No privacy rules needed: ISPs say Web browsing isn’t “sensitive” data
arstechnica.com
arstechnica.com
Looking for other's thoughts...
Want to send a mail from home, as should be the norm? First, you need to get through your ISP's firewall. Many block the outgoing SMTP port, and there is nothing you can do about it. Others forbid you to use that port by contract. Some offer an SMTP relay to compensate, but then you're no longer sending your own email. Plus, they often limit you to 40 emails per day or so, and can spy on you, TLS or no.
Once your mail is sent, it has to pass through spam filters, and they all blacklist residential IP addresses.
This is even worse than manually spying on people: automation gives leverage. Now all we have to do is repurpose these targeted ad engine to deduce things other than buying preferences.
Sure, they have their surface ethic (and Alphabet's employees have their actual ethic), but the tools they have in place for total surveillance is downright chilling.
I don't know what point you're trying to make. Are you assuming everyone uses Google's webmail interface or their apps? Maybe those blur the lines of classic Internet email delivery but when I use Mail.app to send an email, I am the one doing the emailing, not the Google SMTP server acting as a mail transfer agent (MTA).
> Many block the outgoing SMTP port
Comcast doesn't, Time Warner doesn't, Verizon doesn't. My hunch is the large majority of U.S. residential ISP customers can connect to an SMTP server other than their ISP's.
You seem to be confusing the MSA (https://en.wikipedia.org/wiki/Mail_submission_agent) and the MTA. If today your MUA (Mail.app) tried to connect to the destination mail host via SMTP directly it would get rejected. Some early MUAs did actually do that, but today almost all email gets relayed via an MSA and one or more MTAs.
Your MUA would be rejected if it acted as an MTA and connected on port 25 without authenticating. "Using the same host as me" is the case because the mail server knows that it is "your host" because your MUA is connecting to your email server's MSA using SMTP AUTH on port 587 or 465.
In my book, "sending your own email" means you operate your own mail server, without using any third party relay (not Gmail's, not your ISP's).
I'm personally halfway there: I have root access to a virtual machine on the cloud (gandi.net), and configured it to relay my email for me. Next step would be to have physical control, but I kinda abandoned that idea when I learned that residential IPs are blacklisted (Hotmail even made it an explicit policy, it won't even appear in the recipient's spam folder).
Virtually no one else reads that book. To everyone else, the user operating the MUA is sending their own email.
Also, they control your right to send and receive email: if your account is terminated for some reason (they reserve the right to, blah, blah), you cannot move to a new provider, or redirect inbound mail or nothing: they own your email address.
Still think your send your own email? Fool.
Besides, there's more to it than (in)security. For instance, what happens to your various accounts tied to your email if your account gets terminated? You will not be able to redirect your incoming emails, and notifying your friends will be difficult if you relied on the web interface's address book.
Also, it's a hole ecosystem: if you use a big webmail, then you allow your provider to spy on everyone you exchange emails with. If you have the means to avoid those, it is your responsibility to do so. Surely you don't like inflicting this kind of spying on your friends, do you?
So far, the only reliable way to have proper control over our own email is to control our own domain name, and operate our own mail server. Or at least use small, trustworthy providers. In other words, "send our own email".
It's intellectual property/monopoly all over again. One will chose the terms that suits one's side of the debate. I side for privacy, security, and reliability; and argue that webmail providers do not provide any of them. This thread is the first time my "sending one's own email" wording hasn't been an unmitigated success.
The issue here is one of control: relays can basically read every mail they relay, and the likes of Gmail do. Spying on you is how they make money. No targeted ad would be possible otherwise. And the automation only makes it worse (because it scales, and can be repurposed).
And the user can do nothing about it. That total lack of control is why I maintain they do not, in fact, send their own email. Now there's PGP, but that would look conspicuous. If everyone had their own mail server, TLS alone would provide pretty good security.
What angers me the most is, even I don't have a choice: most of my friends use a big webmail provider, which invades my privacy whenever I communicate with them. This would never happen if we all had our own mail servers.
Also, it doesn't hide the authenticated user, envelope mail from or envelope rcpt to values used in the message, unless, like you said, the sender and recipient(s) are using their own SMTP servers.
I run my own mail server. When I send an email via the web interface, would you not agree the MUA is attempting to directly connect to the destination host?
Depending on different factors, it may be classified as spam by the recipient, but from a reputable IP address it shouldn’t normally be rejected outright. Of course there are other factors like SPF, greylisting, etc... but email can be directly delivered.
But if that happened and then the HHS decided to pursue it, the ISP would claim they're simply a conduit for PHI and that the privacy rule doesn't apply.
