back to article Broadband big boys waiting on data pimping

Phorm, the advertising company that wants to pay your ISP to hand over information on which websites you visit, has convinced the UK's three largest providers to trust it, but regulators and the rest of the industry are less impressed. Phorm's deals already mean it has already snagged more than ten million streams of UK users …

COMMENTS

This topic is closed for new posts.
  1. Anonymous Coward
    Go

    @ Sam - not just DNS, no easy fix

    This is not just a DNS hack. They are indeed taking a copy of every page via a transparent proxy and analysing the text - you can see a description on their website www.phorm.com including, for example, how an advertiser can set the search criteria to select the targeted ad. Of course this will increase the time you have to wait for your webpages but then again you will 'benefit' from all those lover-ly targeted adds. Are YOU satisfied with the size...etc etc.

  2. Anonymous Coward
    Anonymous Coward

    Have spoken to C4 News....

    ...and am trying to get this out into the mainstream media.

    To: XXXXXX@itn.co.uk ; XXXXXX@itn.co.uk ; XXXXXX@itn.co.uk

    Sent: Friday, February 29, 2008 1:08 PM

    Subject: New Story - BT, Virgin Media, TalkTalk sell private browsing history to Phorm

    Hi,

    I have spoken to Will on the Newsdesk about raising the profile of this story and he suggested contacting yourselves. The basic story is that BT, Virgin Media and TalkTalk have entered into a deal with a company called Phorm to sell private browsing history to an advertising broker (Phorm). I am personally a customer of VM and am now cancelling my contract as I feel this is a massive invasion of privacy, goes against the DPA and RIPA and is possibly against the law. Phorm themselves are an extremely dubious company, have their servers hosted in China, and have possible links with the Russian Security Services. They also have been previously associated with releasing Spyware into the wild.

    I am technically competent enough to recognize the implications of what VM have done in making a deal with Phorm and so am voting with my cash, as it were, however I do feel that the average man in the street won't be and so am asking if you would investigate this further and bring it into the public domain.

    Further information is here...

    http://www.theregister.co.uk/2008/02/29/phorm_broadband_isp_targets/

    http://www.theregister.co.uk/2008/02/25/phorm_isp_advertising/

    http://www.f-secure.com/sw-desc/apropos.shtml

    Regards,

    Anthony

  3. Alexander Hanff
    Stop

    First of all

    Zen??? You are all being very bloody naive if you think just because Zen say something that it is actually true (or any other company for that matter). Zen made very bold public statements about FuPs, Throttling and Bandwidth Caps for the 4 years I was with them claiming it would -never- happen with Zen, then ADSLMax came along and Zen introduced what has to be seen as one of -the- worst FuP/Throttling/Cap systems ever witnessed on the internet where they cut you off if you got 1byte over your cap and hold your connection ransom to expensive PAYG top up tariffs. If you don't want to pay their ransom, you get no internet, period. Whereas most sane ISPs simple throttle your connection down to a slower speed until you either pay them more money or your next billing cycle starts. So Trust Zen? No thanks after 4 years of being a fan boy only to have that trust destroyed by their lies I would rather remove my testicles with toe nail clippers.

    Secondly...

    Phorm clearly -has- to at least use IP data in order to deliver their ads; how quickly the world seems to forget that in the last 2 weeks (pretty sure it was just in the last 2 weeks) the EU have categorically stated that IPs are personally identifiable and must not be used to track. The Register itself ran an article on the EUs attack on search engines for retaining search data against IP for exactly the same thing Phorm are trying to do (more appropriately target ads). This move by the 3 ISPs to use Phorm is quite simply illegal, there are no ifs or buts, it breaks a number of laws.

    1: RIPA - Yes this breaks RIPA, an Act that normally breaks us is for once proving useful.

    2: DPA - Yes this contravenes DPA which states that data collected by a company (as data controllers) is only permitted to be used specifically for the purpose of your contract/service with them and may not be passed on to 3rd parties.

    3: Human Rights - The right to privacy in our home lives and communication very clearly this activity contravenes such rights.

