
TRUSTe 1997-2007
Established to build confidence in the emerging Internet by protecting individual privacy, TRUSTe is the pre-eminent trustmark on the Internet, recognizing responsible privacy practices among its thousands of sealholders. Its new programs are addressing real threats with pragmatic solutions to build consumer trust. Please join us as we celebrate the collaborative efforts of TRUSTe, our sealholders, supporters and partners, to advance privacy and trust for the networked world.
Join us for TRUSTe’s 10th Anniversary Gala Celebration
When: October 22, 2007 6:30 PM reception, 8:00 PM dinner
Where: The de Young Museum in Golden Gate Park, San Francisco, CA (Map/Directions)
Transportation will be provided from the Westin St. Francis and the deYoung.
What: Networking, reunion photos, a commemorative video and thought-provoking speakers.
Entertainment: Enjoy a performance by Moon Alice to cap off the night, a band founded by Roger McNamee an early TRUSTe supporter. Moonalice is a far flung tribe of musicians who all want to play bass. The tribe - or band, as it is known in Moonalice culture - plays an intoxicating brew of roots, blues, psychedelia, and strange but kind folk.
Networking: Join the TRUSTe group on Facebook that we encourage you to join. Get in touch with early founders, supporters and current TRUSTe employees. Just search TRUSTe under “Groups.”
Our Co-Chairs:
Lori Fena, TRUSTe Founder
John Berard, Zeno Group
Fran Maier, TRUSTe
Thanks to our Sponsors & Table Hosts:
Joe Alhadeff, Oracle
Peter Cullen, Microsoft
Reed Freeman, Kelley Drye Collier Shannon
Jon Hart, Dow Lohnes
Leslie Harris, CDT
Tony Hadley, Experian
Trevor Hughes, IAPP
Parry Kamel, Maxamine
Chris Kelly, Facebook
Barb Lawler, Intuit
Tom McNeil, Apple
Jules Polonetsky, AOL
Larry Ponemon, Ponemon Institute
Richard Purcell, Corporate Privacy Group
Susan Scott, former TRUSTe Executive Director
Scott Shipman, eBay
Billy Spears, Dell
Dave Steer, PayPal
Ralph Terkowitz, ABS Capital
Anne Toth, Yahoo!
Brian Tretick, Ernst & Young
Christine Varney, Hogan & Hartson
Don Whiteside, Intel
More than 300 friends and supporters have already registered to attend, so make sure to register soon. Availability is limited.
September 25th, 2007
As many of you may know, the Federal Trade Commission is holding a Town Hall Meeting on Thursday and Friday, November 1st and 2nd, to address consumer protection issues raised by the practice of behavioral targeting. BT is a prevalent marketing strategy these days, one which several TRUSTe sealholders practice, and we would like to encourage you to participate in Esther Dyson’s Cookie Crumble video contest, the winners of which will be featured during Ms. Dyson’s 90-minute presentation at the Town Hall. Her complete call for participation can be viewed here but the general idea of it is this: create a video that explains how cookies work and then post it on YouTube. The videos with the most views on YouTube will be featured during the presentation, and fame and glory will be yours. The story line (some or all should be included):
- How cookies work (text snippets stored in the user’s browser, which are placed by a server (an ad server or the visited website’s server) and then submitted to the server when the user revisits the cookie-placing server or ad network.
- Website cookies vs. ad network or third-party or tracking cookies
- What data cookies contain in their pure form
- How other data can be *associated* with anonymous cookie data
- How to delete cookies
- What cookies are used for: ease of sign-in, targeting ads, ad frequency capping, monitoring various kinds of user behavior (individually or in the aggregate)
- How cookies can be misused
You may be as creative as you like, and you can be as honest as you like. There is no set deadline, but the sooner the better so you can get as many views as possible in the time between now and the selection. TRUSTe will be happy to assist in promoting your videos using outlets at our disposal. Consumer education is one of the major stumbling blocks of protecting privacy in behavioral targeting, and this is a clever way to bring your ideas and concerns to the public forum. Please feel free to contact edyson@boxbe.com or post your comments on the contest page.
for more information about the contest. We appreciate your contribution!
