- Widespread shortcomings in cyber security: Many services accept weak passwords, do not offer multi-factor authentication and provide insufficient information about phishing and login incidents.
- Systematic data protection violations in tracking: All websites examined use third-party tracking, the majority provide insufficient information, and valid consents are largely missing.
On February 5, 2019, the Bavarian State Office for Data Protection Supervision (BayLDA) published the results of its audit of 20 websites on the criteria “cybersecurity” and of 40 websites on the criteria “tracking”. published.
Cybersecurity
The study examined 20 websites from the categories of streaming/video portals, e‑mail services, electronics stores, photo services, health and cosmetics, furniture, fashion, price comparison and ticket sales, and social networks. The BayLDA came to the following conclusion, among others:
- 75% of the services offer insufficient explanations on how to choose a strong password; furthermore, only 50% of the services inform their users about a password change via e‑mail;
- 9 out of 20 services require a password with less than 8 characters (BayLDA recommends a minimum length of 12 characters);
- all services accept weak passwords (e.g.:123456, abcdefgh or P@assword) and weak passwords are often mistakenly displayed as “secure” or “strong”;
- only 25% of the services require email confirmation of a registration on the website and 80% of the services do not offer multi-factor login (e.g., login with password and SMS code); and
- no website informs users sufficiently about phishing; only 1 website informs users about failed logins or logins via foreign devices, and only 6 out of 20 websites offer support for security issues and hacking.
Tracking
The study examined 40 websites from the categories of online stores, sports, insurance & banking, media, cars & electronics, home & living, and other. The BayLDA came to the following conclusion, among others:
- all websites include third-party tracking tools;
- 75% of the websites do not inform at all or only insufficiently about the use of tracking tools;
- 20% of the websites do not obtain consent for the use of cookies; the remaining 80% obtain consent that does not comply with data protection requirements, so that No consent effective is; and
- only 1 website allows users to effectively choose whether their data can be processed by tracking tools.
The BayLDA has expressed its intention to remedy the deficiencies and to consider initiating fine proceedings.