Feeds

Phorm agrees to independent inspection of data pimping code

But what's a privacy group doing in bed with it anyway?

5 things you didn’t know about cloud backup

Phorm has agreed to allow an independent software expert to inspect its source code as it continues to battle the firestorm provoked by agreements with BT, Virgin Media and Carphone Warehouse to let it build profiles of their broadband customers' web browsing.

It seems a move by the battered firm to try to win some public trust. The identity of the scrutineer has not been decided, but according to Simon Davies, a privacy campaigner who has become embroiled in the controversy because of consulting work he has done for Phorm, it has to be someone universally respected in UK security circles. "Someone like Ross Anderson or Richard Clayton," he suggested.

Both are leading computer security researchers at the University of Cambridge.

Phorm has tried to deflect scrutiny of its Russian-developed code by emphasising that the profiling hardware will be administered by the ISPs. This has not satisfied web users and website adminstrators who have been up in arms over the technology for three weeks now. More than 7,000 have signed a Downing Street petition against the technology.

Davies, a London School of Economics researcher best known as the founder of the pressure group Privacy International, has come under increasing criticism for his commercial role in the Phorm affair. A Privacy Impact Assessment (PIA) by his consulting company, 80/20 Thinking, has been repeatedly cited by Phorm to defend its system, prompting questions over Privacy International's independence.

It hasn't helped that Phorm itself seems confused over whose opinion it has paid for in the PIA. When The Register first became interested in the story, we were told on more than one occasion that Privacy International itself had praised the technology.

"This could all have been handled much better," Davies said.

Yesterday evening, he personally released the PIA to the media. In it, 80/20 Thinking raises, but does not answer many of the questions that have fired the debate. It reads: "Can cookies lead back to users in any way? Of course it is merely a unique identifier but a unique identifier can still be linked to individuals.

"Can an external attacker gain access to the required information to re-link the individual and the unique identifier?"

The report is dated 10 February, and Davies has since praised the system. Defending himself against criticism on the influential UK-Crypto mailing list, he wrote: "For what it's worth, we do believe the company [Phorm] has created some extremely interesting and privacy friendly technology. And in my view the company has gone above and beyond the norm to expunge personal data from its system."

Secure remote control for conventional and virtual desktops

More from The Register

next story
6 Obvious Reasons Why Facebook Will Ban This Article (Thank God)
Clampdown on clickbait ... and El Reg is OK with this
So, Apple won't sell cheap kit? Prepare the iOS garden wall WRECKING BALL
It can throw the low cost race if it looks to the cloud
EE fails to apologise for HUGE T-Mobile outage that hit Brits on Friday
Customer: 'Please change your name to occasionally somewhere'
Time Warner Cable customers SQUEAL as US network goes offline
A rude awakening: North Americans greeted with outage drama
We need less U.S. in our WWW – Euro digital chief Steelie Neelie
EC moves to shift status quo at Internet Governance Forum
BT customers face broadband and landline price hikes
Poor punters won't be affected, telecoms giant claims
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.