deferred final security check, could leak personal data sends data to analytics providers such as Google’s DoubleClick and Pingdom. As Simo reviewed the Web requests being made as part of his movement through the site, he found requests sent to these two providers that included his visit to the password reset pageā€”and all of the user data that was generated by the page. That runs counter to the privacy policy on, which states that no personally identifiable information will be collected by site analytics tools. This is the same sort of behavior that the Federal Trade Commission has fined social networks such as Facebook and MySpace for in the past.

via deferred final security check, could leak personal data | Ars Technica.