Feeds

Phorm agrees to independent inspection of data pimping code

But what's a privacy group doing in bed with it anyway?

Boost IT visibility and business value

Phorm has agreed to allow an independent software expert to inspect its source code as it continues to battle the firestorm provoked by agreements with BT, Virgin Media and Carphone Warehouse to let it build profiles of their broadband customers' web browsing.

It seems a move by the battered firm to try to win some public trust. The identity of the scrutineer has not been decided, but according to Simon Davies, a privacy campaigner who has become embroiled in the controversy because of consulting work he has done for Phorm, it has to be someone universally respected in UK security circles. "Someone like Ross Anderson or Richard Clayton," he suggested.

Both are leading computer security researchers at the University of Cambridge.

Phorm has tried to deflect scrutiny of its Russian-developed code by emphasising that the profiling hardware will be administered by the ISPs. This has not satisfied web users and website adminstrators who have been up in arms over the technology for three weeks now. More than 7,000 have signed a Downing Street petition against the technology.

Davies, a London School of Economics researcher best known as the founder of the pressure group Privacy International, has come under increasing criticism for his commercial role in the Phorm affair. A Privacy Impact Assessment (PIA) by his consulting company, 80/20 Thinking, has been repeatedly cited by Phorm to defend its system, prompting questions over Privacy International's independence.

It hasn't helped that Phorm itself seems confused over whose opinion it has paid for in the PIA. When The Register first became interested in the story, we were told on more than one occasion that Privacy International itself had praised the technology.

"This could all have been handled much better," Davies said.

Yesterday evening, he personally released the PIA to the media. In it, 80/20 Thinking raises, but does not answer many of the questions that have fired the debate. It reads: "Can cookies lead back to users in any way? Of course it is merely a unique identifier but a unique identifier can still be linked to individuals.

"Can an external attacker gain access to the required information to re-link the individual and the unique identifier?"

The report is dated 10 February, and Davies has since praised the system. Defending himself against criticism on the influential UK-Crypto mailing list, he wrote: "For what it's worth, we do believe the company [Phorm] has created some extremely interesting and privacy friendly technology. And in my view the company has gone above and beyond the norm to expunge personal data from its system."

Boost IT visibility and business value

More from The Register

next story
Scotland's BIG question: Will independence cost me my broadband?
They can take our lives, but they'll never take our SPECTRUM
Trying to sell your house? It'd better have KILLER mobile coverage
More NB than transport links to next-gen buyers - study
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
NBN Co adds apartments to FTTP rollout
Commercial trial locations to go live in September
Samsung Z Tizen OS mobe is post-phoned – this time for good?
Russian launch for Sammy's non-droid knocked back
Telstra to KILL 2G network by end of 2016
GSM now stands for Grave-Seeking-Mobile network
Seeking LTE expert to insert small cells into BT customers' places
Is this the first step to a FON-a-like 4G network?
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.