Feeds

Data pimping catches ISP on the hop

Who ate all the cookies?

Beginner's guide to SSL certificates

What's the story with Phorm, NebuAd, and other behavioral targeting firms that track user data from inside the world's ISPs? In some cases, even the ISP can't tell you.

In February, the Silicon Valley-based NebuAd deployed its deep-packet inspection technology on a Middle America ISP known as WOW!, formerly WideOpenWest. The official word from NebuAd is that its partner ISPs are required to directly notify customers via letter or email before its hardware is turned on, but WOW! - America's 12th largest cable operator, serving Illinois, Michigan, and Ohio - says this did not happen on its service.

According to vice president of programming Peter Smith, WOW! updated its terms of service to include a mention of NebuAd, and in some cases, it told customers that the terms had been updated. But it didn't go any further.

"We started rolling out the service in February and we completed the roll-out the first week in March," Smith told us. "About the third week in March, we got an updated memorandum from NebuAd detailing their 'best practice' standards. That was not provided before we rolled the service out.

"When we got the memorandum, we put together a plan to comply with the best practices, and we're in the process of doing that right now, sending customers an email that explicitly alerts them to NebuAd and providing messages on bills."

At least two WOW! customers argue that the ISP's initial notification was not enough. Both of these Chicago-area customers were unaware that NebuAd was tracking their behavior until some unexpected Web cookies turned up on their machines. When they visited Google, non-Google cookies were being read by addresses such as "nebuad.adjuggler.com."

When these users contacted WOW! customer support, reps initially denied that the ISP was responsible for the cookies. So these customers did some digging on their own, eventually turning up the NebuAd mention in WOW's terms of service. Only then did reps confirm that NebuAd was a partner.

Someone else's cookies

When we contacted WOW! to discuss the matter, VP Peter Smith initially denied that NebuAd uses tracking cookies. "There's been a lot of rumors out there are not correct," Smith told us. "NebuAd doesn't drop cookies, so those were someone else's cookies." When pressed, Smith then said that NebuAd only drops a cookie when users opt-out of the service.

But NebuAd makes no bones about the fact that it drops cookies from the get-go. "We place just one cookie for each NebuAd ad-serving domain," said NebuAd CEO Bob Dykes. "It usually contains just an alphanumeric, which is not the number we use internally to identify the user anonymously, and some ad-serving related info such as ad frequency caps, which is similar to functionality used by almost all ad networks in their cookies. If the user opts out, then that is noted in the cookie and the alphanumeric is deleted."

Peter Smith negotiated WOW!'s contract with NebuAd, but he said that these negotiations carried on for months and that NebuAd's practices may have changed since the two companies first spoke.

NebuAd's behavior-tracking service is similar to ISP-based services used by Phorm in the UK and Front Porch here the US (though Front Porch shares its data with outside ad firms). Other operations that appear to be working on similar services include Adzilla and Project Rialto, a "stealth company" created by Alcatel-Lucent, but these firms did not respond to our interview requests.

According to NebuAd, its current ISP contracts give it access to the search and browsing activity of at least 10 per cent of American net surfers. It then uses this data to target advertisements.

NebuAd insists the data is never matched to personally identifiable information. But many - including the Center of Democracy and Technology - believe that end users should be actively notified before these services start tracking their behavior and given every opportunity to opt-out.

Security for virtualized datacentres

Next page: NebuAd aka Nebula

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Blockbuster book lays out the first 20 years of the Smartphone Wars
Symbian's David Wood bares all. Not for the faint hearted
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
This flashlight app requires: Your contacts list, identity, access to your camera...
Who us, dodgy? Vast majority of mobile apps fail privacy test
Apple Watch will CONQUER smartwatch world – analysts
After Applelocalypse, other wristputers will get stuck in
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.