# How did this website get my info?

**URL:** https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762
**Category:** In My Humble Opinion
**Created:** [August 7, 2004, 1:02pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762 "2004-08-07T13:02:23Z")
**Posts on this page:** 18
**Page:** 1

<div class="post-metadata">

### Author: ![kittenblue](https://avatars.discourse-cdn.com/v4/letter/k/ba8739/32.png) [@kittenblue](https://boards.straightdope.com/u/kittenblue)
#### Post date: [August 7, 2004, 1:02pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/1 "2004-08-07T13:02:23Z")

</div>

I admit to being fairly naive about many things, but something just happened that kind of scares me. I went to check out a new website I’d read about last night. They had a really good price on an item, and I wanted to find out how much the shipping charges would be before deciding to order. So I start out as if to order one item, and proceed through the ordering screens. At no time did I register, or give any personal information. I get to the shipping screen and it has filled out the “Ship To” area with my name, address and phone number, all correct. I never gave them any of this information: how did they get it?

How can I prevent a website from getting this information before I give it? I have ordered items online before from other compnaies…big companies…and they have not had any of my personal info. This is a very small company that I had never heard of until midnight last night. Is this a standard practice?

---

<div class="post-metadata">

### Author: ![Fern\_Forest](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@Fern\_Forest](https://boards.straightdope.com/u/Fern_Forest)
#### Post date: [August 7, 2004, 1:08pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/2 "2004-08-07T13:08:20Z")

</div>

I don’t think they had your information. I think your web browser automatically filled that in for you. Check out the options and you can end that esaily enough.

---

<div class="post-metadata">

### Author: ![kittenblue](https://avatars.discourse-cdn.com/v4/letter/k/ba8739/32.png) [@kittenblue](https://boards.straightdope.com/u/kittenblue)
#### Post date: [August 7, 2004, 2:58pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/3 "2004-08-07T14:58:04Z")

</div>

I checked my privacy settings, and they are set high enough that it shouldn’t have happened.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [August 7, 2004, 3:10pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/4 "2004-08-07T15:10:34Z")

</div>

First of all, with _any_ computer question, please provide info on all software and any relevant hardware in use. In this case, OS and browser including versions.

Here is one example of how this can be done if you are using insecure software (e.g., anything by Microsoft).

Let’s say you are an Amazon customer and ordered some stuff from them. All your data is stored in a cookie. Name, address, etc. When you go to EvilCom, they request your Amazon cookie, and presto, they have your data now. EvilCom can now do what they want with your data. Nice, right?

So proper cookie management is a key to avoiding this particular type of problem. Cookies should only be readable by the site that sent the cookie in the first place. All cookies with personal info should be secured, i.e., you are asked each time whether you want the site to read the cookie. “Third party” cookies should be tightly controlled. (Cookies that are sent by a site with an image on the site you’re visiting, so that the Rest Of The Universe can find out where you’ve been.)

Unfortunately, MS IE doesn’t allow you to have that kind of control. But since you are an intelligent person, you’ve never once used MS IE in your life.

When using the Net, be paranoid. There are a lot of Bad Things out there trying to steal your information, drain your accounts, etc.

---

<div class="post-metadata">

### Author: ![Larry\_Mudd](https://avatars.discourse-cdn.com/v4/letter/l/f14d63/32.png) [@Larry\_Mudd](https://boards.straightdope.com/u/Larry_Mudd)
#### Post date: [August 7, 2004, 3:38pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/5 "2004-08-07T15:38:20Z")

</div>

The only thing which can be added to **ftg** ’s succinct answer is a useful link:

> **[Opera Web Browser | Faster, Safer, Smarter | Opera](https://www.opera.com)**
>
> Get a faster, better browser. Opera's free VPN, Ad Blocker, integrated messengers and private mode help you browse securely and smoothly. Share files instantly between your desktop and mobile browsers and experience web 3.0 with a free cryptowallet.

---

<div class="post-metadata">

### Author: ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)
#### Post date: [August 7, 2004, 4:06pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/6 "2004-08-07T16:06:46Z")

</div>

> [@ftg](#):
>
> Let’s say you are an Amazon customer and ordered some stuff from them. All your data is stored in a cookie. Name, address, etc. When you go to EvilCom, they request your Amazon cookie, and presto, they have your data now. EvilCom can now do what they want with your data. Nice, right?

EvilCom cannot “request” your [amazon.com](http://amazon.com) cookie. Cookies are only sent back to the domain from which they came.

> [@](#):
>
> “Third party” cookies should be tightly controlled. (Cookies that are sent by a site with an image on the site you’re visiting, so that the Rest Of The Universe can find out where you’ve been.)

