User comments on ISPs
  >> BT Broadband


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | 4 | 5 | (show all)   Print Thread
Standard User deleted
(deleted) Wed 09-Apr-08 09:45:45
Print Post

Phorm caught editing Wikipedia article


[link to this post]
 
the article on the front page here says it all about how trustworthy Phorm are trying to edit out bits they didn't like ! this is a nail in the coffin as to how they intend to operate - underhand -sneaky and untrustworthy.

i have sent a email to the CEO of BT pointing this out today.
Standard User deleted
(deleted) Wed 09-Apr-08 14:22:25
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Given the amount of energy they have expended trying to put a positive spin on this intrusion into peoples privacy, Im not surprised by anything they do - maybe its a show of how desperate they are to get this launched here. I dont think it would stand a prayer in the USA where Phorms predecessor - 121 media/people on page - were originally from.

I wouldnt put much hope in getting a positive response from BT, they are only too happy to rake in the cash from selling YOUR data to this marketing parasite, you are merely a means to an end... an increased margin to please the shareholders. The privacy of customers comes a long way behind profit margins it seems for some ISP's.
Standard User deleted
(deleted) Wed 09-Apr-08 14:33:45
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
In reply to:

intrusion into peoples privacy




What part of my privacy is being intruded upon?

My name, address, phone number, ip address, BT Username etc?

When I use Google Mail, for example, my emails are being read by Google and adverts inserted relating to the contents of the emails. Is Phorm similar in that it tracks me and pins my searches to a user account?


Register (or login) on our website and you will not see this ad.

Standard User tommybee
(newbie) Wed 09-Apr-08 15:46:30
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Random Jointer

But nice to see the ICO's amended report now stating that implementation should be by "opt in" only.
As in when you contract for G. mail you accept the EULA
BT's offering can hardly be classed as a value added service IMO
Standard User deleted
(deleted) Wed 09-Apr-08 16:10:42
Print Post

Re: Phorm caught editing Wikipedia article


[re: tommybee] [link to this post]
 
Phorm doesn't add any value for the customer, I agree.

However it is not invading anyone's privacy either. It's just another way of making a few bob for the isps.

The biggest invasion of privacy seen around this parish, in my view, was when Entanet Referrer adsl24 pulled data off of his website, dslzone, and published it on Think Broadband in order to discredit someone who gave him a bad review. That's something you would never see BT doing.

So my view is Phorm is nothing to worry about but also gives no benefit to customers and has generated a lot of hot air from tin foil hat wearers.

So I wouldn't be surprised to see it quietly dropped after the forthcoming trial as the revenue figures involved are not great in the grand scheme of things.

Not that I'm bothered either way
Standard User deleted
(deleted) Wed 09-Apr-08 16:28:28
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
You have a clear choice to use Gmail or not. Until today it was expected that Most ISP traffic would be routed by default through Phorms servers unless you had an "opt out" cookie stored, and given how often people clear cookies for security it was easy to see that this was a way of getting many more opted in by default - happily the ICO has ruled that Phorm has to be Opt out by default so this nasty little loophole has been closed off.

There is a strange silence about what happens to traffic from customers who DONT want to be profiled, personally I have no trust in a company that is descended from those behind the "people on page" rootkit and I wouldnt want ANY of my traffic going near a server that they have any access to data from. The Anti phishing protection is nothing that isnt already available in any up to date browser software - even the much vaunted Internet explorer! So Phorm are giving back pretty much nothing in return for you allowing them to see all your browsing (and any webmail you have). The question should also be asked about what value are particpating ISPs giving back to the customers who are having their data sold to a third party?

Look at it. Phorm make money from advertisers for serving the ads (and possibly revealing to other family members what you have been browsing for so dont try to plan a surprise on line). Your ISP gets paid by Phorm for YOUR click traffic... so.. whats in it for you... without whom there is no "business model. You probably pay a fair market price for a BT connection... this isnt Tiscali offering "moon on a stick for �1.99". Why do they feel the need to further profit from your custom in this way? Are they admitting their business model is failing? are their prices unsustainable? I doubt that.. so... WHY?

There is also the question of the secret trials conducted on "live data" that many believe amounted to illegal inteception of data under the RIPA. Hopeful;ly now the ICO has gotten off of his hands, others will have a look at what these 2 companies were really doing with its customers data.

I fully realise that many people fall in to the "I have nothing to hide" category, and thats fine for them, if they are ghappy to surrender to ever increasing levels of snooping into every aspect of their lives, but not all of us are quite so passive - in fact EU law gives us a right to privacy in communications - we are just trying to fight for our right to CHOOSE how much imfo we surrender.

Thats reasonable... isnt it?
Standard User deleted
(deleted) Wed 09-Apr-08 16:34:20
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Interesting Article mentioning Upcoming Phorm trials here . Also looks at the legality of the previous trials conducted in secret on live data and previously discussed elsewhere on this forum
Standard User deleted
(deleted) Wed 09-Apr-08 17:39:34
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
So, in short. What part of my privacy is being invaded by Phorm ?

For example, websites that use Google Analytics, such as Think Broadband, can see my IP address, track my journey through their site and plot my location on a handy little map. I don't remember opting into anything that gave permission to webmasters to track my journey through their site but they do it. Quick, pass me the tinfoil

Does Phorm see my IP address or plot my location on a map?