    4: I am pretty sure that EU antispam law (although I can't remember the exact title of it) requires that people "Opt In" as opposed to being automatically opted in with a chance to opt out. This is why all the forms for credit applications and consumer level services etc. have changed over the past couple of years to get explicit consent to pass details on to third parties as opposed to explicit refusal. These check boxes used to have something like "If you do NOT want us to share your data with 3rd parties please tick this box" which has now changed to "We may at times share your data with partners and other members of the BT Group please tick the following box if you consent to this." (BT is used merely as a placeholder).

    So lets quit with all the crap and actually deal with this in the appropriate way, the courts. BT have already been shown to have trialled this service without receiving the consent of their customers first, which means they have already broken the law and a class action should be started to hold them accountable.

    Seriously, it is about time you lot grew some God damn bollocks instead of just whining in comments to news, on blogs and in forums. I have never been more ashamed to be British than I currently am. These companies only get away with this type of illegal behaviour because YOU (as in a national WE) allow them to. You all complain but can't be arsed to do anything real about it and then wonder wtf this shit happens in the first place.

    WAKE THE HELL UP!

  4. Paul Barnfather
    Alert

    Here's how it works

    (I think, having read all the blurb on the Phorm site...)

    1. All your browsing (URLs, content but not https) is routed via Phorm's server. Presumably due to bandwidth requirements it's physically there in the ISP datacentre (like a wiretap).

    2. Phorm's server sends a unique cookie to your browser, analyses your web traffic and "categorises" that browser in real-time based on your surfing habits (actually 3x an hour, maybe). It then associates your browser ID with your assigned "category".

    3. The OIX database (ad server?) then watches for that cookie ID and injects "relevant" ads into your http data stream based on your current category - either replacing existing ads or even inserting new ones (not entirely clear on this). It may also pass on your cookie ID and category to third parties to that they can do the advertising directly.

    So no, forget any swanky DNS tricks or ad blocking. What the ISPs appear to be doing is allowing a trusted (hah!) third party access to all your surfing content. Phorm claim this "cannot be used to identify you because it's anonymous and we ignore phone numbers and email addresses and IP addresses". Bo||ox. Just one snapshot of a non-https gmail session is enough to identify anyone...

    To me this appears to be in blatant contravention of TalkTalk's privacy policy, which states that they will not disclose personally identifiable information to thrid parties except in a very specific set of circumstances.

    PS: The service does not appear to be live yet on TalkTalk (you can for yourself by going here: http://www.webwise.com/privacy/can-choose-NA.html). You might want to keep checking, and be sure to let your ISP know what you think about this.

  5. Anonymous Coward
    Stop

    Information Commissioner

    As soon as I heard about my ISP (Virgin) and the other two of the "big three" getting into bed with Phorm I contacted the ICO by telephone and had a very useful conversation with one of the ICO reps. They mentioned I was the first to raise the question of the "legality" of this "service" with them and they asked me to write to them with as much information as I could provide: which I have done.

    When I receive their report I will forward a copy to the Reg.

  6. Ade W
    Alert

    Splat

    As an aside, there is a satire by the Roman playwright, Terence, called Phormio in which there is a character (of the same name) described as a 'scheming parasite'. How very nearly apt.

  7. Mark
    Go

    I think people are getting a little over excited...

    ...about this. If anyone uses a Tesco's Clubcard then it's much the same thing.

    It sounds to me like it's just about giving you more targeted adverts as you browse which is hardly the crime of the century. Use an ad blocker if you don't want to see the ads.

  8. Tim
    Stop

    Not sure?

    If they inject adds into a web page are they breaching the copyright of the web page / web site .Also are they in breach of the spam control laws by sending you averts that you don't request?.

  9. Alex
    Linux

    random si good

    ''One little script constantly downloading (but not rendering) random web pages should be enough to make the collected data worthless and the increased traffic would piss the ISPs off too.''

    It seems that me that that is the best option to date since Phorm won't have any statistically relevant information so either they will send random stuff and that would be funny or they would realise that you're feeding them an inhuman number of pages per second and they would just give up. In any case, in makes you a little more anonymous. I guess something of the sorts doesn't already exist but it could be pretty simple to make, I guess.

    Anyonw know of any of this sorta shite is going on in Canada (If for example, Videotron sold out even more than usual ?)