No, only the third party site which sent the cookie knows.

> [@](#):
>
> When using the Net, be paranoid. There are a lot of Bad Things out there trying to steal your information, drain your accounts, etc.

Indeed. But all the happened here was a simple browser-autofill. It’s annoying and can most likely be turned off in the preferences.

---

<div class="post-metadata">

### Author: ![ParentalAdvisory](https://avatars.discourse-cdn.com/v4/letter/p/53a042/32.png) [@ParentalAdvisory](https://boards.straightdope.com/u/ParentalAdvisory)
#### Post date: [August 7, 2004, 8:30pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/7 "2004-08-07T20:30:07Z")

</div>

Maybe the website you were using involked a PayPal type system to pay for the goods, fields for shipping would automatically be filled in by your account info with PayPal, not the site you’re using.

Anywho, help us out here. What site were you using, and what was your method of payment (PayPal, CC, etc…)?

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [August 7, 2004, 9:56pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/8 "2004-08-07T21:56:07Z")

</div>

**Freido** , this is the SDMB, we fight ignorance here. Please read up about cookies and such before making such a post.

In particular: Opera and some other browsers (but not MS IE) _explicitly_ allow you to limit whether a site can request other site’s cookies. In my version of Opera there is an explicit 3rd party/“only accept cookies set to the server itself” option. That is, you turn that off and who knows what servers are reading all of your cookies.

In an ideal world, we wouldn’t have to worry about such matters at all, but since so many web sites are designed to “work” with MS IE, and MS IE allows all sorts of crazy things, other browsers have to allow the option of such “compatibility”. Ugh.

I stand by my post 100%.

---

<div class="post-metadata">

### Author: ![kittenblue](https://avatars.discourse-cdn.com/v4/letter/k/ba8739/32.png) [@kittenblue](https://boards.straightdope.com/u/kittenblue)
#### Post date: [August 8, 2004, 12:10am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/9 "2004-08-08T00:10:30Z")

</div>

> [@ParentalAdvisory](#):
>
> Maybe the website you were using involked a PayPal type system to pay for the goods, fields for shipping would automatically be filled in by your account info with PayPal, not the site you’re using.
> 
> Anywho, help us out here. What site were you using, and what was your method of payment (PayPal, CC, etc…)?

The website I was using was [bariatriceating.com](http://bariatriceating.com), as if that matters. I hadn’t even gotten to a screen that asked how I was going to pay. I had selected one item, gone to the next screen that was shipping options, and BOOM! my info was there waiting. My browser is SBC Yahoo 3.12.

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [August 8, 2004, 12:33am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/10 "2004-08-08T00:33:45Z")

</div>

> [@kittenblue](#):
>
> I checked my privacy settings, and they are set high enough that it shouldn’t have happened.

The privacy settings should have nothing to do with it. The feature where it fills out the form for you sends no information to anybody, until you press a submit button or such. It’s just on the screen.

If it is indeed simply the browser filling out the form for you, and I think that’s what it probably was, then you have nothing to worry about.

---

<div class="post-metadata">

### Author: ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)
#### Post date: [August 8, 2004, 12:43am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/11 "2004-08-08T00:43:16Z")

</div>

> [@kittenblue](#):
>
> The website I was using was [bariatriceating.com](http://bariatriceating.com), as if that matters. I hadn’t even gotten to a screen that asked how I was going to pay. I had selected one item, gone to the next screen that was shipping options, and BOOM! my info was there waiting.

Lessee. Part of the screen was already filled in, which saved you that trouble. And by your own admission, it was correct.

And for all this convenience you are _complaining?_ :rolleyes:

It is unlikely that a tiny bitwise green man is hiding behind your screen, chuckling over the personal info he knows, but more likely all this is being done by impersonal computers who don’t give a CPU cycle about you, personally. Appreciate it. Use it. Go with the flow. Celebrate the technology.

Only partly kidding. 🙂

---

<div class="post-metadata">

### Author: ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)
#### Post date: [August 8, 2004, 3:56am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/12 "2004-08-08T03:56:16Z")

</div>

> [@friedo](#):
>
> EvilCom cannot “request” your [amazon.com](http://amazon.com) cookie. Cookies are only sent back to the domain from which they came.

[Not entirely true:](http://s1.amazon.com/exec/varzea/subst/fx/help/how-we-know.html/102-1483378-5168952#how-does-paybox-know-my-name)

> [@](#):
>
> **How does the Amazon Honor System paybox know my name?**
> 
> When you look at a Web page, the words and pictures you see actually may come from several sources. Your browser software assembles the pieces and displays them as a single page. On the Web site you were visiting, most of the content you saw was transmitted from server computers used by the site’s operator. The image made up of the paybox and your name displayed within the paybox was different–we sent it to you directly from [Amazon.com](http://Amazon.com). This allowed us to recognize you by name just like we do when you visit the [Amazon.com](http://Amazon.com) Web site. Because [Amazon.com](http://Amazon.com)’s servers transmitted the image containing a paybox and your name within the paybox directly to your browser software, the site owner never saw the paybox or your name and never received any information about you.