September 24th, 2007
One of the goals of the Trusted Download Program (TDP) is to change software behavior in the interest of protecting the consumer. Recently, Coupons, Inc., a TRUSTe Web Privacy Seal sealholder and a Trusted Download Program participant was found to leave behind inappropriately-named files after uninstallation, without any disclosure to the consumer. The issue came to our attention when a consumer, using our Watchdog dispute resolution system, submitted an enquiry. TRUSTe immediately investigated and concluded that while the method and lack of disclosure was problematic, Coupons had a legitimate reason for leaving the files behind: an anti-fraud measure.
TRUSTe required Coupons to modify their End User License Agreement (EULA) to provide proper notice that files would be left behind after uninstall. Coupons has worked with TRUSTe in good faith, and in fact a portion of these changes was already in progress. Coupons also agreed to rename the files in question. Finally, the company is planning a software upgrade that will remove old files left behind by previous software versions. TRUSTe is requiring that these changes be completed within 90 days.
This is a demonstration of the benefit of the TDP program in action. A problem was found, investigated, confirmed, and corrected. Behavior of the application is improved and the consumer is protected.
Posted by: Colin O’Malley
September 20th, 2007
The Trusted Download white list is designed to bring companies and software publishers into compliance with best practices - in order to preempt privacy violations, but also in response to privacy violations. TRUSTe provides business incentives to companies that are willing to change their behavior to meet higher standards for consumer privacy. When companies violate our program requirements we can suspend or terminate them as circumstances warrant. In cases where companies are uncooperative or blatantly flaunting compliance or enforcement actions, we reserve the right to report to regulatory and or law enforcement authorities. This is considered a last resort; we consider it our mission to rehabilitate privacy practices for the long-term good of industry and consumers alike.
It is unfortunate that certain headlines have got the focus of TRUSTe’s recent compliance action removing RelevantKnowledge from our TDP white list wrong. comScore and their (former) rogue distributor are at fault in this matter. Once TRUSTe replicated reported incidents of violations of our program requirements, our enforcement action was swift and severe. comScore was removed from our white list for its violations. TRUSTe has outlined on our blog some of the required actions that will strengthen comScore’s distribution accountability. TRUSTe does not plan to reinstate RelevantKnowledge until comScore has implemented these actions to our satisfaction. TRUSTe’s course of action has been transparent, independent and consistent with our mission. You can read a more detailed description here.
July 26th, 2007
Recent news about Microsoft, Yahoo! and Ask changing their privacy practices regarding the duration they will keep search queries is a welcome addition to the debate around search engines and behavioral targeting. Search engine data retention is a complicated and thorny issue, with counterbalancing agendas on both sides of the question. Law enforcement needs for data to investigate crimes is offset by the risk to individual privacy and identity where large amounts of data about the behavior of an individual is retained and available for data mining or potentially exposed to unauthorized acquisition. Businesses have a need to keep records of their business, and individuals have a need to control information about their activities on the Web.
For the most part, privacy is best served where the queries are either anonymous, or are tied to very little identifiable data. This is the direction that Microsoft and Ask have both taken. Further, the idea of developing industry best practices and standards around the appropriate retention and use of search data is worthwhile. TRUSTe has long advocated industry self-regulation as the best way to address new and emerging business models and technologies which may have privacy implications. This movement by Microsoft, Yahoo! and Ask is an excellent opportunity for the industry, in conjunction with privacy experts, to demonstrate the benefits of such industry self-regulation.
- John Tomaszewski
July 23rd, 2007
Earlier this month, after notification by several sources, TRUSTe undertook an investigation of a distributor installing comScore’s RelevantKnowledge on consumer machines through a security exploit. TRUSTe immediately launched an investigation, and with the help of Eric Howes and the team at SunBelt Software, and with the cooperation of comScore, was able to locate the exploit.
Understanding that installation via exploit is a prohibited activity in the Trusted Download Program, TRUSTe removed RelevantKnowledge from the TDP white list for three months. This action reflects the seriousness of the offense perpetuated by a distributor within the RelevantKnowledge distribution network, and provides comScore with time to implement and demonstrate the effectiveness of further controls
A Rogue Distributor Exploits Security Flaws:
The RelevantKnowledge application was observed being installed via a security exploit amongst several other applications. The following describes the series of events observed:
- The user visited an unauthorized distribution web site.
- A series of hidden frames were loaded containing links to dozens of other websites, including sites containing code designed to test and trigger security exploits on the user’s machine.
- by way of these exploits, a cascade of maliciously installed software was downloaded/installed onto the user’s machine without any form of consent. This software included RelevantKnowledge.