As far as I can see, Phorm serves me an advert on a webpage unless I opt out of Phorm in which case I will be served, er, a different advert on the same webpage.



Edited by deleted (Wed 09-Apr-08 17:43:29)

Standard User deleted
(deleted) Wed 09-Apr-08 19:16:40
Print Post

Re: Phorm caught editing Wikipedia article *DELETED*


[re: deleted] [link to this post]
 
Post deleted by warweezil
Standard User deleted
(deleted) Wed 09-Apr-08 19:22:18
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Until early this afternoon when the ICO finally creaked into action, this was "OPT OUT" which meant that if someone followed the oft repeated advice to regularly clear cookies (also quoted as a cure for low speeds IIRC) they were likely to be opted in without Informed consent, however the ICO has ensured that a positive action will be required by a customer, hopefully they will see straight through the Phishing protection scam and realise that up to date browsers already have it and that Phorm is just a get rich quick scheme benfitting the former spyware company and BT shareholders only - all take no give.

You have your view... I have mine, fact is I many find it objectionable for an ISP leeching my data and selling it off to a third party especially when the customer has already paid the going rate for his/her connection. I also object to Phorm using any webpage content I provide to help form a "profile" of my visitors intersts, I object to Phrom having any Profiling access to emails I send to a webmail address that may be accessed from a "Phorm infested" ISP. I have a clear choice to send to Gmail or not, but i dont expect mails sent to yahoo or hotmail to be caught up in any profiling.

As far as IP address Goes, they have no yet proven that the UID cannot be linked to an IP, interseting to note that shortly they will know that some people are in Croydon or Ealing as users from those areas are set to be used in the next trials to take place.

This company has been busy spinning, wiki fiddling and outright lying in its attempt to sanitise this (Virgin are not in fact signed up) what they propose is no bette than the post office opening your mail and using the contents of that to decide what junk mail to put through your door. I think their actions speak louder than any words I have, to display the desperation they have leads me to think that they are getting more and more desperate to get this accepted.
Just My Opinion.... YMMV
Standard User deleted
(deleted) Wed 09-Apr-08 20:06:17
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
In reply to:

Phorm is just a get rich quick scheme benfitting the former spyware company and BT shareholders only




All firms are out to make a profit. They use it to pay tax, invest in the business and divvy up to the shareholders.

BT publish their accounts so you can see how much they make, how much tax they pay, how much they pay out to shareholder and how much they invest. BT also donate a large amount to worthy causes.

Perhaps you might ask your ISP when they are going to publish their accounts overdue way back in 2006 whilst we are looking at corporate probity as I understand they claim to donate all profits to worthy causes yet refuse to file their accounts? I'm sure there is a perfectly acceptable reason why companies can ignore company law it's just that I can't think of one right now

In reply to:

As far as IP address Goes, they have no yet proven that the UID cannot be linked to an IP, interseting to note that shortly they will know that some people are in Croydon or Ealing as users from those areas are set to be used in the next trials to take place.




Phorm do not store IP addresses. Do not store browsing history. That is what is different about Phorm compared to the hundreds of other cookies on your computer or sites such as Think Broadband that use Google Analytics or the millions of people who use free email accounts.

In reply to:

what they propose is no bette than the post office opening your mail and using the contents of that to decide what junk mail to put through your door.




That would be invading your privacy and would be illegal. Of course, the Post Office and marketing companies do use Postcodes to determine profiles and the information is used to target junk mail to specific areas.

Do you get a lot of junk mail advertising cheap tin foil by any chance?

My view is -
Am I worried about Phorm? No.
Do I want Phorm? Not particularly.
Do I want BT Broadband with free hub, vision box, cheap voip service with free kit, free smartphone with inclusive minutes and free access to Openzone and Fon for less money than some providers charge just for broadband alone? Yes, and I've just recontracted.

Edited by deleted (Wed 09-Apr-08 20:19:20)

Standard User Jude105
(newbie) Wed 09-Apr-08 20:55:40
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Not really a surprising view RandomJointer, coming from a BT Shareholder Just a slight conflict of interest, don't you think.

Im sure your views will be noted by everyone :E
Standard User deleted
(deleted) Wed 09-Apr-08 21:16:24
Print Post

Re: Phorm caught editing Wikipedia article


[re: Jude105] [link to this post]
 
Most people have an interest in BT shares either directly or via their pension.

Do you have any information that might assist a shareholder in determining how Phorm is spying on users as it might be helpful in taking a view on my holding?

So far, we have not established any personally identifiable data that Phorm is collecting. In fact, it would appear that my caller display unit collects more data than Phorm.

Edited by deleted (Wed 09-Apr-08 21:17:38)

Standard User deleted
(deleted) Wed 09-Apr-08 21:22:55
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
My ISP? hmm I think you are mistaken there, maybe you mean my RESELLER, and that is between him and the relevent authorities if in fact the database is correct - I wouldnt pretend to know. It seems to be a matter approaching obsession for you as you have been going on about this for a very long time. If you are so interested, why not contact my RESELLER yourself, directly [email protected] , rather than sniping at his customers in this forum?