  10. Paul Scarlett
    Gates Horns

    Does anyone know where this information is being sent.

    Does anyone know the exact url or ip address this information will be sent to or served from. Because if so why not do the simple thing to stop these ad's coming through to you, by adding a entry in your host file that points to 127.0.0.1. That way the ad's should not then reach your pc.

    Bill cos his a devil like phrom

  11. Jon

    Https

    so Paul Barnfather says it only sees http

    so all i need is an https proxy?

  12. Mark
    Thumb Up

    How it works

    There's no 'injecting' going on here. Adverts on most websites are currently served from one of a handful of advertising networks (Tradedoubler, CJ etc). What Phorm are doing is allowing these ad networks to direct adverts at a particular user using knowledge of previous websites they have visited and adverts they have clicked on etc.

    So the content of the website isn't being altered and the website owner has placed and configured the adverts themselves. As Phorm themselves say:

    'The user doesn't see more advertising, just more relevant advertising.'

    It really is no big deal. And for the people saying that they don't want their web surfing to be monitored and logged, I'm afraid this has always been the case and always will be. You'd be better of visiting a library if you're not happy with this concept.

  13. Anonymous Coward
    Pirate

    No way to opt out

    Forget about the ads. There is NO way to opt out of the interception of traffic unless the page you are looking at is delivered over https (a very small percentage of pages)

    No matter what your preferences are for targeted advertising, ALL of the contents of EVERY page you visit WILL be copied off the wire and sent to Webwise/Phorm servers, which are apparently located in China.

    This includes the contents of any cookies being sent, the headers of every page, the contents of any form submissions, any postings to message boards, online forums, web chats etc. and any private webmail you are reading.

    There is no way to opt out of this. You can only opt out of receiving the advertising.

  14. Paul Barnfather
    Stop

    @ Mark

    Not quite. When you go to Tesco, the data stays with Tesco and their privacy policy (presumably) does not allow them to sell data on your shopping habits to third parties. Plus, the Data Protection Act requires them to take care of this data.

    In this case, the ISPs are unilaterally allowing a third party to come in and snoop your surfing habits and sell this private data to who knows. In the contract with your ISP, I would be very surprised if you agreed to give them permission to sell/pass on your surfing habits to third parties.

    That is the problem here: they are doing something with YOUR private data without your permission. They are specifically not allowed to do this by law.

  15. Someone

    Re: I think people are getting a little over excited...

    The analogy with loyalty cards is a bad one. If you’re buying a packet of extra small condoms and some haemorrhoid cream, you can pay without handing over your Clubcard. You could even pay with cash! Look at these, or possibly even more private, things on the Internet and Phorm may well know.

    (While shops do use secure websites, they are often just for the checkout page. Filling your basket is done ‘out in the open’.)

  16. Paul Barnfather
    Thumb Up

    @ Jon

    Yes, an https proxy should should do it.

    According to Phorm, "[the] technology does not view any information on secure (HTTPS) pages"

    More here: http://www.phorm.com/about/faq.php

  17. Anonymous Coward
    Anonymous Coward

    People aren't getting overexcited (IMHO)

    When I go to tesco's and use a clubcard, it is entirely by choice, and is part of a transaction between me and tesco.

    What this bunch of ***** is doing, is intercepting communications between 2 parties. (and I strongly doubt that their will be any informed consent).

    .....and then, the little blighters actually go on to change the content of the communications.....

    The exec's who ok'd this at the respective companies really do think they can do anything they like to their customers.

    This is more akin to someone creating a machine that reads your post, "anonymously analysises it" and then shoves leaflets into the envelops and reseals them.

    J.

  18. Jeff Deacon
    Unhappy

    And another thing ...

    Webwise has had a couple of mentions above, so I went to have a look at their site. They claim "to offer [a] combination of security and customization benefits." The security being anti-phishing. Run "by" BT and TalkTalk. On their FAQ page I found this:

    "What is Webwise?

    "... that is designed to provide a safer, more personalised Internet browsing experience. ... ... Webwise also replaces a website’s generic ads with ones more relevant to your interests, based on your browsing behaviour – while remaining ‘blind’ to who you are. ..."

