Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

ISP Secretly Added Spy Code To Web Sessions, Anyone with BT?

Thread Tools
 
Search this Thread
 
Old 06 June 2008, 12:21 PM
  #1  
Dedrater
Scooby Regular
Thread Starter
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default ISP Secretly Added Spy Code To Web Sessions, Anyone with BT?

Leaked Report: ISP Secretly Added Spy Code To Web Sessions, Crashing Browsers | Threat Level from Wired.com

Leaked Report: ISP Secretly Added Spy Code To Web Sessions, Crashing Browsers
By Ryan Singel June 05, 2008 | 5:43:36 PMCategories: Network Neutrality

An internal British Telecom report on a secret trial of an ISP eavesdropping and advertising technology found that the system crashed some unsuspecting users' browsers, and a small percentage of the 18,000 broadband customers under surveillance believed they'd been infected with adware.

The January 2007 report (.pdf) -- published Thursday by the whistle blowing site Wikileaks -- demonstrates the hazards broadband customers face when an ISP tampers with raw internet traffic for its own profit. The leak comes just weeks after U.S. broadband provider Charter Communications told users it would be testing a technology similar to what's described in the BT document.

The report documents BT's partnership with U.K. ad company Phorm, which specializes in building profiles of ISP customers, then serving targeted ads on webpages the user visits.

From late September to early October 2006, British Telecom secretly partnered with Phorm to let the company monitor and track 18,000 of the BT's customers. Phorm installed boxes on BT's network that redirected web requests through their proxy server.

Those boxes inserted JavaScript code into every web page downloaded by the users. That script then reported back to Phorm the contents of the web page, which Phorm used to create ad profiles of a user. Additionally, Phorm purchased advertising space on prominent web sites, showing a default ad for a charity. But when a user who had previously looked at car sites visited one of those pages, he instead got an advertisement for car insurance.

The users were not informed they were being made guinea pigs for a new revenue system for BT and had no way to opt out of the system, according to the report. The JavaScript caused flickering problems for some users as the script reported back information about the content of the web page to a Phorm server. The script also crashed browsers that loaded a website that relied excessively on anchor tags. Additionally, the rogue JavaScript showed up unexpectedly in user's posts to some web forums.

Despite these problems, the technical assessment concluded the test was successful and was largely went unnoticed by most users.

The operation of the system does have noticeable side effects, which included web-page tag insertion and navigation bar flutter.

From the postings, no user correctly determined the source of these effects and users did not post that the system was causing poor performance.

However all postings suspected that their machines had a virus, a malware or a spyware infection.

Neither Phorm nor BT returned calls seeking comment on the document.

The U.S.'s fourth largest ISP, Charter Communications, is set to test out technology similar to Phorm's in the coming weeks using a U.S.-based company called NebuAd. After Charter sent out notice of the test to customers, two influential members of the U.S. House of Representatives asked the company to postpone the test, citing possible violation of privacy laws.

Congressman Ed Markey, who chairs a powerful telecom oversight subcommittee, is planning to meet with company representatives next week, according to a spokeswoman.

Charter's partner, NebuAd, claims to have have applied for a patent for its technology to let users opt-out of having their web sessions eavesdropped on and categorized, but the only patent applied for under its name is one that replaces ads on third-party websites with ads of their own.

BT's secret test first came to light when one suspicious user contacted The Register about the problem. At the time, BT denied any involvement, though the company later admitted it had run a secret test and planned to expand the monitoring technology to its entire network.

The newly released documents confirm a further report in The Register in April about the extent of the secret test.
Disturbing, BT
Old 06 June 2008, 03:04 PM
  #2  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

has been covered in the register for weeks
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Darrell@Scoobyworx
Trader Announcements
26
30 January 2024 01:27 PM
Rbon91
ScoobyNet General
49
21 November 2018 03:23 PM
Sam Witwicky
Engine Management and ECU Remapping
17
13 November 2015 10:49 AM
south_scoob
ScoobyNet General
22
03 October 2015 01:05 PM
Wurzel
Computer & Technology Related
10
28 September 2015 12:28 PM



Quick Reply: ISP Secretly Added Spy Code To Web Sessions, Anyone with BT?



All times are GMT +1. The time now is 04:24 PM.