Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Senate Scrutinizes Privacy Issues of ISP User Tracking

Posted by kdawson on Tue Jul 08, 2008 05:30 PM
from the you-want-to-watch-me-you-have-to-pay dept.
Hugh Pickens writes "As companies collect, use, and disseminate data regarding online users, there is concern that tracking individuals' Internet activity and gathering information from online users violates their expectations of privacy. The Senate Commerce Committee will hold a hearing Wednesday to look at the policy issues, and the hottest topic will be proposed systems by which ISPs can watch users and sell information about their surfing habits to advertising companies. The Center for Democracy and Technology has issued a report suggesting that these systems may violate federal law (PDF). 'Advertising per se is not the evil here,' says Leslie Harris from CDT. 'It's the collection of individuals' information, usually without their knowledge, always without their consent, creation of profiles and the complete inability of people to make choices about that.' On the other side NebuAd, the most active ad-targeting company, says its profiles are interest-based, and not personally identifiable. 'We have designed our entire company to make sure that we stay on the opt-out side of those laws and policies,' says NebuAd CEO Robert Dykes. Charter Communications announced last month that it would suspend a trial of NebuAd due to customer concerns about privacy."
+ -
story

Related Stories

[+] Charter's Trials of NebuAd Halted 97 comments
RalphTheWonderLlama writes "The trials of NebuAd by Charter Communications were halted after it gained the attention of Congressmen Ed Markey and Joe Barton. The online behavioral targeting system has been called "a 'man-in-the-middle attack' and various other unflattering names" but would certainly be an easy way for an ISP to cash in on client profiling." PaisteUser points out MSNBC's coverage as well, according to which the ad-insertion scheme was dropped because of "concerns raised by customers."
This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • by suck_burners_rice (1258684) on Tuesday July 08 2008, @05:39PM (#24107485)
    I'd say it's great that the Senate is scrutinizing what ISPs do to track people, but this shouldn't be limited solely to ISPs. There should be a lot of scrutiny about what the government does with your information, and I'm talking about all levels of government from the local level up to the federal level. Further, there are millions of businesses around the world, small and large, that gather all kinds of information. It is difficult to scrutinize so many companies, so I would say that the Senate should concentrate on the government first. Because the government collects the most.
    • Re: (Score:2, Interesting)

      Agreed. When an ISP makes a bone-headed move, like using NebuAd, it gets a lot of bad press and has a strong competitive incentive to say sorry and fix its mistake.

      I'm a lot more concerned about government invading my privacy than my ISP. You can always sue a company, but thanks to qualified immunity, government agents can break the law and get away scot-free.

      Now there is a bill in the Senate, sponsored by Grassley, to force online retailers to inform the government of every online credit card transact

      • by PopeRatzo (965947) * on Tuesday July 08 2008, @07:48PM (#24109009) Homepage Journal

        You can always sue a company.

        Not so. After tomorrow, for example, Americans will no longer be able to sue AT&T for violating the law by letting the Bush Administration tap their phones without any judicial oversight.

        The current president has taken the 60-year old notion of "state secrets" to an extent that absolutely shreds the Bill of Rights, but there was always the possibility that the truth would come out and the lawbreakers would have to pay. After tomorrow, not any more.

        • by corsec67 (627446) on Tuesday July 08 2008, @09:05PM (#24110029) Homepage Journal

          Doesn't "state secrets" as currently used in court violate the first amendment?

          Not the speech part, the ... to petition the Government for a redress of grievances. part.

          • Doesn't "state secrets" as currently used in court violate the first amendment?

            Absolutely. It was argued so in the 1948 case that started this whole "state secrets" baloney.

            There's a recent book by Barry Siegal, Claim of Privilege which tells the story of how this remarkable encroachment on the Constitution first occurred, when a military plane crashed and some contractors died. Their wives sued and just wanted to see the accident report. The government, trying to prevent a scandal and the relatively ti

            • George Bush has raised the claiming of state secrets to an artform. A very ugly, thuggish and anti-American art form. May he and Dick Cheney rot in hell.

              And you are not condemning Harry Truman [wikipedia.org] and Alben Barkley [wikipedia.org] to same for starting this non-sense — not to defend the country, mind you, but simply to cover-up their government's fuck-up — because?.. Oh, right, they were Democrats and thus could do no wrong...

  • Yeah, and? (Score:3, Informative)

    by Red Flayer (890720) on Tuesday July 08 2008, @05:39PM (#24107495) Journal

    'It's the collection of individuals' information, usually without their knowledge, always without their consent, creation of profiles and the complete inability of people to make choices about that.'

    Hey, guess what... if a partner in a two-way correspondence chooses to share details of that correspondence, that's their choice (i.e., don't give private info to someone you don't trust). If you choose not to make safe your correspondence from third parties via encryption, that's your problem.