Phorm CLAIM they do not store, but have we seen any cast iron proof? Similarly, I note you ignored the potentially illegal interception of data during the trials which many people - more expert in this area than you or I - consider to be a breach of RIPA .

As for Phorm, you are clearly happy to play along with thier game, in the same way as many others are not, and I think I said clearly enough that we occupy different positions on this, such is life, If my ISP started to make a few million off of its users data, without giving me anything extra - Id be looking for my share - or I'd want my data keept away from any profiling equipment. I am happy to see that companies will now be forced to ask thier customers to pot in, rather than expecting those uncomfortable with this to Opt out.

Your tin foil remarks only cheapen the debate, even the Information Commissioner has warned previously of the dangers we face from increasing tracking and surveilance, its bed enough when our government do it, but now it seems companies we "employ" seem to feel it is ok to take advantage of the data that passes between us on whatever level for further profit. Simply put, I pay a company to connect me to the net, I dont pay them to pimp my data especially to a company that has its roots in Malware.

There seems little point in continuing this. we occupy opposing positions. and as I tagged my last post -

Just My Opinion -YMMV!


Administrator MrSaffron
(staff) Wed 09-Apr-08 21:44:08
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
If Phorm was being sold to consumers as what it was rather than a webwise phishing protection system then I'd be more comfortable.

If those who opted out were guaranteed a route through the network that did not touch any Phorm servers (including ones leased to the ISP) then I'd be more comfortable.

if it only does what it is said to do, then in terms of privacy it should be fine, and here is the BUT, past experience has shown these sort of things to have a degree of function creep or flaws that expose information.

If the trials had been open, or done just on BT staff then I'd have less worries.

There are concerns and this sort of thing should have been all known about at the point when the service was announced, not slipping out bit by bit as people figure things out


Andrew Ferguson, [email protected]
www.thinkbroadband.com - formerly known as ADSLguide.org.uk
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
Standard User deleted
(deleted) Wed 09-Apr-08 21:44:19
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
In reply to:

My ISP? hmm I think you are mistaken there, maybe you mean my RESELLER, and that is between him and the relevent authorities if in fact the database is correct




According to my enquiries on the matter, Companies House webcheck is no more than 48 hours behind.

In reply to:

you have been going on about this for a very long time.




Well, UKFSN have been overdue on their accounts for a very long time. I would be highly suspicious of firms who claim to donate profits to worthy causes yet fail to file their accounts.

In reply to:

Phorm CLAIM they do not store, but have we seen any cast iron proof? Similarly, I note you ignored the potentially illegal interception of data during the trials which many people - more expert in this area than you or I - consider to be a breach of RIPA .




I would expect BT, Carphone etc have the odd guy around who knows a few things about how the law affects communications providers.

In reply to:

the Information Commissioner has warned previously of the dangers we face from increasing tracking and surveilance




Yes it's all very worrying. How is Phorm tracking me again? What data do they get that tells them anything about me at all?

In reply to:

There seems little point in continuing this.




But we were getting on great and I was looking forward to finding out what personally identifiable data Phorm was collecting from me?



Standard User deleted
(deleted) Wed 09-Apr-08 21:50:21
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
A load of people overreacting to something they don't really understand, either through lack of information available or pure laziness to understand what exactly it is about.

So Phorm edited their article on Wikipedia - didn't Sony do the same to an XBOX 360 article relating a new game?

I very much doubt BT will roll-out Phorm now after the mass uprising its caused. Its more likely to send share prices down, which would not go down too well with the shareholders. The sole purpose of business is to maximise shareholder wealth.

In reply to:

Well, UKFSN have been overdue on their accounts for a very long time. I would be highly suspicious of firms who claim to donate profits to worthy causes yet fail to file their accounts.



Might have something to do with the fact that UK Free Software Network Ltd is a Private Limited Company and thus does not have to publish its accounts for the public.

Edited by deleted (Wed 09-Apr-08 21:53:36)

Standard User deleted
(deleted) Wed 09-Apr-08 21:50:35
Print Post

Re: Phorm caught editing Wikipedia article


[re: MrSaffron] [link to this post]
 
Surely that is what a trial is all about?

My view is Phorm is nothing to worry about but it gives no benefit to consumers.

So the resulting hysteria will probably kill it off after the trial but it would be a shame if it also killed off investment.

BT hold one of the biggest databases in the country of personally identifiable data. Peoples names, addresses, bank accounts and phone numbers. They have held that data with the utmost respect for peoples privacy for years. I have no problems trusting BT when it comes to privacy.
Standard User Jude105
(newbie) Wed 09-Apr-08 22:29:57
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
"Can I find out what PII Phorm Service keeps about me?
The Phorm Service is designed to avoid the collection and storage of PII, however you have the right to request a copy of any information that Phorm may have about you and to have any inaccuracies corrected. A reasonable fee may be charged for information requests, and we reserve the right to request such evidence as we consider reasonably necessary in the circumstances to prove your identity We will use reasonable efforts to supply, correct or delete any information about you that Phorm may have"

how can that be possible? If as continually stated, everything is anonymous.

"Even this non-personally-identifiable information is automatically purged from the production system immediately. (Research and debug logs may be kept on a separate system for a maximum of 14 days)."

Separate system? 14 days??

Phorms CEO's history with 121 media and their rootkit is enough for most people.