The application which ultimately installed RelevantKnowledge contained a code which identified it as belonging to an authorized comScore distribution partner. This distributor was authorized to offer RelevantKnowledge as part of a software bundle available at a website that had been reviewed and tested by both TRUSTe and comScore, and confirmed to obtain positive user consent. Unfortunately, it appears that the distributor ‘went rogue’ by facilitating the installation of RelevantKnowledge on one or more unauthorized distribution sites, and by using unauthorized installers which circumvented consent mechanisms required by comScore and by the TDP Program Requirements.
While the course of events described contains several potential violations of TDP Program Requirements, it should be noted that the observed activity on the malicious sites was not directly tied to actions by comScore, and took place on web sites that were not controlled or associated with comScore. The malicious activity observed took advantage of exploits in the RelevantKnowledge distribution model in order to make it appear to comScore that a consensual installation had taken place.
comScore Took Decisive Action:
As soon as it was informed of the offense, comScore took immediate action which it promptly communicated to TRUSTe. Within 24 hours, comScore:
- Terminated the distributor.
- Disabled all installations associated with the distributor.
- Activated a self-delete switch in the RelevantKnowledge software, that will automatically uninstall the software at the next reboot opportunity.
- Began developing changes to its methods of distributor monitoring and control to correct weaknesses that allowed this exploit to take place.
In order to achieve tighter security in its distribution process, comScore implemented additional verification measures, including a review of distribution urls to check for authorized distribution points and a validation check for an authorized distribution installer “footprint”.
Re-Attaining Trusted Download Status:
TRUSTe and comScore will continue to work together through this period, and comScore will attempt to re-emerge with a substantially more robust anti-fraud systems. Over the next 90 days, TRUSTe is requiring comScore to roll out additional changes, and comScore has agreed to make whatever changes might be necessary. These changes will, at a minimum, include:
- Termination of install unless the installation was initiated from a verified source (by url or installer).
- Termination of the install in the event that it is detected that the install is triggered via a security exploit.
- Move to a consent model directly controlled by comScore.
- Improve consumer feedback/complaint channel.
- Improve auditing process.
comScore will be subject to additional TRUSTe monitoring.
Community Cooperation on Standards and Policing
Without the cooperation of the anti-spyware community, the damage inflicted on users by this rogue affiliate could have been much greater. It is an admittedly difficult task to monitor the behavior of each and every distributor and affiliate by any single entity. Vigilance, cooperation, and mutual assistance by the entire online community — anti-spyware companies, third-party certification entities, government enforcement, consumer-complaint mechanisms, and self-policing by “good players” all have roles to play in making the internet a safer place for everyone.
Posted by Colin O’Malley
July 20th, 2007
You may have seen the TRUSTe Privacy Seal on many of your favorite Web sites such as Apple, eBay, Facebook, Monster.com and The New York Times. This ubiquitous seal marks 2,400+ Web sites that are dedicated to protecting your privacy. On June 11, TRUSTe will commemorate its 10th anniversary by introducing a modernized version of its former logo, retaining the TRUSTe name and its familiar green and black colors.

TRUSTe’s Web Privacy Seal means that a Web site keeps its promises to protect your privacy, and allows you to have a choice about the use and sharing of your personal information.
Subjecting Web sites to tough standards and rigorous testing since 1997, TRUSTe has been:
1) Making sure that Web sites treat your identity and email address with respect and transparency. Any Web site with the TRUSTe seal will give you the right to access your information, delete your information, and give you a choice to keep it private. Not every Web site can meet TRUSTe’s tough standards. The privacy statement and TRUSTe approval can be validated by clicking on the seal or visiting the TRUSTe Web site.
2) Monitoring any changes to a sealholder’s Web site or promises. The TRUSTe seal on a Web site means that the site can be trusted to keep the promises it makes in its privacy statement. TRUSTe regularly monitors Web sites’ adherence to their privacy statements and has the power to enforce compliance with its program. In 2006, TRUSTe conducted 24 investigations of sealholders and revoked the seal in a number of those cases.
3) Resolving your individual privacy-related complaints. If you believe your privacy has been violated on a Web site displaying the TRUSTe seal, contact TRUSTe directly by registering a complaint on TRUSTe’s Watchdog complaint form at http://www.truste.org/watchdog. This is a unique service to help you guard and protect your individual personal information.
Look for the TRUSTe seal and ask your favorite Web sites to make sure they are protecting your privacy by joining TRUSTe.
