z97
    CPU:
    Intel i7 4790K 4.0Ghz
    Memory:
    Corsair Vengeance 16GB (2x8GB) DDR3 2133
    Hard Drive:
    Crucial 256 Gb SSD+ WD Raptor 300 Gb Sata III
    Graphics Card:
    Radeon R9 280 2GB HDMI
    Power Supply:
    Seasonic 750 watt
    That is why I posted it I am a little perplexed by it too. The software is probably the poorest out there for protection and
    terrible system drag. I cannot understand for the life of me why Intel bought them. John MacAfee who is a lunatic but been out of the company for years an years has been behind
    more internet scandals than almost anyone in Silicon Valley.
     

Share This Page