AOL: We're Not Spying on AIM Users
The Llama King writes "America Online tells the Houston Chronicle's TechBlog that, despite a recent Slashdot posting to the contrary, AOL Instant Messenger's terms of service do not imply that the company has the right to use private IM communications, and the section quoted in the Slashdot article applies only to posts in public forums -- a common provision in most online publishers' terms of service. AOL spokesman Andrew Weinstein says flatly: 'AOL does not read person-to-person communications.' He also says AIM communiques are never stored on AOL's hard drives. The original Slashdot item was linked throughout the blogosphere -- it will be interesting to see if AOL can extinguish this fire." (Read more below.)
It could be that they don't actually take advantage of its terms, but the Terms of Service seem to broadly favor AIM's right to do exactly what they say they're not doing; rather than drawing any distinction between IM services and public forum posts, the actual terms seem clearly to apply to all AIM products. Here's how they put it:
For purposes of these Terms of Service, the term "AIM Products" shall mean AIM software (whether preinstalled, on a medium or offered by download), AIM services, AIM websites (including, without limitation, AIM.COM and AIMTODAY.COM) and all other software, features, tools, web sites and services provided by or through AIM from America Online, Inc. and its business divisions (e.g., Netscape) (collectively "AOL") and AOL's third-party vendors.AOL could probably erase many of the worries about conversation snooping if they would provide a definition of the words "post" and "submit" as used in the following paragraph of their ToS (which says it applies to "any AIM Product"), and explicitly disclaimed an "irrevocable, perpetual, worldwide right to reproduce, display, perform, distribute, adapt and promote" the contents of online conversations:
You may only post Content that you created or which the owner of the Content has given you. You may not post or distribute Content that is illegal or that violates these Terms of Service. By posting or submitting Content on any AIM Product, you represent and warrant that (i) you own all the rights to this Content or are authorized to use and distribute this Content on the AIM Product and (ii) this Content does not and will not infringe any copyright or any other third-party right nor violate any applicable law or regulation.
"We're not evil. We promise. Trust us. Just because we say we can doesn't mean we will."
I personally use AIM but that doesn't mean that I'm going to trust any communications I want private with a giant multi-billion company.
I'm a virgo and on Slashdot. Coincidence? Yes.
I already uninstalled my AIM and done gone somewhere else with my IMing.
Their PR parrots and Legals should have collaborated BEFORE they opened their big mouths on this matter. Now they are having to play catchup, in a BIG way.
Bad timing aoHell. In this day and age, that kind of legal play can lose you a couple of million users as fast as your CSRs (customer service reps) can field them.
First rule of holes; When in one, stop digging.
Why are people walking around surprised that AOL would, at the very least, not guarantee absolute privacy in conversation?
The best way to deal with this is to always treat any conversation, ESPECIALLY over the internet, and ESPECIALLY on a service like AIM as insecure. Period.
Everyone and their mother who read that previous Slashdot anti-privacy post will of told ten people. Everyone who reads this one, will probably forget about it in ten minutes and revert back to thinking AOL is logging all of your chats. Damage is done.
-Imidazole
Hilarious Office Prank!
Once again a big hoopla is created over a bunch of Slashdot idiots NOT READING THE FAWKING ARTICLE or doing anything other than shallow psuedo-research!
Of course, if it's on SlashDot, it must be true!
This is another case of agreements being way beyond what a company needs, but lawyers saying "well what about this one bizarre case that might happen once in a hundred years where you might want to use this clause?" So the company makes an agreement like this one, not counting on geeks like us to actually read it and cause trouble.
Companies exist only to enrichen their owners and shareholders. All decisions are based on this one fundamental truth.
If they have the authority to do something, and it becomes in the company's best interest to do it, they will do it, without hesitation.
Translating what they are saying now, it just means "it's not currently in AOL's overall best interest to monitor instant messaging traffic, so right now we're (probably) not doing it. But we can change our minds at any time, without notice."
I work for the Department of Redundancy Department.
