Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • YouTube Anti-Scientology Takedowns: Good News, Bad News
  • NSA Judge: 'I feel like I'm in Alice and Wonderland'
  • CIAS Hosts Second Annual National Collegiate Cyber Defense Competition
  • MySpace Quietly Fixes Bug that Gave Voyeurs Access to Teens' Private Photos
  • Comcast's Disappointing Defense
  • Google Online Security Blog: All Your iFrame Are Point to Us
  • Technology: Data mining - Fighting crime with databases

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

Opting In (or Out) is Hard to Do - Thoughts on implementing DPI

Submitted by MacRonin on October 7, 2008 - 12:31pm.
  • Activists
  • Anonymity
  • Companies
  • Data Mining
  • Databases
  • Editorial
  • Exploits
  • Hmmm
  • How-To
  • ID
  • Infrastructure
  • ISP - Internet Service Providers
  • Issues
  • Privacy
  • Remember
  • Rights
  • Security
  • Standards
  • Surveillance
  • Tracking

Opting In (or Out) is Hard to Do - Via Freedom to Tinker:

Thanks to Ed and his fellow bloggers for welcoming me to the blog. I'm thrilled to have this opportunity, because as a law professor who writes about software as a regulator of behavior (most often through the substantive lenses of information privacy, computer crime, and criminal procedure), I often need to vet my theories and test my technical understanding with computer scientists and other techies, and this will be a great place to do it.

This past summer, I wrote an article (available for download online) about ISP surveillance, arguing that recent moves by NebuAd/Charter, Phorm, AT&T, and Comcast augur a coming wave of unprecedented, invasive deep-packet inspection. I won't reargue the entire paper here (the thesis is no doubt much less surprising to the average Freedom to Tinker reader than to the average lawyer) but you can read two bloggy summaries I wrote here and here or listen to a summary I gave in a radio interview. (For summaries by others, see [1] [2] [3] [4]).

Two weeks ago, Verizon and AT&T told Congress that they would monitor for marketing purposes only users who had opted in. According to Verizon VP Tom Tauke, "[B]efore a company captures certain Internet-usage data for targeted or customized advertising purposes, it should obtain meaningful, affirmative consent from consumers."

I applaud this announcement, but I'm curious how the ISPs will implement this promise. It seems like there are two architectural puzzles here: how does the user convey consent, and how does the provider distinguish between the packets of consenting and nonconsenting users? For an ISP, neither step is nearly as straightforward as it is for a web provider like Google, which can simply set and check cookies. For the first piece, I suppose a user can click a check box on a web-based form or respond to an e-mail, letting the ISP know he would like to opt in. These solutions seem clumsy, however, and ISPs probably want a system that is as seamless and easy to use as possible, to maximize the number of people opting in.

Once ISPs have a "white list" of users who have opted in, how do they turn this into on-the-fly discretionary packet sniffing? Do they map white-listed users to IP addresses and add these to a filter, or is there a risk that things will get out of sync during dhcp lease renewals? Can they use cookies, perhaps redirecting every http session to an ISP-run web server first using 301 http status codes? (This seems to be the way Phorm implements opt-out, according to Richard Clayton's illuminating analysis.) Do any of these solutions scale for an ISP with hundreds of thousands of users?

And are things any easier if the ISP adopts an opt-out system instead?

(Read Original Article - Via Freedom to Tinker.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
  • China thinks twice – and its 300m internet users scent a rare victory
  • Did the Sanford E-Mail Tipster or the Newspaper Break the Law?
  • Supreme Court Serves Up Remote-Recording Victory
  • Deep-Packet Inspection in U.S. Scrutinized Following Iran Surveillance
  • ATM Vendor Halts Researcher’s Talk on Vulnerability
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.