    How it can be "personalised" and "'blind' to who you are" at one and the same time is an issue that has been raised before. Of course at least one of those statements must be a deliberate lie.

    What really puzzles me though, is how "replaces a website’s generic ads with ones more relevant to your interests" can be anything other than outright fraud on the publisher of the original web site. Especially if they are paid on click through.

    It seems to me to be on the same level as Microsoft's one time "feature" to pop up their own adverts on any page rendered by IE6 regardless of the site publisher's wishes. This is the cause for many to insert the meta tag

    <meta name="MSSmartTagsPreventParsing" content="TRUE"> into their pages.

  19. Red Bren

    @Mark

    Its easy to opt out of the clubcard system. If you're buying a family pack of rubber jonnies and you don't want Tesco to know your favourite brand, you don't hand over the card. Or don't get a card in the first place. Or you go to a different shop. How do you opt out if your ISP is giving wholesale access to surfing data to a third party?

    You can use blocking software to "opt out" of the targetted spam, but this is just the same as not opening junk mail. The sending company still has your surfing/shopping habits.

  20. Simon Greenwood

    Madasafish/Brightview

    Just checked on thinkbroadband.com and confirmed that MAAF/freenetname/Brightview have also confirmed that they won't be implementing it (basically as they have been joined up with PlusNet by BT buch as such are a separate entity from BT Broadband).

  21. Peter Leech Silver badge

    Re: Not sure?

    > If they inject adds into a web page are they breaching the copyright of the web page / web site .Also are they in breach of the spam control laws by sending you averts that you don't request?.

    Interesting question. Its not going to be a breach of copyright, but the last bit gave me something to think about.

    Phorm say "Our platform gives consumers advertising that's tailored to their interests - in real time - with irrelevant ads replaced in the process."

    Now, If I am running a website and I have, say my own static adverts on that I am gaining income from and Phorm replace my "irrelevant ads" with their own ones then I am going to lose income because they are replacing my ads. Do they have the legal or moral right to do that? The word "theft" comes to mind. (Not that I use ads on my site anyway, but I am sure someone does...)

    I would imagine that informing large ad brokers of this will probably cause more of a reaction that pointing this out to the ICO. In fact, going to the Office of Fair Trading would probably be a good idea. Thinking about it, they are effectively creating an advertising cartel in Phorms favour by preventing other companies from entering the market, which has to be the definition of anti-competitive behavior. Advertising Standards would probably be interested as well, this has several breaches of the CAP code principles.

    It could also have the effect of putting websites out of business if they rely on advertising income. I am sure I have missed a few implications as well.

    I would think that besides of the ICO investigating this the OFT could get involved along with the ASA. That would probably slow down the implementation down a little.

  22. Aristotles slow and dimwitted horse

    This has been raised...

    As an E-petition with 10 Downing street. Go sign it...

  23. Jeff Deacon
    Unhappy

    @ I think people are getting a little over excited...

    It is for that reason that I choose not to have a Tesco loyalty card, and to shop there using only cash. At the time of writing, these are perfectly legitimate options.

    But customers of BT, TalkTalk and VirginMedia are being told in effect that loyalty cards are mandatory, that they come as an integral part of the "service"!

  24. ZeroTheHero
    Alert

    Until ...

    ... Chris Williams and the rest of the Vulture Central team get back from the pub, sorry, Register Research Institute and Archives with a concise, well researched and relevant exposé into how this works, we won't know anything concrete or lager flavoured.

    From my skimming of the patent application mentioned above and the Cable Forum thread on this subject it looks like Paul Barnfather has the closest grasp on what MAY be the actual mechanism

    However, his 1st point may not be correct, Phorm state on their website that "Phorm technology does not view any information on secure (HTTPS) pages, and ignores strings of numbers longer than three digits to ensure that we do not collect credit card numbers, phone numbers, National Insurance or other potentially private information." The implication being that they may receive the https pages from your ISP. As to ignoring numbers longer than 3 digits - All your postcodes are belong to Phorm.

    A proxy on it's own won't work, https or otherwise.

