Register (or login) on our website and you will not see this ad.
|
These posts have been archived and can no longer be replied to or modified.
|
Pages in this thread: 1 | 2 | [3] | 4 | 5 | (show all)
|
Print Thread
|
|
|
With regards to RIPA etc it remains to be seen, it is often the case that lawyers interpretations will vary, law is very often not clear cut.
previous versions of Phorm which it appears BT trialed were clearer cases of interception and modification i.e. the insertion of javascript onto pages.
If a provider can do this when it makes a few million, why not do something for the BPI to track access to music websites that may have copyright material without the holders permission, and tracking of access to torrents. If BT got paid to do it would it be worthwhile.
|
|
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
|
|
|
The ethics of web 2.0 are somewhat new and it seems PR people may have something to learn, it takes a while for new providers to our forums to learn what is acceptable in terms of pushing ones own product.
If Phorm had wanted to do it better, they'd have had much better information available at the start, i.e. avoid many of the mis understandings.
|
|
The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
|
|
|
RandomJointer,
You are surprisingly in the minority when it comes to accepting being �spied� on by your ISP but that�s your choice.
There is a wealth of information on the internet regarding Phorm e.g. http://www.theregister.co.uk/2008/02/29/phorm_roundup/ and most rational people after researching will come to a negative conclusion.
Simply put, if Phorm is so good why does it smell so bad, a good product sells itself.
Putting YOUR tin hat on, the Phorm service is designed to avoid the collection and storage of PII, you have to take their word on this i.e. ISP�s have no access to the Soviet source code of Phorm�s kit used in the exchange and therefore cannot guarantee that foreign nationals aren�t intercepting internet communications by UK government departments or major industry for other purposes.
The Guardian* has ditched Phorm
*With 19.52 million visitors in February, The Guardian is the UK's most popular newspaper website according to the industry standard ABCe audit system.
In an email to a concerned reader, advertising manager Simon Kilby revealed the retreat:
It is true that we have had conversations with them [Phorm] regarding their services but we have concluded at this time that we do not want to be part of the network. Our decision was in no small part down to the conversations we had internally about how this product sits with the values of our company.
I hope you appreciate that the quality of the Guardian's editorial is funded by our advertising sales operation and it is our duty to keep abreast of all developments in this sector. In this instance, however, I agree with you that this is not something that we should be partnering.
|
|
Register (or login) on our website and you will not see this ad.
|
|
|
|
They seem to be using 3 PR companies to put across their message, one forum started getting "on message" posting from "tech team" which turned out to be a PR company - not technically versed at all.
They have lied about trials, making at least one person jump though hoops trying to rid himself of a mysterious"infection" on his machine (I bellieve he went as far as buying a NEW PC, ) then once the secrecy was broken, they went on a PR offensive, invading anywhere that the name was mentioned, posting spin and selective comments to put their chosen slant on comments that didnt excatly fit their needs, and now it transpires that the *deal* with Virgin media is now being reported as only Virgin "expressing an interest" - not "signed up" at all.
Given the amount of spin and deceit involved I wonder that anyone trusts them at all.
|
|
|
Why not let�s have the two behemoths of this board come together for a nice discussion! First point, I don't hold ANY BT shares so no conflicts here!! Also sorry for the quite long post.
My view on form is one very cautious one, why are Phorm so worried about highlighting the benefits of this system. So far going back to what MrSaffron has said, it does appear they have something to hide, after all why start a full on PR offensive if everything is good. The best comment in regards to Phorm has to be from Charles Dunstone, he essentially said that if Phorm want to make their product a success then THEY will have to sell it to Talk Talk customers and make it worth the customer�s time. I have the same view on Gmail/Google Mail. Google provide me with a first class e-mail service, in return they get to scan all mail and target me with ads. Clearly I am getting a service in return whereas with Phorm and BT/Virgin Media/Talk Talk I don�t appear to be getting any benefits. Yes Phorm and the ISP�s involved will tell me that I get targeted advertising or Phishing protection but those are not services I find useful.
Let�s rewind to 2004 the major free e-mail providers were just Hotmail and Yahoo Mail, Hotmail provided you with 2MB of storage for free and Yahoo 5MB. 5MB is nothing even by 2004 standards, by that time you had photographs being exchange via e-mail, even text based e-mail would fill the paltry 2MB provided by Hotmail at that time. Google comes along and says well we will offer 1GB of storage to anybody regardless BUT we will scan the contents of the e-mail and have targeted advertising in return for the service. I got my Gmail account in June of 2004 it would have been one of the very first accounts available with the public invitations and I never gave the e-mail scanning a second thought because I got 1GB of storage space.
