Evaluating Website Data Leaks through Spam Collection on Honeypots
Oghenerukevwe Elohor Oyinloye, Carol Fung · 2024
Nowadays, people rely heavily on online services in their daily lives such as communication, education, shopping, and entertainment.While online services offer convenience in daily living, users often receive a large number of spams as a result.While previous studies have linked spam receipt primarily to user behavior, this research proposes that spam can serve as a forensic indicator of data leaks by websites.To test our hypothesis, we conducted an experiment to deploy 148 honeypots across 370 websites spanning 12 communities.We monitored and audited the spams received by our honeypots for 47 weeks and analyzed their nature, pattern and origin.The results reveal that some legitimate websites leak user data despite having privacy policy statements.The findings also highlight that some websites automatically enroll users in newsletters or mailing lists without asking consent during the sign-up.This issue arises from conflating privacy policies with spam subscription and third party share agreements.To address these issues we suggest that regulators enforce websites to separate subscription agreement from privacy policy statements, and direct consent for third party share be requested at sign up.Also, websites should evaluate third party chain to ensure user data protection.