Lets be honest if the service is free to you in a monetary sense, it's nice to think that there are no other costs to you. I'm not a nut in a shelter somewhere in the tundra - but a little paranoia can be healthy. I have met and worked for enough companies/individuals to know that altruism does not currently stand as the dominate principle in business. (though, evolution of society...OSS...who knows what will happen) It's just common sense to assume that there are hidden strings attached to something given to you for "free" from a corporation (and most individuals, even you grandma). I never buy anything on my Super Saver Card that I don't want the Super Saver Company to know about, and I treat AIM/MSN/Hotmail/Whatever the same way. If I want a private conversation I use something I can control - Point to point with encryption.
The rock, the vulture, and the chain
Eh? Encryption isn't the solution to end users logging conversatations in their IM client.
This issue relates to the main central servers eavesdropping on EVERYONEs conversations.
Encrypting the conversation should prevent eavesdropping on route, but won't prevent logging in the client.
liqbase
"The original Slashdot item was linked throughout the blogosphere -- it will be interesting to see if AOL can extinguish this fire."
I would think it would be fairly easy to put out the fire. Instead of making the assurances below in public, put them in the TOS in an invariant section.
"AOL Instant Messenger's terms of service do not imply that the company has the right to use private IM communications, and the section quoted in the Slashdot article applies only to posts in public forums -- a common provision in most online publishers' terms of service. AOL spokesman Andrew Weinstein says flatly: 'AOL does not read person-to-person communications.' He also says AIM communiques are never stored on AOL's hard drives."
all the best,
drew
FreeMusicPush If you want to see more Free Music made, listen to Free
The fact that they now say they're not monitoring, does not covince me that the TOS weren't intentionally vague.
C'mon, people. AOL has better things to do than monitor people talking to their internet girlfriends. What possible benefit could it serve? I mean really, if you're doing something over AIM where privacy is a serious concern, you're probably not too bright in the first place (and by the way, I'm from your bank - we seem to have lost your account information). What do you thinks gonna happen - someone on AIM mutters the word "ICQ" and instantly hundreds of America OnLine programmers come bursting through your door with free AOL discs?
(insert conspiracy nuts claiming that they can install monitor programs for the FBI/NSA/PETA. Also include the people who will claim that this is the first rights infringement on the path to a corporate controlled world where Pepsi can recruit you into slavery and Bed Bath and Beyond owns your house because you "Just had to have that towel rack")
yeah, let's make a big deal of someone reading our IMs but totally forget that email can be read too. Here's an idea...don't write anything online that you wouldn't want publiched. Problem solved.
That said, I doubt AOL employees really care about your fucking IMs.
xXx-@DeathBecomesME@-xXx: LOL
supertard: heh
xXx-@DeathBecomesME@-xXx:dude, did you see that one show? LOL
supertard: yeah lollerz!1
*rolleyes* who fucking cares if they read your chat logs?
It isn't security through obscurity, it's security through absurdity.
http://xkcd.com/386/
in gaim encryption is done client>client, the server doesn't get anything readable because the protocol doesn't support it.
"In each such case, the submitting user grants OSDN the royalty-free, perpetual, irrevocable, non-exclusive, transferable license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform, and display such Content (in whole or part) worldwide and/or to incorporate it in other works in any form, media, or technology now known or later developed, all subject to the terms of any applicable license." - Thus go the TOS of slashdot.org. Surprize, surprize!
I tried to submit this story to ./ sometime back but of course, they wont accept it :-)
Gaim Encryption plugin Use gaim, use plugin. Give friends, etc. an ultimatum. I strongly encourage the use of this in more sensitive environments, especially if you're slinging account numbers around.
This message brought to you by the letter Q and the number 8.
but personally, I don't want to worry about some third party reading through posts or messages not intended for them. To remedy this problem, I recommend grabbing GAIM with one of the many GAIM encryption plugins. As a bonus, paranoid folks won't have to worry about the (insert governmental agency of choice) snooping on them.