Change that over to Phorm and now we have an issue I already have a Phishing filter provided by AVG 8.0 and Firefox/IE7/Opera so I don�t really need another and targeted advertising well is that even a feature.
People are more than happy to give away some freedom in exchange for a worthwhile service which Phorm isn�t. Going back to my original point if Phorm has as much benefits as they are making out why not make it opt-in, surely if it has all said benefits users will sign up anyway. Don�t get me wrong BT provide a shed load of services which really add value to their broadband product, really until BT don�t provide certain services until customers opt-into Phorm it will sink, or Phorm give the users direct benefits which they can see and use.
Privacy is a concern but not as much as what number 1 gets out of the deal. Much more users would sign up to Phorm if they got something worthwhile from it. It�s also my personal belief that Phorm do seem to be very open about the system they have and that if we turn away from it completely we could end up with something which is much worse. Kent (sorry can�t spell surname) has a good concept which just about every corporation with money spare is doing since the announcement. Look at Equifax even they are looking at doing it and they are a credit reference agency!!
Edited by deleted (Thu 10-Apr-08 00:58:54)
|
|
|
|
Up until now, the conduit between users and the websites they visit has been a neutral one and users haven't had to worry about it. Yes, many of the websites that users visit do profile them. Yes, many websites have relationships with ad networks, and those ad networks profile users as they move around partner websites. That profiling, which is limited in reach, will continue no matter what. Most websites, however, don't profile users or have relationships with ad networks. People have the option of visiting those. In addition, there are a massive number of darknet websites (private to semi-private, invitation only so to speak). Most of the web is privacy friendly. If the context were a Phorm enabled ISP, that would be WAS privacy friendly.
The first huge issue with the Phorm system is that it taps directly into the ISP network, and by doing so can both intercept and manipulate most all of the traffic that is sent to and from each user. Even if the Phorm system only captures HTTP, it will still have tremendous visibility into the activities and lives of users. Far, far more than any traditional advertising system. The Phorm system and others like it can observe activity and content that other advertising systems and even search engines can't see. Including a very large percentage of password protected HTTP content (webmail, forums, private documents, etc.).
Now lets talk a little bit about the system. Basically, the system assigns you a unique ID (stored in a cookie) and intercepts all of your HTTP (only, they say) traffic and captures most of it. That would tend to include HUGE amounts of personally identifiable information, personal information, sensitive information, you name it. What the system actually does with that data after capturing it is essentially impossible to verify. Not even the ISPs know for sure, as Phorm, Inc. has said that ISPs don't get access to the source code. All we can go on are representations, and faith that those representations are true now and remain true forever. Which is easy for some people, absurd to most. Anyway, the representations are that this huge amount of frequently personal and sensitive information is pseudo-anonymized and pseudo-sanitized, then matched against targeted advertising channel rules. The system keeps timestamped logs of the channels you match (entries are retained for up to six months), and the logged data is subsequently used to select which ads will be shown to you when you visit a partner website.
Phorm, Inc. and the ISPs stress that the URLs you visit, the words you search for at search engines, the keywords extracted from the pages you visit, etc aren't stored... only the channel matches. Maybe that is true, maybe not, again we can't be sure. When they describe what gets logged they mention high level categories like "sports" and "travel". Well, if per user profiles stored nothing but high level interests like that, we wouldn't be talking about this now... nobody would want to use it. This is a system which is designed to deliver, not broadly targeted advertising, but precisely targeted advertising. Those that create advertising channels can configure them to target users who search for specific words at search engines, who visit a specific website or websites, who view content that matches specific words, etc. They can configure things so that advertisements are only shown to those who match those rules a certain number of times during a certain period. That level of targeting. Now think about that for awhile. Ask yourself "how can the system allow ads to be shown only to those who visited website <whatever> twenty times in the past four months?" and the system not KNOW that the user visited website <whatever> twenty times in the past four months? It doesn't make any sense does it? It's like a friend of yours telling you to hold up a particular picture to them when you see them reading a particular book every day for two weeks. You can't do that without knowing that they've read the book and when. You might make some cryptic entry in a notebook whenever you see them doing it. You might show that notebook to someone and say the notebook doesn't reveal anything. They might even agree with you. However, that notebook does contain detailed information about what your friend was doing. Chew on that for awhile, and project that idea onto the Phorm system and I think you'll be on the money.