Then: http://www.thisismoney.co.uk/investing-and-markets/article.html?in_article_id=430955&in_page_id=3

I could go on all night but quite frankly have better things to be doing, like finding another ISP.

If BT really think that being associated with all this is good for business, then GL
Administrator MrSaffron
(staff) Wed 09-Apr-08 23:50:21
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
"but it would be a shame if it also killed off investment. "

What investment? BT surely has revenue from advertising now? Is Phorm going to provide many millions more than what it could generate using existing schemes.

Perhaps we have different views of trials...people did spot the preivous trials and as no-one knew they were going on did all sorts of stuff to try and rid themselves of it. If a trial proper then support would have known about it etc

BT may hold the data - but does it hold this data - the Phorm system operates an OIX so the resulting advertising profile for a connection is looked up on the OIX server for all sites that server OIX adverts. What assurrance is there that BT would not add a tracking option to record visits to broadband provider sites, and then start offering retention adverts.

It may be nothing to worry about, but when I start to get pre-emptive phone calls about a new service it tends to make me worried about why they using the big PR machine on me - what do I need convincing about.

Andrew Ferguson, [email protected]
www.thinkbroadband.com - formerly known as ADSLguide.org.uk
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
Administrator MrSaffron
(staff) Wed 09-Apr-08 23:54:09
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
With regards to RIPA etc it remains to be seen, it is often the case that lawyers interpretations will vary, law is very often not clear cut.

previous versions of Phorm which it appears BT trialed were clearer cases of interception and modification i.e. the insertion of javascript onto pages.

If a provider can do this when it makes a few million, why not do something for the BPI to track access to music websites that may have copyright material without the holders permission, and tracking of access to torrents. If BT got paid to do it would it be worthwhile.


Andrew Ferguson, [email protected]
www.thinkbroadband.com - formerly known as ADSLguide.org.uk
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
Administrator MrSaffron
(staff) Wed 09-Apr-08 23:58:10
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
The ethics of web 2.0 are somewhat new and it seems PR people may have something to learn, it takes a while for new providers to our forums to learn what is acceptable in terms of pushing ones own product.

If Phorm had wanted to do it better, they'd have had much better information available at the start, i.e. avoid many of the mis understandings.

Andrew Ferguson, [email protected]
www.thinkbroadband.com - formerly known as ADSLguide.org.uk
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
Standard User sej
(experienced) Thu 10-Apr-08 00:08:26
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
RandomJointer,

You are surprisingly in the minority when it comes to accepting being �spied� on by your ISP but that�s your choice.

There is a wealth of information on the internet regarding Phorm e.g. http://www.theregister.co.uk/2008/02/29/phorm_roundup/ and most rational people after researching will come to a negative conclusion.

Simply put, if Phorm is so good why does it smell so bad, a good product sells itself.

Putting YOUR tin hat on, the Phorm service is designed to avoid the collection and storage of PII, you have to take their word on this i.e. ISP�s have no access to the Soviet source code of Phorm�s kit used in the exchange and therefore cannot guarantee that foreign nationals aren�t intercepting internet communications by UK government departments or major industry for other purposes.

The Guardian* has ditched Phorm
*With 19.52 million visitors in February, The Guardian is the UK's most popular newspaper website according to the industry standard ABCe audit system.

In an email to a concerned reader, advertising manager Simon Kilby revealed the retreat:
It is true that we have had conversations with them [Phorm] regarding their services but we have concluded at this time that we do not want to be part of the network. Our decision was in no small part down to the conversations we had internally about how this product sits with the values of our company.

I hope you appreciate that the quality of the Guardian's editorial is funded by our advertising sales operation and it is our duty to keep abreast of all developments in this sector. In this instance, however, I agree with you that this is not something that we should be partnering.
Standard User deleted
(deleted) Thu 10-Apr-08 00:19:17
Print Post

Re: Phorm caught editing Wikipedia article


[re: MrSaffron] [link to this post]
 
They seem to be using 3 PR companies to put across their message, one forum started getting "on message" posting from "tech team" which turned out to be a PR company - not technically versed at all.

They have lied about trials, making at least one person jump though hoops trying to rid himself of a mysterious"infection" on his machine (I bellieve he went as far as buying a NEW PC, ) then once the secrecy was broken, they went on a PR offensive, invading anywhere that the name was mentioned, posting spin and selective comments to put their chosen slant on comments that didnt excatly fit their needs, and now it transpires that the *deal* with Virgin media is now being reported as only Virgin "expressing an interest" - not "signed up" at all.

Given the amount of spin and deceit involved I wonder that anyone trusts them at all.

Standard User deleted
(deleted) Thu 10-Apr-08 00:58:24
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Why not let�s have the two behemoths of this board come together for a nice discussion! First point, I don't hold ANY BT shares so no conflicts here!! Also sorry for the quite long post.

My view on form is one very cautious one, why are Phorm so worried about highlighting the benefits of this system. So far going back to what MrSaffron has said, it does appear they have something to hide, after all why start a full on PR offensive if everything is good. The best comment in regards to Phorm has to be from Charles Dunstone, he essentially said that if Phorm want to make their product a success then THEY will have to sell it to Talk Talk customers and make it worth the customer�s time. I have the same view on Gmail/Google Mail. Google provide me with a first class e-mail service, in return they get to scan all mail and target me with ads. Clearly I am getting a service in return whereas with Phorm and BT/Virgin Media/Talk Talk I don�t appear to be getting any benefits. Yes Phorm and the ISP�s involved will tell me that I get targeted advertising or Phishing protection but those are not services I find useful.

