Research


MOST RECENT POST

ComScore Cross-Site Tracker Found in PBSKIDS.org 

Updated 1/22/24  We’re happy to report that the ScorecardResearch tracker has been removed from the PBSKids.org website. We appreciate PBS removing this cross-site tracker.   Updated 11/29/23  As a non-profit, independent product safety testing organization, Internet...

read more
All Research Posts
Another School District Hacked

Another School District Hacked

Two of the districts covered in our 2022 benchmark find themselves victims of recent data breaches at the hands of the same entity,...

What is Respectful Use of Location Information? New Me2BA Research Published

What is Respectful Use of Location Information? New Me2BA Research Published

As we’ve been performing independent product audits over the past year and a half, we received some push-back on our passing criteria related to the automatic translation of IP address to geographic location. Vendors felt that automatically calculating the user’s geographical location was, in fact, a benefit. However, in our specification, that behavior will receive a failing score. At an impasse, we decided to conduct some validation testing with Me-s.

Dangling Domain From SDK Installed in 150+ Apple Apps Putting Kids, Families and Crypto Traders at Risk

Dangling Domain From SDK Installed in 150+ Apple Apps Putting Kids, Families and Crypto Traders at Risk

Over the past month, the Me2B Alliance product testing team has been investigating something we refer to as “dangling domains” and the risks they pose to people, especially children and families.

A “dangling domain” refers to any URL/domain previously owned by a legitimate organization or business, but which has been either abandoned due to the business shutting down, or due to a mistake where the organization or business forgets to renew their own domain.

Flash Guide #10: Data Flow & the Invisible Parallel Dataverse

Flash Guide #10: Data Flow & the Invisible Parallel Dataverse

The reality of online data flows is nothing like what we expect. Our personal data flows do not start light and increase with time and trust. Instead, a firehose of personal information is released – and shared with a host of unseen third parties – as soon as we open an app or website. Me2BA’s Respectful Tech Specification V.1 is largely focused on testing for these invisible parallel dataverse data flows.

Flash Guide #8: Digital Me2B Commitments & Deals

Flash Guide #8: Digital Me2B Commitments & Deals

Over the course of the digital Me2B Lifecycle, individual “Me-s” (Data Subjects) will have the choice of deepening the relationship through a series of Me2B Commitments with the online vendor, “B” (Data Controller). This guide provides examples of common Commitments and Deals, and shows how they map to the stages of a Me2B Lifecycle. It also reflects social norms for being anonymous, recognized, or known at each stage.