    I'm willing to risk some troll or flamebait mods here to make a point:

    No correspondence should ever be considered absolutley private. The same tools that allow data aggregation by companies like Google and ISPs give us better access to information and (arguably) a better quality of life. You have to take the bad with the good.

    Creation of profiles allow vendors to serve us better. They allow better targeting of ads so we're not bombarded with ads for things we have no interest in (ok, in theory. In practice, this needs further work). They allow people and businesses to target our needs better, so it's easier for me to find what I'm looking for.

    As long as we have the ability to anonymize and encrypt our traffic (which isn't a given), I have no problem with profiling. Those who want to opt out can do so easily... and if there is enough demand for it, there will be off-the-shelf tools for joe sixpack to do so.

    So my point is this: Allow us to anonymize our traffic. Allow us to encrypt our traffic. Then you can go ahead and profile all you want.

    • Re: (Score:3, Insightful)

      Have you ever counted or even looked at the 1 pixel images embedded into web sites?
      I encountered a recent ridiculous one from a Yahoo access - something like that:
      us.bc.yahoo.com/b?P=FjLh6UWTUG8MnHdaSGkxXR + over 1000 characters more

      To load 1 PIXEL!!!!!

      There is tons of that stuff embedded in web sites. And that's got nothing to do with 2-way communication whatsoever.

      Wo tracks it, who controls it, who sells and buys it?
      Are the neurons in Sentat's heads interlinked enough to grok this?

      Highly doubtful -
      • Wo tracks it, who controls it, who sells and buys it?

        And why should you care, if your traffic is anonymized and your personal information, when needed, encrypted?

        • "if"

          -yeah, encrypted web surfing/email for the masses is happening and Tor has lightning access speed.

          It's just not reality at this point and will it ever be? So, your premise to arrive on your conclusion to "no need to care" is not a given, it's a cloud castle.
          • If there is a demand for anonymization and encryption services, someone will provide it. As more people are aware of (and concerned about) privacy issues, they will make use of such services, even if they have to pay for it.

            Just because you don't see it happening a ton today doesn't mean it won't be used a lot tomorrow.

            What is important is that our *right* to use anonymization services and encryption is not abrogated.
        • And why should you care, if your traffic is anonymized and your personal information, when needed, encrypted?

          But honestly, in order to get anonymous internet, you either have to A) take a huge speed-hit or B) trust a proxy. Neither of those are usually good options.

          • Re: (Score:3, Interesting)

            Not only are there people who don't know anything about encryption

            If they care about their privacy, that is their problem. If they don't care, no harm, no foul.

            but why should I have to do something extra to ensure I have what is already supposed to be mine?

            I have tons of problems with this question. Why do you assume that "it" is supposed to be yours? You're transmitting postcards, not sealed envelopes... assuming that by "it" you are referring to privacy, what makes you think that you have any expecta

            • You're transmitting postcards, not sealed envelopes... assuming that by "it" you are referring to privacy, what makes you think that you have any expectation of privacy...

              To complete your analogy, I guess it would be okay for the US government to read all postcards sent via the US mail, log the data, and use it for whatever purpose they want? After all, not sending it in a triple-sealed container means that we clearly wanted this information gathered and used. UPS can open and examine packages sent in paper envelopes or cardboard boxes, since if we cared about privacy we would have used a welded box.

              You're confusing what could happen with what should happen. Just becau

    • There is no harm in a business wanting my data to serve me better.

      Provide I, and only I, decide when they get what data.

      • Fully agreed. Hence the right to use anonymization and encryption must be held sacred. A built-in opt-out clause solved through technology, not through legislation (which is bound to have transgressions).
        • I don't see why I should have to take steps to avoid being spied on by corporations. Such a notion pretty much means that privacy becomes the prerogative of people technically savvy enough to protect it.

    • if a partner in a two-way correspondence chooses to share details of that correspondence, that's their choice

      Maybe. But that doesn't mean it's legal, and, more to the point, that there isn't "an expectation of privacy."

      If you choose not to make safe your correspondence from third parties via encryption, that's your problem

      So we should google over SSL? I can't find their https search service.

      The same tools that allow data aggregation ... give us better access to information... You have to take the bad with the good.

      Why do we have to "take the bad with the good"? Is there some law of quantum physics that says website visitor tracking must be entangled with advertising services?

      • But that doesn't mean it's legal, and, more to the point, that there isn't "an expectation of privacy."

        Why should it be illegal? Other than things like credit card numbers, social security numbers, etc, why should it be illegal? Is it illegal for me to tell my wife the details of a conversation I had with you?

