ISP Embarq Monitors User Traffic
Deli Korkmaz writes "The Washington Post reports that Sprint-Nextel spin-off Embarq, currently the US's fourth largest DSL provider, monitored Internet activity on some 26,000 customers in Kansas using deep-packet inspection technology NebuAd in order to deliver targeted advertising to users' desktops. CNet provides coverage as well. The House of Representatives Committee on Energy and Commerce is investigating whether any privacy laws were broken. Users were informed of this test and invited to opt out only via Embarq's online Privacy Policy; a mere 15 subscribers did so."
If we can get web servers to support TLS (for multi-domain encryption on a single IP vs. SSL), and create a non-identity framework for encryption, we should just start encrypting everything end to end. ISPs are asking for it with these behaviors.
...because the opt out was buried in a 5000 word privacy policy. If anything, this story should lead the house to realize that merely posting a privacy policy on your website doesn't mean the customers are bound by it especially in terms of rights, privacy and willingness to be subjected to monitoring merely for advertising sake.
~ Ron Fitzgerald
Disclaimer: I am an Embarq employee.
It was used to better target the advertisements on MyEmbarq.com and on the DNS redirection pages for server not found. If there was any more past that, then the general work force was not aware of it. No modifying of pages or redirecting others' advertisements.
This system would only work if you used Embarq's DNS servers.
If they are using the NebuAd services, it IS both deep packet inspection and inserting javascript in all pages.
The fact that it uses the information it gathers to give better targeted ads on your DNS redirection (a separate kind of internet breaking evil you should be ashamed of, BTW) is just gravy.
You as an employee have only received half the story, and it makes it sound a whole lot better that way.
Wikipedia's article on NebuAd will give you some of the real scoop, but it gets worse the more you find out about it..
http://en.wikipedia.org/wiki/NebuAd
Blessed are the pessimists, for they have made backups.
I might go along with the Insightful were it not for the gratuitous (and most likely inaccurate) use of "middle America." There are a number of things wrong with this:
1) I can think of a lot of places in world (having lived there) where people are at least as technologically clueless as the average American. There is nothing special about Americans - either positive or negative - in that regard;
2) If you meant "middle" as in "middle class" you missed. The most technologically clueful income strata in America is most likely the middle class. One of the things that keeps the poor in poverty is lack of clue combined with means to acquire it; rich people, on the other hand, have middle class people who are paid to do all that stuff for them, and thus don't acquire clue about computers unless they are very interested in them or were once middle class;
3) If you meant "middle" as in "geographic center" it is still likely that you missed. Even in the Silicon Valley area, where I live, computer cluefulness remains largely the province or those who are in the industry or who are computer enthusiasts on their own. Everyone else is as clueless as they are everywhere else. Those who aren't clueless are, again, mostly in the middle class.
If you'd written that the majority of people (everywhere) are unaware, I might have spent one of my remaining mod points to mod you up. As it is, I was tempted to use to mod you troll, but decided to take the time to explain why I consider your post a troll instead.
tom.gerke@embarq.com was the contact for the CEO back in March. I assume it is still legitimate...
Weird slashbug #455
Please be careful with the terminology.
Opt-out means that you're in and you have to opt-out to stop your membership/subscription/whatever.
Opt-in is what you want: it's your choice to subscribe/join/whatever, and if you don't, there is no membership/subscription/whatever.
For example: The do-not-call list is an opt-out scheme. Unless you take action and put your name on the list, they're allowed to call you. Most newsletters are opt-in: You only receive the newsletter if you subscribe. Spam is neither opt-in nor opt-out: You get spam without doing anything. If you try to opt-out, you get more spam.
Whenever you have to search long and hard to find new 'features', this can only mean one of several things:
Even more on-topic are these quotes from the Wiki article (provided by spinkham above):
According to Nebuad's sales pitch less than 1% of users opt-out. One ISP expects to earn at least $2.50 per month for each user (..) Generally, NebuAd provides an additional income stream to network operators, which may maintain or lower consumers' internet access bills.
As we've all known for a long time, ordinary people's surfing habits are worth money. What when you'd ask people up front: "Do you want your surfing habits to remain private, or give up this privacy in exchange for a discount?"
I'm afraid the vast majority of people would go for the discount. The anything-connected-to-everything world of today has gotten us so used to data breaches and 'unknown parties' snooping through our private info, that we just don't seem to care anymore. Which seems strange: the less (privacy) you have left, wouldn't you value those last remains more than you used to?