For more information on TRUSTe and its new look, visit www.truste.org.
June 11th, 2007
TRUSTe has successfully certified twelve software applications in the Trusted Download Program Beta to date, and a dozen more are in the process of certification. Over the past few months the focus of the Beta program has moved from certifying software to monitoring the distribution networks of certified software.
As applications enter and leave the whitelist for either voluntarily or through investigation and compliance actions, TRUSTe will notate the additions and departures through the TRUSTe blog to provide additional detail to interested parties. This is the first notice on withdrawal of a software application from the whitelist.
Vomba 1.2.0.1 is no longer listed in the whitelist and its distribution and technical operation are no longer monitored by TRUSTe.
TRUSTe certified the software application Vomba 1.2.0.1 and placed the application on the whitelist in provisional status in February. In order for any covered advertising or covered tracking application to maintain certification status they must also certify their distribution partners and subject those partners to TRUSTe monitoring on an ongoing basis.
Vomba began rolling out its distribution network after certification, and always communicated in good faith with TRUSTe during the planning and initial deployment phases of the network. Unfortunately, as Vomba considered scaling their distribution network, they decided that the cost associated with maintaining that network within the Trusted Download Program Beta were not consistent with their financial objectives.Vomba was additionally exploring new and creative distribution methods, particularly in the peer-to-peer market. Vomba would have been required to discontinue this approach.
TRUSTe was actively engaged in an exploration into the level of separation between Vomba and another entity under the corporate umbrella. We ultimately did not reach a conclusion on this matter, but were in the process of requiring additional process and further certifications of Vomba’s corporate neighbors, given the lack of clarity on boundaries.
To be clear, TRUSTe did not embark on an enforcement process with Vomba. Vomba has made a business decision that they no longer want to make the financial commitment to maintain certification, with the cost of their growing distribution network playing a primary role.
Posted by: Colin O’Malley
June 11th, 2007
A study conducted by researchers at Carnegie Mellon University Usable Privacy and Security Labs found that consumers choosing to purchase among retailers providing easily accessible privacy information, were willing to pay a premium on websites with more protective privacy practices. The search engine designed for the experiment offered a five-point scale that could match P3P machine-readable privacy statements to the test subject’s privacy preferences for using information. It has long been thought that internet shoppers considered privacy as an afterthought in their purchasing decisions. However, TRUSTe sealholders that have been testing the impact of privacy seals on transactions have known all along that making privacy accessible, reassuring and protective, can build trust and increase engagement. This study offers more evidence that good privacy = good business.
Read the full paper (.pdf)
June 7th, 2007
No company has been certified so far in the Trusted Download Program without making changes to their software, particularly in the areas of notice and control.
WhenU Case Study on Primary Notice
WhenU’s primary notice prior to certification was already above the then industry standards, especially in how it described key software functionality, and provided prominent notice of the types of advertising that would be displayed. WhenU used direct and clear terminology, such as: “ads slide or pop up in front or behind the browser…”
Affirmative Consent
The Trusted Download Program does not allow pre-selected option consent for advertising or tracking software. The intent is to ensure that users do not end up with advertising or tracking software on their computer as a result of moving through consent screens by hitting enter repeatedly, without taking the affirmative action of selecting a button to download when presented with material information.
WhenU Primary Notice Before 
TRUSTe reviewed all instances of WhenU Primary Notices. A number of associated Primary Notices were either opt-out or the consent option (“Next” or “I Accept”) was highlighted by default.
TRUSTe guidance during the certification process required WhenU to provide an affirmative consent for Save/SaveNow, and for the acceptance and decline options to be featured with equal promininence universally throughout the WhenU distribution network. WhenU understood and agreed with our requirements, and acted quickly to make the required changes.
TRUSTe’s subsequent review of Save/SaveNow Primary Consent screens were verified to offer the required consent mechanism.
Timing of Ads
TRUSTe Guidance during the certification process also advised that advertising software is required to give a level of specificity on when the advertising will be displayed. For example, will ads appear when the user is browsing the internet or at any time? In this case WhenU added the disclosure that advertising would be served “While you are browsing online, our software will show you pop-up advertisements…related to Web-browsing activity.” This provides sufficient specificity to set user expectations and equips the user to make an informed decision about the value exchange they are agreeing to.
WhenU Primary Notice After

Posted by: Colin O’Malley, Director of Product Development
February 15th, 2007
Previous Posts