Let�s rewind to 2004 the major free e-mail providers were just Hotmail and Yahoo Mail, Hotmail provided you with 2MB of storage for free and Yahoo 5MB. 5MB is nothing even by 2004 standards, by that time you had photographs being exchange via e-mail, even text based e-mail would fill the paltry 2MB provided by Hotmail at that time. Google comes along and says well we will offer 1GB of storage to anybody regardless BUT we will scan the contents of the e-mail and have targeted advertising in return for the service. I got my Gmail account in June of 2004 it would have been one of the very first accounts available with the public invitations and I never gave the e-mail scanning a second thought because I got 1GB of storage space.

Change that over to Phorm and now we have an issue I already have a Phishing filter provided by AVG 8.0 and Firefox/IE7/Opera so I don�t really need another and targeted advertising well is that even a feature.

People are more than happy to give away some freedom in exchange for a worthwhile service which Phorm isn�t. Going back to my original point if Phorm has as much benefits as they are making out why not make it opt-in, surely if it has all said benefits users will sign up anyway. Don�t get me wrong BT provide a shed load of services which really add value to their broadband product, really until BT don�t provide certain services until customers opt-into Phorm it will sink, or Phorm give the users direct benefits which they can see and use.

Privacy is a concern but not as much as what number 1 gets out of the deal. Much more users would sign up to Phorm if they got something worthwhile from it. It�s also my personal belief that Phorm do seem to be very open about the system they have and that if we turn away from it completely we could end up with something which is much worse. Kent (sorry can�t spell surname) has a good concept which just about every corporation with money spare is doing since the announcement. Look at Equifax even they are looking at doing it and they are a credit reference agency!!

Edited by deleted (Thu 10-Apr-08 00:58:54)

Standard User BitWrangler
(newbie) Thu 10-Apr-08 04:56:51
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
Up until now, the conduit between users and the websites they visit has been a neutral one and users haven't had to worry about it. Yes, many of the websites that users visit do profile them. Yes, many websites have relationships with ad networks, and those ad networks profile users as they move around partner websites. That profiling, which is limited in reach, will continue no matter what. Most websites, however, don't profile users or have relationships with ad networks. People have the option of visiting those. In addition, there are a massive number of darknet websites (private to semi-private, invitation only so to speak). Most of the web is privacy friendly. If the context were a Phorm enabled ISP, that would be WAS privacy friendly.

The first huge issue with the Phorm system is that it taps directly into the ISP network, and by doing so can both intercept and manipulate most all of the traffic that is sent to and from each user. Even if the Phorm system only captures HTTP, it will still have tremendous visibility into the activities and lives of users. Far, far more than any traditional advertising system. The Phorm system and others like it can observe activity and content that other advertising systems and even search engines can't see. Including a very large percentage of password protected HTTP content (webmail, forums, private documents, etc.).

Now lets talk a little bit about the system. Basically, the system assigns you a unique ID (stored in a cookie) and intercepts all of your HTTP (only, they say) traffic and captures most of it. That would tend to include HUGE amounts of personally identifiable information, personal information, sensitive information, you name it. What the system actually does with that data after capturing it is essentially impossible to verify. Not even the ISPs know for sure, as Phorm, Inc. has said that ISPs don't get access to the source code. All we can go on are representations, and faith that those representations are true now and remain true forever. Which is easy for some people, absurd to most. Anyway, the representations are that this huge amount of frequently personal and sensitive information is pseudo-anonymized and pseudo-sanitized, then matched against targeted advertising channel rules. The system keeps timestamped logs of the channels you match (entries are retained for up to six months), and the logged data is subsequently used to select which ads will be shown to you when you visit a partner website.

Phorm, Inc. and the ISPs stress that the URLs you visit, the words you search for at search engines, the keywords extracted from the pages you visit, etc aren't stored... only the channel matches. Maybe that is true, maybe not, again we can't be sure. When they describe what gets logged they mention high level categories like "sports" and "travel". Well, if per user profiles stored nothing but high level interests like that, we wouldn't be talking about this now... nobody would want to use it. This is a system which is designed to deliver, not broadly targeted advertising, but precisely targeted advertising. Those that create advertising channels can configure them to target users who search for specific words at search engines, who visit a specific website or websites, who view content that matches specific words, etc. They can configure things so that advertisements are only shown to those who match those rules a certain number of times during a certain period. That level of targeting. Now think about that for awhile. Ask yourself "how can the system allow ads to be shown only to those who visited website <whatever> twenty times in the past four months?" and the system not KNOW that the user visited website <whatever> twenty times in the past four months? It doesn't make any sense does it? It's like a friend of yours telling you to hold up a particular picture to them when you see them reading a particular book every day for two weeks. You can't do that without knowing that they've read the book and when. You might make some cryptic entry in a notebook whenever you see them doing it. You might show that notebook to someone and say the notebook doesn't reveal anything. They might even agree with you. However, that notebook does contain detailed information about what your friend was doing. Chew on that for awhile, and project that idea onto the Phorm system and I think you'll be on the money.