---

<div class="post-metadata">

### Author: ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)
#### Post date: [August 8, 2004, 6:18am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/13 "2004-08-08T06:18:18Z")

</div>

> [@ftg](#):
>
> I stand by my post 100%.

Then, you’re 100% wrong. [Why](http://www.quirksmode.org/js/cookies.html) [don’t](http://www.4pcb.com/cookies.htm) [you](http://www.aging-parents-and-elder-care.com/Pages/Cookies.html) [read](http://cookies.surferbeware.com/cookies-advanced.htm) [up](http://www.cof.orst.edu/net/software/web/browsers/netscape/cookies.php#security) [on](http://www.contacteast.com/help/cookies.asp) [cookies](http://www.cyberartisans.com/newsletter/nletter_v2n5.htm)?

There is one [exception](http://www.cookiecentral.com/bug/), but in this case the website delivering the cookie must write it so that it can be read by other websites. No standard cookie can be read by any other website, however malevolent it may be.

---

<div class="post-metadata">

### Author: ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)
#### Post date: [August 8, 2004, 6:20am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/14 "2004-08-08T06:20:30Z")

</div>

> [@Fear Itself](#):
>
> [Not entirely true:](http://s1.amazon.com/exec/varzea/subst/fx/help/how-we-know.html/102-1483378-5168952#how-does-paybox-know-my-name)

Your cite does not in any way contradict what **friedo** said. It is _still_ [Amazon.com](http://Amazon.com) reading an [amazon.com](http://amazon.com) cookie.

---

<div class="post-metadata">

### Author: ![DeadlyAccurate](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@DeadlyAccurate](https://boards.straightdope.com/u/DeadlyAccurate)
#### Post date: [August 8, 2004, 7:50am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/15 "2004-08-08T07:50:10Z")

</div>

> [@kittenblue](#):
>
> The website I was using was [bariatriceating.com](http://bariatriceating.com), as if that matters…My browser is SBC Yahoo 3.12.

Actually, I think it does. I just went out there and noticed it’s a Yahoo store. Most likely, it pulled it up from your Yahoo account or you’ve ordered from another Yahoo store in the past. I made a pretend order myself and saw that it pulled up my address, too. Since it’s a Yahoo store and you have a Yahoo internet account (I’m guessing by the fact that you use their browser), I think that’s the answer.

---

<div class="post-metadata">

### Author: ![kittenblue](https://avatars.discourse-cdn.com/v4/letter/k/ba8739/32.png) [@kittenblue](https://boards.straightdope.com/u/kittenblue)
#### Post date: [August 8, 2004, 1:36pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/16 "2004-08-08T13:36:49Z")

</div>

Thanks **DeadlyAccurate**. That answer makes sense to me. And thanks for the reassurance, **Revtim**. And **musicat** , you know what bugged me the most? When it filled in the form it didn’t capitalize the appropriate words, like my name, city, street: it was all lower case. I get a little anal when I fill in forms, and I want them to look right!

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [August 8, 2004, 1:49pm UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/17 "2004-08-08T13:49:48Z")

</div>

That’s odd that it’s not capitalizing, especially if you are anal about yourself. Since it got its data from a form you filled out, it should be the way you fill them out.

I use Mozilla, so I’m less familiar with IE. Any other IE users ever see it where it loses capitalizations on the auto-fill?

---

<div class="post-metadata">

### Author: ![Kat](https://avatars.discourse-cdn.com/v4/letter/k/b19c9b/32.png) [@Kat](https://boards.straightdope.com/u/Kat)
#### Post date: [August 9, 2004, 1:22am UTC](https://boards.straightdope.com/t/how-did-this-website-get-my-info/258762/18 "2004-08-09T01:22:47Z")

</div>

Never. However, I’ve also never seen it autofill a form until I’ve started entering the info. The autofill on my IE browser will create a dropdown menu under or above the data field I’m filling out with any words/phrases previously entered on forms that start with the letter(s) I’ve already entered. Once I click on the word/phrase that should be used, it populates the field with that word/phrase, using the casing that was used previously, no matter what casing I have it entered in on the current form. (e.g. if I enter sTR and then choose Straight Dope from the dropdown list, it populates as Straight Dope, not sTRaight Dope.)
