Take-Aways (AI)
  • Wide­spread short­co­mings in cyber secu­ri­ty: Many ser­vices accept weak pass­words, do not offer mul­ti-fac­tor authen­ti­ca­ti­on and pro­vi­de insuf­fi­ci­ent infor­ma­ti­on about phis­hing and log­in incidents.
  • Syste­ma­tic data pro­tec­tion vio­la­ti­ons in track­ing: All web­sites exami­ned use third-par­ty track­ing, the majo­ri­ty pro­vi­de insuf­fi­ci­ent infor­ma­ti­on, and valid cons­ents are lar­ge­ly missing.

On Febru­ary 5, 2019, the Bava­ri­an Sta­te Office for Data Pro­tec­tion Super­vi­si­on (BayL­DA) published the results of its audit of 20 web­sites on the cri­te­ria “cyber­se­cu­ri­ty” and of 40 web­sites on the cri­te­ria “track­ing”. published.

Cyber­se­cu­ri­ty

The stu­dy exami­ned 20 web­sites from the cate­go­ries of streaming/video por­tals, e‑mail ser­vices, elec­tro­nics stores, pho­to ser­vices, health and cos­me­tics, fur­ni­tu­re, fashion, pri­ce com­pa­ri­son and ticket sales, and social net­works. The BayL­DA came to the fol­lo­wing con­clu­si­on, among others:

  • 75% of the ser­vices offer insuf­fi­ci­ent expl­ana­ti­ons on how to choo­se a strong pass­word; fur­ther­mo­re, only 50% of the ser­vices inform their users about a pass­word chan­ge via e‑mail;
  • 9 out of 20 ser­vices requi­re a pass­word with less than 8 cha­rac­ters (BayL­DA recom­mends a mini­mum length of 12 characters);
  • all ser­vices accept weak pass­words (e.g.:123456, abcdef­gh or P@assword) and weak pass­words are often mista­ken­ly dis­play­ed as “secu­re” or “strong”;
  • only 25% of the ser­vices requi­re email con­fir­ma­ti­on of a regi­stra­ti­on on the web­site and 80% of the ser­vices do not offer mul­ti-fac­tor log­in (e.g., log­in with pass­word and SMS code); and
  • no web­site informs users suf­fi­ci­ent­ly about phis­hing; only 1 web­site informs users about fai­led log­ins or log­ins via for­eign devices, and only 6 out of 20 web­sites offer sup­port for secu­ri­ty issues and hacking.

Track­ing

The stu­dy exami­ned 40 web­sites from the cate­go­ries of online stores, sports, insu­rance & ban­king, media, cars & elec­tro­nics, home & living, and other. The BayL­DA came to the fol­lo­wing con­clu­si­on, among others:

  • all web­sites include third-par­ty track­ing tools;
  • 75% of the web­sites do not inform at all or only insuf­fi­ci­ent­ly about the use of track­ing tools;
  • 20% of the web­sites do not obtain con­sent for the use of coo­kies; the remai­ning 80% obtain con­sent that does not com­ply with data pro­tec­tion requi­re­ments, so that No con­sent effec­ti­ve is; and
  • only 1 web­site allo­ws users to effec­tively choo­se whe­ther their data can be pro­ce­s­sed by track­ing tools.

The BayL­DA has expres­sed its inten­ti­on to reme­dy the defi­ci­en­ci­es and to con­sider initia­ting fine proceedings.