So we have this system that is storing detailed information about the activities, interests, and behavior of <insert gigantic number> users. Is that not enough to send a chill down the spine of a reasonable person? Perhaps you are saying "no, because it is impossible to correlate any of that information with specific people". Impossible? Ha! Who designed this system? Who wrote the software? Who understands all the debug options and software updating mechanisms? Phorm, Inc employees. Do you REALLY think it would be difficult for them to link your UID to your IP Address or other personally identifiable information that the system chews on? Give me a break. Goodness knows a subpoena would get both Phorm, Inc and the ISP to cough up everything they have and can acquire from the systems they control. Plus, and this is a real gem, the system literally forges cookies for the websites you visit and puts your UID in those cookies. Take that laptop to work and do some surfing... presto, the HTTP sites you visit (which typically includes sites that actually know who you are) have your UID. Just think of all the backdoor opportunities that raises.

It is usually at this point that people fall back to "what's the problem, you can opt-out if you don't like it". Well, the opt-out mechanism was so thoroughly botched that the potential partner ISPs have had to rethink how they might manage that at a higher (account) level, and there is no guarantee they won't make matters worse by closely coupling the Phorm system with their authentication system (which automatically knows who you are). If such systems take root and the ISPs get hooked on the income, do you really think they will continue to allow users to opt-out without paying more for the privledge? I sure don't. At least I wouldn't count on it, and the last thing I think people should be doing is paying premiums to maintain some semblance of privacy.

This is getting too long and I'm just going to stop here. Even though we've barely scratched the surface. It is easy, and almost automatic, for those who aren't concerned about their privacy to be dismissive of the privacy concerns of others. If you fall into that category, so be it. A great many people with considerable technology and privacy experience consider this an extremely important issue and such systems unacceptable. One data leak or exploit could have profound consequences for the privacy and/or security of millions upon millions of people.
Standard User deleted
(deleted) Thu 10-Apr-08 13:31:32
Print Post

Re: Phorm caught editing Wikipedia article


[re: BitWrangler] [link to this post]
 
Excellent points raised, I do think that if the Phorm profiler just copied the HTTP headers and read where user 123456789 was going to and then matching it with a list of know categories that would be better.

e.g. user visits xbox.com and will get ads for games consoles. Instead of the user going to their private messaging area where they talk with another user about speaker systems and then get ads about speaker systems.
Standard User BitWrangler
(newbie) Thu 10-Apr-08 20:54:11
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
If you think about how traditional TV, radio, newspaper, and magazine advertising works... the advertisements are chosen based on the nature of the content and aggregate information about the types of people that are interested in that content. That is the way online advertising used to work too. However, those in the advertising industry... knowing that they could exploit technology to acquire information about individuals and their past/present interests... kept pushing and pushing for increased data collection and targeting. Tracking and profiling was foisted upon Internet users - out of greed.

I think it is very important to recognize that history and the motivations and priorities of those in the industry. Do you feel they could now be trusted to give up their addiction for per user data? Do you feel they could now be trusted to use only one thing they see (say the host or domain name of the website the user is currently viewing) and not remember that in some way or use the other things they see?

When a system is only tapped into individual websites that have agreed to participate, the system can only see some of what you do and thus there is some compartmentalization of the threat. When a system is tapped into the ISP's network and sits between you and everything else, it can see everything that isn't encrypted which is most of what a user sends/receives. I basically agree with the idea that it would be better for advertising to be based simply upon the nature of the website one is visiting. However, I don't think advertising folks can be trusted to do that. I don't think they can be trusted with control over a box that sits between me and the Internet. There is an inherent conflict of interest.

Sorry for using so many words to get points across. I'm just deeply upset by this push by Phorm, NebuAd, and others to conspire with like minded folks inside ISPs to tap my connection to the Internet.
Standard User deleted
(deleted) Thu 10-Apr-08 22:31:41
Print Post

Re: Phorm caught editing Wikipedia article


[re: MrSaffron] [link to this post]
 
In reply to:

What investment?




If Phorm works it will make money. It will make money by serving relevant ads. Money made will partly be invested in the network.

Websites depend on ads for click through revenue. If the ads are relevant, websites make a few bob. If ads are not relevant they wont.

The king of click ads at the moment is Google. Everyone wants a slice of that pie including webmasters.

I have been looking for 205/55 r16 tyres today. Thinkbroadband has been serving Google Ads inviting readers to view upskirt photos of Britney Spears. If ThinkBroadband was serving OIX ads, I'd be far more likely to click through to tyre ads than photos of Britney's knickers.

In other words, websites have and will always have ads. Relevant ads are better for websites, advertisers and providers. In this case they are also better for consumers.

Phorm is cleverer than Google and it also does not collect the data Google Ads and Google Analytics do so providers and webmasters are going to be interested in trialing it.