So we have this system that is storing detailed information about the activities, interests, and behavior of <insert gigantic number> users. Is that not enough to send a chill down the spine of a reasonable person? Perhaps you are saying "no, because it is impossible to correlate any of that information with specific people". Impossible? Ha! Who designed this system? Who wrote the software? Who understands all the debug options and software updating mechanisms? Phorm, Inc employees. Do you REALLY think it would be difficult for them to link your UID to your IP Address or other personally identifiable information that the system chews on? Give me a break. Goodness knows a subpoena would get both Phorm, Inc and the ISP to cough up everything they have and can acquire from the systems they control. Plus, and this is a real gem, the system literally forges cookies for the websites you visit and puts your UID in those cookies. Take that laptop to work and do some surfing... presto, the HTTP sites you visit (which typically includes sites that actually know who you are) have your UID. Just think of all the backdoor opportunities that raises.
It is usually at this point that people fall back to "what's the problem, you can opt-out if you don't like it". Well, the opt-out mechanism was so thoroughly botched that the potential partner ISPs have had to rethink how they might manage that at a higher (account) level, and there is no guarantee they won't make matters worse by closely coupling the Phorm system with their authentication system (which automatically knows who you are). If such systems take root and the ISPs get hooked on the income, do you really think they will continue to allow users to opt-out without paying more for the privledge? I sure don't. At least I wouldn't count on it, and the last thing I think people should be doing is paying premiums to maintain some semblance of privacy.
This is getting too long and I'm just going to stop here. Even though we've barely scratched the surface. It is easy, and almost automatic, for those who aren't concerned about their privacy to be dismissive of the privacy concerns of others. If you fall into that category, so be it. A great many people with considerable technology and privacy experience consider this an extremely important issue and such systems unacceptable. One data leak or exploit could have profound consequences for the privacy and/or security of millions upon millions of people.
|
|
|
|
Excellent points raised, I do think that if the Phorm profiler just copied the HTTP headers and read where user 123456789 was going to and then matching it with a list of know categories that would be better.
e.g. user visits xbox.com and will get ads for games consoles. Instead of the user going to their private messaging area where they talk with another user about speaker systems and then get ads about speaker systems.
|
|
|
|
If you think about how traditional TV, radio, newspaper, and magazine advertising works... the advertisements are chosen based on the nature of the content and aggregate information about the types of people that are interested in that content. That is the way online advertising used to work too. However, those in the advertising industry... knowing that they could exploit technology to acquire information about individuals and their past/present interests... kept pushing and pushing for increased data collection and targeting. Tracking and profiling was foisted upon Internet users - out of greed.
I think it is very important to recognize that history and the motivations and priorities of those in the industry. Do you feel they could now be trusted to give up their addiction for per user data? Do you feel they could now be trusted to use only one thing they see (say the host or domain name of the website the user is currently viewing) and not remember that in some way or use the other things they see?
When a system is only tapped into individual websites that have agreed to participate, the system can only see some of what you do and thus there is some compartmentalization of the threat. When a system is tapped into the ISP's network and sits between you and everything else, it can see everything that isn't encrypted which is most of what a user sends/receives. I basically agree with the idea that it would be better for advertising to be based simply upon the nature of the website one is visiting. However, I don't think advertising folks can be trusted to do that. I don't think they can be trusted with control over a box that sits between me and the Internet. There is an inherent conflict of interest.
Sorry for using so many words to get points across. I'm just deeply upset by this push by Phorm, NebuAd, and others to conspire with like minded folks inside ISPs to tap my connection to the Internet.
|
|
|
In reply to:
What investment?
If Phorm works it will make money. It will make money by serving relevant ads. Money made will partly be invested in the network.
Websites depend on ads for click through revenue. If the ads are relevant, websites make a few bob. If ads are not relevant they wont.
The king of click ads at the moment is Google. Everyone wants a slice of that pie including webmasters.
I have been looking for 205/55 r16 tyres today. Thinkbroadband has been serving Google Ads inviting readers to view upskirt photos of Britney Spears. If ThinkBroadband was serving OIX ads, I'd be far more likely to click through to tyre ads than photos of Britney's knickers.
In other words, websites have and will always have ads. Relevant ads are better for websites, advertisers and providers. In this case they are also better for consumers.
Phorm is cleverer than Google and it also does not collect the data Google Ads and Google Analytics do so providers and webmasters are going to be interested in trialing it.
Edited by deleted (Thu 10-Apr-08 22:54:17)
|
|
|
I would go for the knickers myself
__ ____ ______________ ____ __
BTBroadband
"We've just tested your line and can confirm your line supports the UK's most complete broadband package, BT Total Broadband and we can confirm that you will be able to reach a maximum download speed of 7.5 (Megabits per second)"
IP profile for your line is - 7150 kbps
DSL connection rate: 448 kbps(UP-STREAM) 8128 kbps(DOWN-STREAM)
Actual IP throughput achieved during the test was - 6538 kbps
|
|
|