        As for the expectation of privacy, are you kidding me? Were you never taught that emails (or for that matters, any packets) should be considered postcards, not sealed envelopes? The internet is a

        • > why should it be illegal?
          Because it isn't opt-in.

          > Is it illegal for me to tell my wife the details of a conversation I had with you?
          The more relevant question would be: Is it ethical for the phone company to record and correlate all conversations going through their lines and sell (summaries of) the recordings to third parties? Without their customers' consent? Without their knowledge?

          > Were you never taught that emails ... should be considered postcards
          What I've been taught is irrelevant. W

    • Re: (Score:2, Interesting)

      Collecting information about people's habits without their knowledge or explicit consent for the purpose of making money is reptilian. I say reptilian because I'm not sure that I can say it's unethical, because I don't believe that taking pictures of people in public is unethical. But then, what they do is more akin to paying someone you're likely to speak to to secretly record your conversation for them.

      If we all believed that companies just wanted to serve our best interests, then there would be no back

      • But then, what they do is more akin to paying someone you're likely to speak to to secretly record your conversation for them

        Sure. And why should I expect that this would never happen? Because it's unprofitable for them. But when the value of my conversations is more than the cost of paying people to eavesdrop, I have no expectation that people won't do so. This is why if you have information worth a lot to you, you don't share it, except with people you trust.

        And saying that, basically, if you don't

    • Hey, guess what... if a partner in a two-way correspondence chooses to share details of that correspondence, that's their choice

      Actually, that's not always the case. With phones for example, in some states[1], it is illegal to record a phone call without the other person's knowledge and consent. This is the reason for that "this call may be monitored or recorded" thing. Staying on the line implies consent.

      [1]California, Connecticut, Delaware, Florida, Massachusetts, Maryland, Michigan, Montana, New Hampshire, Pennsylvania, and Washington.

      • the free market has killed democracy quite badly.

        Reminds me of a quote (or sig) I saw once, wish I could remember the source:
        "In the 80s, capitalism triumphed over communism. In the 90s, it triumphed over democracy."

        • Reminds me of a quote (or sig) I saw once, wish I could remember the source:
          "In the 80s, capitalism triumphed over communism. In the 90s, it triumphed over democracy."

          Source of the quote: David Korten [davidkorten.org].

          (Props to Jeremiah Cornelius [slashdot.org], where I first saw it.)

      • > the free market has killed democracy
        Maybe it's not so much the "free market" that's to blame, but that we allowed our government to sell itself.

        > [killed] quite badly.
        It just so happens that it's only mostly dead.

      • Why do I want this, again?

        Because it pays for the content you're accessing? Because it helps offset the cost of providing service to you?

          • Re: (Score:3, Interesting)

            As to encryption, it's a sad day when you cannot trust your service provider to provide a service, without eavesdropping for profit. What next, encryption for snailmail? We could always use invisible ink, but that might prove difficult for the mail service to deliver

            If you're going to continue the snailmail metaphor, again I have to stress that without encryption, you are sending postcards, not sealed envelopes. And plenty of people have used, and still use, encryption with snailmail, as they deem it neces

  • Boiling a frog (Score:5, Insightful)

    by Mike Rice (626857) on Tuesday July 08 2008, @05:43PM (#24107565)

    How ironic that Congress is, in all likelihood, about to pass a telecoms immunity bill which allows them to spy on us... but are giving lip service to the issue of telecoms spying on us.

    CongressCritters and Snoozators will soon be making a lot of noise about how they are protecting the public from being spied upon, while at the same time making it legal for us to be spied on.

    Nothings changed, just another election year.

    • Re: (Score:3, Informative)

      CongressCritters and Snoozators will soon be making a lot of noise about how they are protecting the public from being spied upon, while at the same time making it legal for us to be spied on.

      Democracy in action :) - or rather that's what happens when the free market and democracy collide.

      We had a similar situation in the UK recently with a company called Phorm. ISP's were entering into secret deals with them to collect our data so that they could modify the html streams returned from sites to inject target

      • Re:Boiling a frog (Score:4, Insightful)

        by Opportunist (166417) on Tuesday July 08 2008, @06:23PM (#24108117)

        What free market? I hope you don't mean the mockery thereof that the current market of corporate cartels is.

        • Re: (Score:3, Interesting)

          Perhaps I'm using the wrong term - I'm ignorant of world affairs..

          I'm talking about the situation that exists when profit is used as a means to determine what is moral.

          • Re: (Score:3, Insightful)

            It's not even profit anymore. Profit as a measurement of morality could be considered free market. What we have today is more control instead of profit. Everything is moral and fine as long as I get more control. More control of the market (in case I'm a corporation) or more control of the people (in case I'm a government).

      • "9% approval rating - seriously. 9%."