    Tor will work, but will impact on your page loading times, as will JAP

    Firefox users can use either TrackMeNot or RefControl to obfuscate the search data being sent Phorm by making it so noisy as to be useless, but the information will still be sent to Phorm by your ISP

    The web ads being served by Phorm can be opted out of, but this requires you to have a cookie placed on your machine, if you nuke your cookies during housekeeping you have to go and opt out again (or after about 2 years as the cookie has a roughly 760 day expiry time). This will not stop your information being sent to Phorm by your ISP

    As mentioned previously there is a lengthy thread on this at Cable Forums ( http://www.cableforum.co.uk/board/12/33628733-virgin-media-ad-deal-updated-see.html ) if you've got the time to read it

  25. Andy Livingstone

    Information Commissioner

    Anonymous Coward waiting for a response may well see Christmas first. That office is miles behind after being inundated by complaints from the world and his brother. After the first acknowledgment, any review will simply give the best reason they can think of for taking no further interest. Based on experience.

    No good phoning till after the acknowledgment arrives with their all-important reference reaches you either. Their "smart" system can recognise only documentation that has been typed. Anything hand-written is in boxes which they cannot afford staff time to search through.

    I've obtained written confirmation from my ISP that they will not indulge in these games. Not sure how reliable it is, but at least they know where I stand.

  26. Eden

    OK but what about...

    Aren't ads revenue for many pages, surely by injecting ads they are stealing revenue from people by overwriting the ads they "Host" with their own injected ones without the web page holders permission?

    The other way round don't some advertisers PAY to be shown on big web pages who will then be "cut out" by phorm?

  27. Anonymous Coward
    Dead Vulture

    @ not sure & co etc etc

    The ads will be selected to be displayed in the space of advertisers already signed up to OIX.COM. So there are other big names knowingly or unknowingly signed up to this - FT.COM for example - who are already buying advertising from OIX.com but who will be able to build simple scripts that parse the contents of your browsed web pages and use that to choose exactly which ad to display in the OIX space. Other adverts will not be affected. So the REAL issue is do we want them to have the content of all the web pages we choose to access. The advertising changes will be minor from our perspective.

  28. Brian Miller
    Heart

    DEMON INTERNET IS THE BEST

    I have been with Demon for a long while now and cannot fault them in any way. They are as truly unlimited as you can get on a home package nowadays, fair use applies to the top small percentage (3 i think) as calculated over a rolling 10 day period, though it seems imperceptible to me, and I would describe myself as quite a heavy internet user.

    Their privacy policy categorically states that they will not hand over your info including IP to third parties (apart from contractors for their own internal purposes which is then immediately deleted) unless under a court order.

    They are Faultless in my mind, having had no problems in a couple of years. I have never heard any grumbles from other demon users.

  29. Mark
    Happy

    I love the internet!

    People get a snippet of info and then make the rest up!

    No one is going to alter the contents of a web page to insert adverts - the web site publisher has to be in on this too (it explains all of this on the Phorms website). It simply changes the adverts which are served from the ad agency which the particular website is using. It won't affect all websites - it depends who they are using to serve their banner adverts etc.

    Websites already do all of this via cookies anyway - this just sounds like a more efficient means. And the data is anonymous as Phorms will never know your personal details.

    There really is nothing to see here - move along.

  30. Paul Barnfather
    Stop

    @Mark "There is no injecting going on here"

    The Phom website implies otherwise:

    "The OIX uses data from ISP pipes to upgrade the generic advertising on websites with more relevant ads. These ads will be viewed by that ISP's subscribers who are most likely to be looking for the advertised product or service based on keyword patterns in their browsing behavior. "

  31. Mark

    @ Paul Barnfather

    The 'generic ads' are placed there by the website publisher. An example is Google ads which reacts to what's on the page. The Phorm ads instead react to who the user is (without using personal details - just your IP).

    There is no injecting going on here - the ISPs really would never get away with it even if they thought it was a good idea.

  32. Anonymous Coward
    Anonymous Coward

    ...Have spoken to C4 News...and Private Eye

    ----- Original Message -----

    From: XXXX, Anthony

    To: strobes@private-eye.co.uk

    Sent: Friday, February 29, 2008 3:51 PM

    Subject: New Story - BT, Virgin Media, TalkTalk sell private browsing history to Phorm

    Dear Mr Hislop,

    I am forwarding this email to you to try and raise the profile of this (scandalous, in my opinion) deal in which BT, Virgin Media and TalkTalk have agreed to sell browsing history, web page scans, webmail conversations etc to an advertising broker called Phorm without the user's knowledge or consent. Phorm have a dubious past, they host their servers in China and have possible connections with the Russian Security Services. I hope you feel it is worth further investigation by your esteemed organ.

