Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • Reform The PATRIOT Act: Stop Abuse of National Security Letters
  • RIAA Going After a 10-Year-Old Girl
  • Sued By Craigslist, South Carolina’s Top Cop Declares Victory and Goes Home
  • Concerns Over Microsoft's Internet User Profiling
  • Employee profiling: A proactive defense against insider threats
  • Pentagon Seeks a New Generation of Hackers
  • EA's Spore Spawns on BitTorrent

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

Bad Phorm on Privacy

Submitted by MacRonin on April 3, 2008 - 3:07pm.
  • Activists
  • Advertising
  • Alert
  • Anonymity
  • Companies
  • Data Mining
  • Databases
  • Editorial
  • Europe
  • Hmmm
  • Infrastructure
  • ISP - Internet Service Providers
  • Privacy
  • Remember
  • Spin Zone
  • Surveillance
  • Tracking

Bad Phorm on Privacy - Via Freedom to Tinker:

Phorm, an online advertising company, has recently made deals with several British ISPs to gain unprecedented access to every single Web action taken by their customers. The deals will let Phorm track search terms, URLs and other keywords to create online behavior profiles of individual customers, which will then be used to provide better targeted ads. The company claims that “No private or personal information, or anything that can identify you, is ever stored - and that means your privacy is never at risk.” Although Phorm might have honest intentions, their privacy claims are, at best, misleading to customers.

Their privacy promise is that personally-identifiable information is never stored, but they make no promises on how the raw logs of search terms and URLs are used before they are deleted. It’s clear from Phorm’s online literature that they use this sensitive data for ad delivery purposes. In one example, they claim advertisers will be able to target ads directly to users who see the keywords “Paris vacation” either as a search or within the text of a visited webpage. Without even getting to the storage question, users will likely perceive Phorm’s access and use of their behavioral data as a compromise of their personal privacy.

What Phorm does store permanently are two pieces of information about each user: (1) the “advertising categories” that the user is interested in and (2) a randomly-generated ID from the user’s browser cookie. Each raw online action is sorted into one or more categories, such as “travel” or “luxury cars”, that are defined by advertisers. The privacy worry is that as these categories become more specific, the behavioral profiles of each user becomes ever more precise. Phorm seems to impose no limit on the specificity of these defined categories, so for all intents and purposes, these categories over time will become nearly identical to the search terms themselves. Indeed, they market their “finely tuned” service as analogous to typical keyword search campaigns that advertisers are already used to. Phorm has a strong incentive to store arbitrarily specific interest categories about each user to provide optimally targeted ads, and thus boost the profits of their advertising business.

The second protection mechanism is a randomly-generated ID number stored in a browser cookie that Phorm uses to “anonymously” track a user as she browses the web. This ID number is stored with the list of the interest categories collected for that user. Phorm should be given credit for recognizing this as more privacy-protecting than simply using the customer’s name or IP address as an identifier (something even Google has disappointingly failed to recognize). But from past experience, these protections are unlikely to be enough. The storage of random user IDs mapped to keywords mirroring actual search queries is highly reminiscent of the AOL data fiasco from 2006, where AOL released “anonymized” search histories containing 20 million keywords. It turned out to be easy to identify the name of specific individuals based solely on their search history.

In the least, the company’s employees will be able to access an AOL-like dataset about the ISP’s customers. Granted, distinguishing whether particular datasets as personally-identifiable or not is a notoriously difficult problem and subject to further research. But it’s inaccurate for Phorm to claim that personally-identifiable information is not being stored and to promise users that their privacy is not at risk.

(Read Original Article - Via Freedom to Tinker.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
  • China thinks twice – and its 300m internet users scent a rare victory
  • Did the Sanford E-Mail Tipster or the Newspaper Break the Law?
  • Supreme Court Serves Up Remote-Recording Victory
  • Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
  • ATM Vendor Halts Researcher’s Talk on Vulnerability
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.