Edited by deleted (Thu 10-Apr-08 22:54:17)

Standard User Tenacious_T
(member) Thu 10-Apr-08 22:46:33
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
I would go for the knickers myself

__ ____ ______________ ____ __

BTBroadband

"We've just tested your line and can confirm your line supports the UK's most complete broadband package, BT Total Broadband and we can confirm that you will be able to reach a maximum download speed of 7.5 (Megabits per second)"

IP profile for your line is - 7150 kbps
DSL connection rate: 448 kbps(UP-STREAM) 8128 kbps(DOWN-STREAM)
Actual IP throughput achieved during the test was - 6538 kbps
Standard User deleted
(deleted) Thu 10-Apr-08 22:50:07
Print Post

Re: Phorm caught editing Wikipedia article


[re: Tenacious_T] [link to this post]
 
Maybe you would, I have young kids and would rather not be served irrelevant ads. So Phorm would serve me and my kids tyre ads, you would get some 'other content'
Standard User Tenacious_T
(member) Fri 11-Apr-08 00:09:39
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
my norton offers add blocking so it's very rare i see add's on sites... wouldnt this prevent adds being offered by phorm too?

Also I do think some people need to lighten up on the subject... If your interested in Phorm then opt in if/when it becomes available... If you don't want it then it's simple dont opt in!!!

Peace!!!

__ ____ ______________ ____ __

BTBroadband

"We've just tested your line and can confirm your line supports the UK's most complete broadband package, BT Total Broadband and we can confirm that you will be able to reach a maximum download speed of 7.5 (Megabits per second)"

IP profile for your line is - 7150 kbps
DSL connection rate: 448 kbps(UP-STREAM) 8128 kbps(DOWN-STREAM)
Actual IP throughput achieved during the test was - 6538 kbps
Standard User BitWrangler
(newbie) Fri 11-Apr-08 04:50:58
Print Post

Re: Phorm caught editing Wikipedia article


[re: Tenacious_T] [link to this post]
 
This system uses a man in the middle attack to breach one of the most important security & privacy protocols on the net, forging and deleting cookies for every domain it can. That activity can negatively impact websites and those that operate them.

This system effectively uses the user's credentials to gain access to password protected areas that, in many cases, contain private and/or personal information belonging to others. Others who did not agree to such interception and the privacy risks posed by this system.

This is a centrally controlled system that may be tapped into many heterogeneous, distributed, ISP systems in the UK and other countries, and it has the ability to silently snoop, manipulate, and steer traffic. Which makes it a national and international infrastructure & security issue. Doubly so given the Russian development team.

The opt-out mechanisms are flawed and even if you opt-out your traffic is still intercepted by the system.

Phorm, Inc. and the ISPs are pushing ahead with this and will continue to do so unless frequently apathetic or otherwise neutralized entities muster the power to actively combat their plans.

Is it a little easier to understand why this is a "heavy" issue?
Administrator MrSaffron
(staff) Fri 11-Apr-08 10:20:49
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
That add from google you are talking about should no longer appear, it was a mis match on the keyword system it would seem.

If google can do this - why Phorm? Tyres could turn up slimming adverts, as in get rid of the spare tyre.

Question is how much more income will Phorm generate over say a sites existing income? Relevant ads are entirely possible now if the advertising people place their ads on the appropriate pages e.g. buy space on the motoring section of a portal.

Google et al do what they do without any hardware in the ISP's network, this hardware I presume is not free, what tests has phorm done to be sure its system will scale to cope with the browsing habits of a couple of million people? Consider this how many HTTP requests does each web page generate, a lot more than the one in the browser bar.

For some people Phorm would appear to be a step too far in the advertising game, but then advertising does like to push the boundaries in an attempt to gain exposure.

In shared households will the wife when viewing her favourite websites be more likely to click adverts for stuff that is relevant to your browsing?


Andrew Ferguson, [email protected]
www.thinkbroadband.com - formerly known as ADSLguide.org.uk
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
Standard User deleted
(deleted) Fri 11-Apr-08 11:26:51
Print Post

Re: Phorm caught editing Wikipedia article


[re: MrSaffron] [link to this post]
 
Another issue which is bothering me about Phorm is the amount of inaccuracies their CEO has when giving interviews. A good example of this was when the Guardian said about Privacy International who NEVER gave Phorm any approval but it was Simon Davies and 80/20 Thinking who did and Kent just said well yes Privacy International.

Kent Ertegrul claims to be from the UK so surely he would understand the grasp of the English language. A Fiat well its a Ferrari isn't it? It's all the same company at the end of the day but I doubt they are similar.

Here caught red handed on the tech radar interview
http://www.techradar.com/news/internet/exclusive-techradar-interviews-phorm-ceo-315326

"TechRadar: How can Phorm convince the average web-user that their data is being profiled �anonymously�?

Kent Ertugrul, Phorm: We built the system from the ground up with privacy in mind and have been very transparent about how it works. We�ve had Ernst & Young, privacy experts from a company called 80/20 Thinking and technology professor, Richard Clayton review the technology."

Richard Clayton REVIEWED the technology but never approved it. In fact if anything he has more criticisms about Phorm. I don't see this building much trust trying to pull the wool over users eyes like this.
Standard User sjr
(experienced) Fri 11-Apr-08 12:36:02
Print Post

Re: Phorm caught editing Wikipedia article


[re: MrSaffron] [link to this post]
 
In reply to:

In shared households will the wife when viewing her favourite websites be more likely to click adverts for stuff that is relevant to your browsing?