    Regards,

    Anthony

    ----- Original Message -----

    From: XXXXX, Anthony

    To: XXXXXX@itn.co.uk ; XXXXXX@itn.co.uk ; XXXXXX@itn.co.uk

    Sent: Friday, February 29, 2008 1:08 PM

    Subject: New Story - BT, Virgin Media, TalkTalk sell private browsing history to Phorm

    Hi,

    I have spoken to Will on the Newsdesk about raising the profile of this story and he suggested contacting yourselves. The basic story is that BT, Virgin Media and TalkTalk have entered into a deal with a company called Phorm to sell private browsing history to an advertising broker (Phorm). I am personally a customer of VM and am now cancelling my contract as I feel this is a massive invasion of privacy, goes against the DPA and RIPA and is possibly against the law. Phorm themselves are an extremely dubious company, have their servers hosted in China, and have possible links with the Russian Security Services. They also have been previously associated with releasing Spyware into the wild.

    I am technically competent enough to recognize the implications of what VM have done in making a deal with Phorm and so am voting with my cash, as it were, however I do feel that the average man in the street won't be and so am asking if you would investigate this further and bring it into the public domain.

    Further information is here...

    http://www.theregister.co.uk/2008/02/29/phorm_broadband_isp_targets/

    http://www.theregister.co.uk/2008/02/25/phorm_isp_advertising/

    http://www.f-secure.com/sw-desc/apropos.shtml

    Regards,

    Anthony

  33. Anonymous Coward
    Flame

    @ Mark - get your facts straight!

    Some people have put a lot of effort into researching this and you would do well to study the facts before dismissing them as unimportant. You are right that many adservers dynamically select the ads to display. The difference in this case is that the entire text of the web page will be analysed in order to select the most appropriate ad. However this is till not the main issue. The main issue is that a company with dodgy credentials operating outside of the UK will have a full copy of every web page you retrieve including for example webmail, search terms, form fields which may include personal information, etc. The very fact that they say that they will ignore numbers longer than 3 digits shows that they have access to them and there is no regulatory body to prevent them from for example harvesting social security numbers and passing them to their Russian spyware-pushing friends just as they have previously done under their '121' incarnation .

  34. This post has been deleted by its author

  35. Dave Bell

    It's a million-to-one chance, but it just might work.

    So, if I run a website supplied with adverts by a company which has a contract with Phorm, those adverts will be matched to Phorm's image of the reader?

    If I get adverts from other sources, my reader's activities will still be monitored by Phorm.

    Will my webpage and adverts be analysed? It seems that Phorm can't be relying on URLs, thay have to be looking at the webpage content being sent to the user. Is there some way I can tell Phorm to piss off? I might be running a subscription-only news service, and here's the ISP and Phorm taking my product and making a derivative work.

    I wonder what happens if I use HTTPS to look at my ordinary ISP web data?

  36. Paul Barnfather
    Alert

    @ Mark

    Yes, having read El Reg's latest analysis you're right - there's no ad "injection" going on here (other than the Phorm cookie, which *is* injected). They seem to be replacing generic OIX ads with targeted ones. So if that is true, it's apparently no worse than DoubleClick.

    BUT they are definitely passing your (private) web traffic onto a third party for "processing". Even if they claim to delete this stuff straight away, this is an absolute no-no as far as the Data Protection Act is concerned, and almost certainly violates the ISPs own privacy policy (until they change it, that is...). Even so, you simply cannot pass on copies of private data to a third party for any kind of processing without consent of the individual concerned.

  37. Anonymous Coward
    Thumb Down

    @Mark

    Bollocks to that.

    The issue of receiving advertising is a red herring. There are two real problems here:

    1. Portions of your web traffic are being copied and sent without your knowledge to a third party other than your isp, potentially to another country. These copied packets could well contain items of private information even if the packet which contains it is supposedly anonymous.

