Feeds

American data pimper exposes ad equation

26,000 tracked, 15 opt out

Boost IT visibility and business value

How much notice did American ISPs provide when testing NebuAd's Phorm-like behavioral ad targeter? Not as much as NebuAd CEO Bob Dykes would have you believe.

Responding to an open letter from three big-name US Congressman, Middle American ISP Embarq Corp. has admitted that before activating NebuAd's deep packet inspection hardware, it notified customers with no more than an update to its 5,000-word privacy policy.

Bob Dykes has always claimed that NebuAd's ISP partners provide "direct notice" to customers. Speaking to The Reg in April, he was adamant that a paragraph posted to an ISP's website or buried in its terms of service does not qualify as direct notification. And when he testified before Congress last week, he said that ISPs customers always receive an email or a letter or some extra words in their billing statements.

Of course, even these methods are less then adequate. As Ed Markey, chairman of the House Subcommittee on Telecommunications and the Internet, told Dykes during last week's Congressional hearing, NebuAd should always require an opt-in. In an effort to target online ads, NebuAd's deep packet inspection hardware tracks the search and browsing activity of web surfers from inside an ISP's network.

At one point during the hearing, Markey accused Dykes of "beating consumers." But Dykes insisted his system maintains user privacy by anonymizing IP addresses and offering an opt-out.

Earlier in the week, Markey and fellow Congressmen John D. Dingell (chairman of the House Committee on Energy and Commerce) and Joe Barton (ranking member of the House Committee on Energy and Commerce) fired a letter at the Kansas-based Embarq, demanding details on the NebuAd test it performed earlier this year. Since The Reg first contacted the company in April, it has openly acknowledged the test, but refused to give specifics.

As it turns out, Embarq tested the technology on about 26,000 broadband customers in Gardner, Kansas over the course of about two weeks. During that time, only 15 customers opt-ed out.

Chances are, most of the 26,000 didn't realize there was brand new language buried somewhere in the company's privacy policy.

Nonetheless, Embarq says it provided customers with adequate notice. "Embarq followed the prevailing industry practices of the most similar business model, that of online advertising networks, which also collect anonymous information across multiple unrelated web sites and use it to serve personalized display advertisements," the company explained this week in a letter to Markey, Dingell, and Barton.

But ordinary ad networks aren't tracking all your browsing activity from inside your ISP. In failing to require an opt-in, NebuAd and other behavioral ad targeters may run afoul of the Communications Act of 1934, the Cable Act of 1984, the Electronic Communications Privacy Act, and other wiretapping-related US statutes.

Of course, Embarq says it conducted its very own legal analysis of the situation, and the company has no doubt that an opt-out is enough.

It should be noted, however, that NebuAd's cookie-based opt-out isn't quite an opt-out. Ars Technica has spoken with a network engineer who's worked with NebuAd's hardware, and he confirmed that even if you opt-out, NebuAd continues to collect your browsing activity.

"When the user opts out, NebuAd does not collect the data on that user, and we do not serve targeted ads to that user," NebuAd has told us. "The data flowing through the system is immediately and permanently flushed out." The key words here are "data flowing through the system." Your info is still leaving your ISP for a third party. ®

Seven Steps to Software Security

More from The Register

next story
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Apple orders huge MOUNTAIN of 80 MILLION 'Air' iPhone 6s
Bigger, harder trouser bulges foretold for fanbois
Bring back error correction, say Danish 'net boffins
We don't need no steenkin' TCP/IP retransmission and the congestion it causes
GoTenna: How does this 'magic' work?
An ideal product if you believe the Earth is flat
Samsung Z Tizen OS mobe is post-phoned – this time for good?
Russian launch for Sammy's non-droid knocked back
Telstra to KILL 2G network by end of 2016
GSM now stands for Grave-Seeking-Mobile network
Seeking LTE expert to insert small cells into BT customers' places
Is this the first step to a FON-a-like 4G network?
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.