        It could be 0% and nothing would change. Ask any voter and they'll tell you that the House of Representatives is composed of 434 voting asshats and one person who walks on water, who just happens to represent their district. Besides, the incumbents have seniority due to tenure, which further disinclines voters to vote against them.

  • by fahrbot-bot (874524) on Tuesday July 08 2008, @05:48PM (#24107631)

    We have designed our entire company to make sure that we stay on the opt-out side of those laws and policies,' says NebuAd CEO Robert Dykes.

    ... If they'd stay on the "opt-in" side, but I'm sure user participation and company profits would be lower. Too bad, so sad...

    • Charter Communications announced last month that it would suspend a trial of NebuAd due to customer concerns about privacy. The sad thing was, their page specifically stated that their Cookie would opt you out of seeing the ads. They did not say that the cookie would keep you from being tracked. Even most non-tech people know to clean their cookies, and many programs will do it for you, like ccleaner on windows. Their privacy policy explicity states they will turn over all logs and information for a warra
    • Re: (Score:3, Insightful)

      Not necessarily - what if you could opt in for a little discount. You get 5 bucks off your monthly internet bill, and in exchange they have permission to keep a cookie on your machine to track what your doing. On the other hand, as a government backed monopoly I suspect that the ISP's are going to come out of this whistling the tune of the free market.
      • Why would they need a cookie to track what you are doing? They can just monitor your connection directly as it flows through their network.

  • by Ollabelle (980205) on Tuesday July 08 2008, @06:12PM (#24107979)
    To me, the money here is targeting the user to feed him/her ("them") ads based on what that user has already seen, queried, etc.

    Yet, NebuAd says the data they collect is not "personally" identifiable. I'll bet a six-pack that the data is damn-sure "individually" identifiable by cookies, etc.

    "Personally" just means they're not selling my name along with my surfing habits. But they are very much tracking my individual habits/interest and selling that; user by individual user. I say send them back to tele-marketing, the scum-bags.

  • Putting it simply (Score:5, Interesting)

    by CopaceticOpus (965603) on Tuesday July 08 2008, @06:24PM (#24108133)

    What is needed is a clear separation between those companies that sling bits (ISPs) and those who provide content and advertising. Each ISP should be required to transfer data as fairly as possible with a minimum of interference and monitoring.

    Most broadband providers have a monopoly or duopoly, and therefore need to be regulated strongly. Otherwise, customers who object to these invasions of privacy will have nowhere to turn.

  • One question that the article doesn't explain is HOW they are showing targeted ads on sites... Sure, I understand if I were a Charter Communications ISP customer going to a Charter site, then there would be some ad-targeting... But I seriously doubt most customers are frequenting sites that are affiliated with their ISP. Of course, this knocks out Google, Yahoo, YouTube, Slashdot, ESPN, most newspapers, Hotmail, TinyURL, etc. as they really aren't affiliated with a specific ISP that could provide data for
    • Re: (Score:3, Informative)

      Neubud purchases ad space on tons of websites.. when the web page is requested, they check the requesting IP. If its on a network they "service" then they call up the cookie and the profile from the monitoring hardware at the ISP, and instead of displaying a static ad, display one targeted to your surfing habits. Then they give the ISP a chunk of change (or a percentage of ad revenue, not sure), for allowing them to have their monitoring/profiling tools installed at their access points.. The ads don't go
  • Great and grand until the the bastards grant them immunity for breaking the law again.
    Do you really think that the government is going to give this a pass so that ads can be sold? Fuck no. It's going to be used as another spying opportunity when they deem fit stating, "all that information is just sitting there, why don't you give us some so we can hunt bad guys."
    This will just be abused when they deem it necessary to incarcerate you for a longer period of time on some trumped up charge. 1984 is just that
  • All that will come out of this is when signing up for any broadband service, you will simply sign away your rights entirely.

    The gov doesnt give a shit if you're privacy is protected.

    To have service you will have to sign away all rights. Its that simple.

  • Forget ISP's for a moment, why not investigate media companies trawling other companies (Youtube) for data on what viewer viewed what video, and how often (trade secrets)... http://tech.slashdot.org/article.pl?sid=08/07/03/121221 [slashdot.org] .
    • by Tackhead (54550) on Tuesday July 08 2008, @06:00PM (#24107793)

      They're going to grant the telecoms immunity and the Bush Administration a free pass on breaking federal wiretap laws and violating the 4th Amendment, but *this* concerns them? Spare me.

      1970s: Don't steal. The government hates competition.
      2010s: Don't spy on your users. The government still hates competition.

      • "The Bush administration will make their life difficult if they investigate telecomm immunity."

        For six months? Does the phrase "lame duck" mean anything to you? All anybody that didn't support the immunity and wasn't complicit in it would have to do is run out the clock, and yet...