disconnectme / disconnect-tracking-protection

Canonical repository for the Disconnect services file
Other
647 stars 221 forks source link

Tinypass breaks logins and accounts #351

Closed whatisjasongoldstein closed 4 months ago

whatisjasongoldstein commented 4 months ago

Domain(s) to review. Separate them by comma.

tinypass.com

Rationale for removing, adding, or recategorizing.

This is a full login and accounts system

Where domain(s) observed. Separate them by comma.

www.scientificamerican.com

Additional notes

Tinypass (piano.io) sells a DMP but it's primary function is account login/management + paywalls. Having it on this list at the domain level means Firefox Incognito users can't sign in to their accounts.

Can you please either remove it or find a way to narrowly target the tracking offerings?

Thanks!

Jason Goldstein Director of Engineering, Scientific American

disconnectme commented 4 months ago

Thank you for bringing this to our attention. Our technical and policy review determined that tinypass.com meets our definition of Tracking (See https://disconnect.me/trackerprotection) and that this domain is properly classified as a Tracker.

Our technical review revealed Request URLs from tinypass.com’s subdomains are present on thousands of 3P sites. We are seeing what appear to be tracking requests (containing information like “experience” and “page_view_ID”) from subdomains including but not limited to the following:

In regard to the specific login breakage, we were able to replicate this issue, and we are looking into moving the tracking domain associated with the login functionality into our Content category, which could solve the issue. This review could be expedited by communicating directly with a contact at TinyPass/Piano, if you would like to put us in touch. Our contact email is support@disconnect.me.