    2. This system clearly involves some kind of lookup to the third parties servers from the web server where you are requesting a document. Obviously this is going to a - add latency to your web browsing, and b - artificially increase traffic on certain network routes.

  38. Anonymous Coward
    Pirate

    @ all the people replying to Mark

    Reading his different posts, it sure sounds like our friend Mark is astroturfing for Phorm - conveniently skirting the issue of data collection and harping on the fact that we'll just get more interesting ads.

    Let the FUD begin !

  39. Dazed and Confused

    @Mark

    > without using personal details - just your IP

    Your IP address is legally "Personal details" at least in Europe.

  40. Anonymous Coward
    Stop

    Injection a red herring, illegal interception the issue - and how to punish your ISP

    Yep, I really dunno how anyone who's been following the story could think they're going to inject anything into your traffic, but that's not the point; this is an illegal wiretap. Your ISP does not have the right to snoop on and forward your traffic to a third party any more than BT has the right to listen to all your phonecalls. The fact that they're only listening in order to find out what you're talking about so they can sell that information to advertisers is not an excuse under the RIPA.

    And the best way to get revenge on your ISP is to hit them where it hurts, in the pocket. Closing your account and moving to another provider is one way to do that, but since the ISPs are doing this in order to subsidise their costs, another way would be to keep your account and start using an encrypted anonymiser such as Tor. That way you're still costing them the overheads but you're not giving them any useful data they can sell to defray them.

  41. plastical
    Flame

    I do know something about it...

    So, I have Virgin their 5 days. Yes, they are doing it. No, its not opt in. Or opt out. There's no opting about it. (Disclaimer: he said that he would check that). He understands my concerns about privacy. However, there are "no pricacy worries". "No private data is collected"...sorry, but the contents of my e-mails are private. He is sorry Virgin hasn't told customers sooner, and offered to file a complaint with Ofcom. I'll leave that one till the next call...

  42. Anton Channing
    Go

    @ Aristotles slow and dimwitted horse

    I would sign the petition, but you failed to provide the url.

    I've just looked for this e-petition on the http://petitions.pm.gov.uk website, but searching for Phorm, revealed no petitions, and scanning through all 161 petitions in the "Information and communication" category also turned up nothing that seemed to be about this issue.

    If there is a petition, could we have the url please? I would create one, but you seem to imply that one should already be there and I don't want to duplicate the effort...

  43. Paul Barnfather
    Alert

    TalkTalk denies any partnership with Phom!

    Just got this back from customer services.

    I quote:

    --

    Thank you for your e-mail regarding a possible new partnership between

    TalkTalk and Phorm.

    I can confirm that TalkTalk is not in any partnership with this company

    and all data from our customers accounts is kept confidential and is not

    shared with any other company.

    --

    Interesting, huh?

  44. Anonymous Coward
    Anonymous Coward

    Re E-Petition

    Aristotles slow and dimwitted horse - Under which heading and under what name is the e- petition?

    Anon

  45. Duncan

    The issue...

    ... alot of talk all over this but surely the issue pure and simple is that they have not asked. Isn't it always that? Really you'd have thought someone somewhere in some marketing department would have twigged that the same thing happens everytime if you don't ask? Maybe a bit of revenue sharing with the users?

    Anyway.... I'd not sign up even with that but I think thats the main problem here.

    On the e-petition is there one somewhere? Link or create soon I feel :)

    From scouting around I have to say that Phorm looks pretty dodgy to me, but maybe just maybe I'm missing something... :P

  46. Mark
    Happy

    @ everyone replying to me

    Perhaps the reason that I'm not bothered by any of this is down to the fact that I don't regard web browsing as in anyway a completely private activity. I browse at work where my company can easily monitor the websites I visit. I browse at home where Virgin Media log every page I visit and will turn this info over to the police at the drop of a hat.

    I'm certainly not going to lose sleep over a company sifting through my web activities anonymously in order to provide me with more targeted adverts, which I think on the whole is good idea and the future of the web as it stands today may even depend on such mechanisms.