4 .exe?download
More information regarding this topic is available on the technology blog "It's Geek to Me" located at http://itsgeektome.blogspot.com/
For Windows users, you can grab GAIM here:
http://prdownloads.sourceforge.net/gaim/gaim-1.1.
You can get a nice GAIM Encryption Plugin here:
http://gaim-encryption.sourceforge.net/
I read the TOS, and concluded it was just a case of lawyeritis (inflammation of the lawyers). The actual intent seems to be to establish that AOL shall NOT be held liable for copyright infringement due to copyrighted material (specifically meaning words written *by* AIM users) being passed through their servers.
So if you write something and send it via AIM, you have given AOL the right to "reproduce" it on their servers, and therefore you cannot sue AOL for copyright infringement, nor can you claim that AOL owes you anything for "distributing" it. (However, this does not *assign* the copyright to AOL.)
IOW, it's just overly-paranoid ass-covering as performed by lawyers, probably due to some asshole having actually sued them for "storing my works on your server and thereby infringing my copyright" (even if that's just for the few seconds as it passes through) without grokking that this is how sending stuff via AIM works.
[I can readily see someone like Harlan Ellison going off the deep end about this natural side effect of transmitting data, thus getting the lawyers in a tizzy.]
~REZ~ #43301. Who'd fake being me anyway?
You have to love the panic mongers. If you have a deep, dark secret, don't shout it in a public place, don't share it on a public network. It just takes a bit of common sense. Yeah, they could monitor me, but is there anything that they'd want to know?
Then there is the logistics of the matter. I know that they could filter out 99% of my conversations. I know many people like myself who just leave their chat clients up as a sort of answering machine or phone replacement. If you have a potentially sleeping baby in the house, or are working on a vexing problem from which you cannot be distracted, ringing the phone for minor things is considered rude. IM is a safe, quiet conversation. I can speak to a friend, and come off as semi-articulate and intelligent, and they can't hear me yelling at my 4 kids in the background.
A typical conversation of mine:
Of course, "pick up bread" is code for pseudo ephedrine, coffee filters, drain cleaner, ether....
People can intercept your email too, so what? The implementation of Martial Law, oh, I mean The Patriot Act, has extended the government's wire tap privileges further into the phone system, with less and less of a reason needed. What about the security of cell phones? And how many of these panic mongers don't think twice before using a regular cordless phone at home. I can tell you from experience that these are not secure! I had to quit using a baby monitor, as I was sick of listening to my neighbor's late night drunken sobs to her friends about her husband. Hmm, the things that you learn when you listen to people's private calls. That was a morbid fascination for a short time, but it wore off quickly.
Much of it comes down to the fact that monitoring most people's communication would be a crashing bore. Sure, you could write content filters, as you do for spam detection, but how many false negatives, and how many false positives do you have with that? I'd expect the same level of difficulty monitoring IM's
IM is great for jotting off a few thoughts. It's not for exchanging company secrets. If you want to do that, at least use a private network, or better yet, meet in person. IM is great for multi-tasking. As you sit on hold, or buried in the 7th level of voice mail hell, you can carry on a conversation, or give and get tech support. "What was the command to fix that problem on my machine again?" copy, click, paste, Fixed! "Thanks again!" Do you realize how much easier that former scenario is than saying "Pipe, that straight line, on the key over the enter key, do you see it? It didn't work? Did you hit shift? Is the line vertical, or slanted?...(continue ad infinitum)"
With IM, you can, potentially help multiple people at one time as well. (All while playing a game of whatever keeps you from slitting your wrists on a daily basis.) As your minions actually attempt to execute what you have given them, there is invariably some time wasted. If you were on the phone with them, you'd have to hang on while they check to see if the fix worked. This way, they are still in your que, and yet you can move on to someone else.
There is also another great element to IM on a public server, with public profiles. People can, if they wish, put things in their public profile that would bring together people with like interests from around the world. I have developed many online friends due to one common interest or another listed on a public profile. Sure, for the