For me this is one huge flaw in the thinking. These days it is quite common for more than 1 PC to access the internet so how can Phorm differentiate between traffic when only 1 IP is visible to the outside world?
Also, if BT and others use dynamic IPs, how can they target relevant ads without holding some sort of identifiable information, despite their protestations to the contrary?

Regards,
Steve
Standard User phantom66uk
(experienced) Fri 11-Apr-08 15:18:10
Print Post

Re: Phorm caught editing Wikipedia article


[re: sjr] [link to this post]
 
In reply to:

For me this is one huge flaw in the thinking. These days it is quite common for more than 1 PC to access the internet so how can Phorm differentiate between traffic when only 1 IP is visible to the outside world?
Also, if BT and others use dynamic IPs, how can they target relevant ads without holding some sort of identifiable information, despite their protestations to the contrary?




This is why the system is so reliant on "Cookies", each machine will have it's own unique "Cookie" and there will never be two of the same. It's this way that Phorm can target the correct machine on the network regardless to whatever IP address is currently being used.

Zen 8000 Pro User
SLAYRadio Listener
Standard User BitWrangler
(newbie) Fri 11-Apr-08 17:06:53
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
I concur regarding the shifty sales and PR techniques. Regarding Simon Davies and 80/20 Thinking approving Phorm, Simon Davies posted a message on the subject of their engagement with Phorm, which ended with "I understand you are concerned about alleged endorsement, but let me reassure you that if we ever endorsed a product, you�d know about it. The last time we endorsed anything was PGP in the era of Phil Zimmermann".

It is hard if not impossible to have a frank discussion with 80/20 Thinking staff now that they are engaged with Phorm Inc. However, my personal belief is that in private they would tell you that they very strongly prefer that such systems never be used by ISPs.
Standard User deleted
(deleted) Fri 11-Apr-08 18:08:28
Print Post

Re: Phorm caught editing Wikipedia article


[re: BitWrangler] [link to this post]
 
I HIGHLY recommend you listen to this: http://www.guardian.co.uk/technology/audio/2008/mar/11/charles.arthur.phorm at 23:30(mm:ss) in they start talking about Privacy International and Simon Davies. Kent just doesn't even understand the difference.Cant believe he even argues about it, remember Kent claims to have been brought up in the UK so if I understand it then I'm sure he will.

Sure after this interview has been posted online he is still claiming that Privacy international endorse Phorm.

Remember I participate on the Microsoft public newsgroups in my spare time so that means in my own time I'm a Microsoft employee. Not quite the same but not too far off.

Edited by deleted (Fri 11-Apr-08 18:19:33)

Standard User AbandonShip
(fountain of knowledge) Fri 11-Apr-08 18:55:15
Print Post

Re: Phorm caught editing Wikipedia article


[re: MrSaffron] [link to this post]
 
In reply to:

Question is how much more income will Phorm generate over say a sites existing income? Relevant ads are entirely possible now if the advertising people place their ads on the appropriate pages




If an advertiser wants to target visitors to a specific site, conventionally the advertiser will have no choice but to pay that site's going rate. But with Phorm the advertiser could target that site's visitors after they leave the site, in some cases it might even be cheaper. That website would see none of that advertiser's money.


In reply to:

what tests has phorm done to be sure its system will scale to cope with the browsing habits of a couple of million people? Consider this how many HTTP requests does each web page generate, a lot more than the one in the browser bar.




According to the CEO's statement in Phorm's 2006 results, it was about to conduct a trial of its new system on a test base of several 100,000 users. The statement was dated april 2007, so presumably this large scale test would have occurred in 2007


The Company has built on its existing PageSense platform to create a new server-based architecture called ProxySense. In Q4 of 2006, we conducted a live user trial of PageSense with a UK ISP, and we are about to start a larger trial of ProxySense with a test base of several hundred thousand users."


http://www.phorm.com/reports/Announcement_of_Annual_Results_2006.pdf

Stop ISP's breaching customers privacy http://petitions.pm.gov.uk/ispphorm/

Edited by AbandonShip (Fri 11-Apr-08 19:04:35)

Standard User deleted
(deleted) Fri 11-Apr-08 20:02:23
Print Post

Re: Phorm caught editing Wikipedia article


[re: AbandonShip] [link to this post]
 
Very intriguing... wonder if BT accidentally said 18,000 and meant 100,000!
Standard User AbandonShip
(fountain of knowledge) Fri 11-Apr-08 20:43:07
Print Post

Re: Phorm caught editing Wikipedia article


[re: deleted] [link to this post]
 
If it was a BT test, maybe BT only counted the ones that were opted-in for targeted advertising

Stop ISP's breaching customers privacy http://petitions.pm.gov.uk/ispphorm/

Edited by AbandonShip (Fri 11-Apr-08 20:44:38)

Standard User deleted
(deleted) Fri 11-Apr-08 21:01:36
Print Post

Re: Phorm caught editing Wikipedia article


[re: AbandonShip] [link to this post]
 
Well the only UK ISP it could be is BT, VM don't seem to be close to implementing it unlike BT who have started trials and are continuing them. Also in 2006 VM was still Telewest and NTL so unless it was that two they trailed it with who knows.
Pages in this thread: 1 | 2 | 3 | 4 | 5 | (show all)   Print Thread

Jump to