    Sites such as The Register rely solely on advertising in order to keep running free of charge - they do not run on fresh air. So would you rather have targeted advertising or have to start paying a subscription? You may believe that paying a subscription to The Register is worthwhile, but how much is a fair amount? £10 a year? £25 pounds a year? And how many websites do you regularly visit? That could add up to a lot of £25 subscriptions. If every site started charging a subscription then the web would be a very different place. Being able to dip in and out of websites would become a thing of the past.

    I know from personal experience that ad banners produce very little revenue for websites. I also keep reading how apps such as the BBC iPlayer are costing ISPs far more in bandwidth costs than they are charging customers. All of this is going to come to a head at some point and initiatives along the lines of this Phorn one are, I'm afraid, inevitable. In my opinion it's naive to think otherwise.

    And no, I am in no way affiliated with Phorn, who from reading the other Reg articles on the subject do sound a little dodgy. But the major companies involved in this will not be doing this lightly as they really do not want to start losing customers (especially Virgin Media!). If people want the internet to remain 'free' then some form of compromise between customers and the ISPs is required and this sort of initiative is really only the start of it.

  47. Pierre
    Thumb Down

    Good point Mark.

    So I guess that you're OK with all your snail mail being copied and sent to an advertiser in China (Anonymously of course. We remove the envelope, so it's anonymous).

    Your browsed webpages are already monitored by your ISP. Right. But they have a legal obligation to keep it secret and not to misuse it. Phorm doesn't have any obligation, of any kind, and they'll see all your e-mails and all your visited webpages, including data in forms, all nicely tied together by your "anonymising number". So in less than a week they are bound to have your full name, email adress, street adress and phone number, associated with the complete coordinates of your friends and family, and with the content of the pages you browsed (including whatever you bought, and what it was worth).

    Anonymous indeed. If you do use online banking services, they'll also have your full bank credentials (they say that the system "doesn't use" large numbers, not that they won't get them... but not use them. Of course. Plus, even if they truncate large numbers now, I bet that noone is going to notice if it's later changed, during a "routine maintenance" or a "firmware upgrade" for example.) And no-one can do anything to prevent them to re-sell all this information to anyone. Or dry up your bank account themselves, followed by a quick run towards the Cayman Islands.

    Actually, it's even worst, because as they operate from China, they might just empty your bank account and get away with it whithout even having to hide. Who is going to analyse their servers to prove the fault?

    As for the internet being free, you might find that it's not the case at all. You pay to browse it, you pay each time you access an ad-funded site. That's not the main problem. No-one here pretended that the ads are the major issue (though it's bound to be annoying at least).

    Methink you should also buy a few spare Winsta packages, you know, just in case your computer crashed.

    And get some KY on the way back, you're gonna need that.

  48. Anonymous Coward
    Anonymous Coward

    @Mark

    Most people here are concerned about free speech; you seem to be more concerned about free beer (well free-ish internet). Don't get me wrong, I'm in favour of free beer, but perhaps free speech will cost money?

  49. BitTwister

    @DEMON INTERNET IS THE BEST

    Brian, my thoughts too. Seems that all the noise is being caused by the new 'meja' kids on the block - the ones only interested in what they can harvest through being an ISP instead of just providing a reliable pipe with minimal control-freakery, period, like Demon do - and always have.

  50. system

    Plusnet pleasing customers?

    I was with plusnet at the time they started opting everybody in to tiscali unbundling without any form of notice or consent. The customers had to fight them tooth and nail to get an opt out added to profiles.

    On top of that, they brought in new caps on bandwidth usage by application as well as overall, pulling a Comcast on not just p2p traffic but also anything that was encrypted, denying all claims of "throttling" and then using the term "management" instead. They prefered instead to ensure that all VOIP calls on their VOIP service got through (killing skype, teamspeak and others).

    Before signing up I had phoned them twice and spoken to two different operators to ensure that their "unlimited" service could cope with 100GB/month. Later, when they knocked us all down to 10GB/month, they continually denied ever selling an unlimited package even when people pointed to their own archives.

    If you enjoy dealing with a sack of snakes, go to plusnet. If not, there are actually some reputable companies out there offering broadband services. Sure, you wont get it at £10 a month, but it's nice to not be constantly bent over.

This topic is closed for new posts.

Other stories you might like