If the ISP wants to "simply be a conduit", I can only applaud, as long as they follow the rules of common carriers they just implied by saying so: no snooping, no filtering, no selective throttling, no looking at TCP packets to look for a "25" (SMTP requests) and block them…
If they do that, they don't have to follow any privacy rule: they already respect mine.
Sometimes I just want unmolested water.
[0] http://www.dw.com/en/experts-on-drug-wastewater-analysis-say...
These are classist policies and should be illegal. It is not OK in a civil society to say privacy is a product people buy, rather than a right.
[1] patient is probably the wrong term here, without a doctor/nurse directly involved
Your ISP would not be a covered entity.
If we assume that webmd.com would count as a "health care provider" (probably a questionable assumption) that would not be enough to get your ISP covered as a "business associate". Googling turns up rulings that ISPs are not HIPAA "business associates" when a patient uses them to reach a provider.
[1] https://www.hhs.gov/hipaa/for-professionals/covered-entities...
(Scanning the data is done on government level so I won't even bother to mention it)
The survey might have been a DNS redirect instead as by the time I noticed I had already navigated away from the original page and that was one of my few machines that can sometimes use my ISP's DNS. The emergency message test was HTML/Javascript directly injected into a random non-encrypted page I had loaded.
> "Web browsing and app usage history are not 'sensitive information,'" CTIA said
I wonder if they might feel differently if someone hacked them or their ISP and posted a month's worth of traffic logs, etc., for the public to see.
Maybe if the Internet histories of a handful of the top-level folks at these organizations were shared with the world (along with their identities, of course), they would change their mind.
Since the ISPs are planning to sell that personal information, it sure seems commercially valuable. It's a shame that, instead of ISPs simply not being dicks (er, "unlocking value"), we will have to waste time and money to encrypt everything and route it through TOR.
Using a simple free VPN to encrypt your traffic is enough. This does not cost time or money. Neither does TOR.
You shouldn't trust your ISP to not be collecting your information in either case. Even if they say they aren't spying on you that does not mean they should be trusted with any of your plaintext data.
You prefer taking your logs away from the potentially-prying eyes of regulated ISPs and giving them to an unknown, unregulated person? Free VPNs are a medicine that's--at best--only as bad as the malady.
Two gems from the rant are, "You actually don't need to be open-minded about Oracle," and "Don't anthropomorphize the lawnmower."
If so, then why should AT&T get a pass for repeatedly snooping and recording my activity?
ISPs are telecommunication providers and bound to special secrecy, disclosing browsing history is punishable by criminal law (§ 88 TKG in Germany).
Cambridge Analytics showed us, how dangerous it is for democracy to know users habits, values, attitudes, preferences and their contact details and how easy it is to manipulate individuals.
US-Americans, you seriously need to wake up and get your democracy back before your society is to Orwellian.
Also, you are giving a bad example. And stop cheering USA USA USA, your society is malformed and dysfunctional, you shouldn't be proud of it and lie to your self about it.
/s
> Web browsing and app usage history are not “sensitive information.”
[1] https://ecfsapi.fcc.gov/file/1031683478226/170316%20CTIA%20R...
Don't Facebook, et. al. do this already? Don't most people spend most of their time on Facebook anyway? ISPs just want a cut of the action.
This is very different from a service provider collecting and selling information about communications between third parties.
A service provider, on the other hand, is in a position that has absolutely no legitimate claim on the contents of communications between third parties.
Postal services are not expected to rifle through the contents of their customer's packages. Phone companies are not expected to record people's phone calls (or even reveal who's calling who). There is no reason why data communication providers should be allowed to do these things.
We should strongly push for real legislation that bars these companies from collecting browsing metadata from users, regardless of what service they're providing.
I would argue that as postal services can not force you to give up you a privacy with the contract terms (you are entering into a contract by sending a mail), so should not Facebok or ISP.
Of course, it is an first level intermediate, and ISP are second level, but still an intermediate.
At least you have some idea of what you're doing with FB; someone may switch from FB to private browsing mode in a browser to look something up.
(And FB should be subject to additional privacy rules as well, that just happens not to be within scope of this particular FTC action).
> "Privacy rules for ISPs are important and necessary, but it is obvious that the more substantial privacy threats for consumers are not the ISPs," the advocacy group said. The bigger threat is posed by "the largest email, search, and social media companies."
By which they're obviously referring to Google and Facebook without naming them. CTIA, the mobile broadband lobbying group, cited this statement in their argument:
"even a prominent privacy advocacy organization asserted that it is 'obvious that the more substantial threats for consumers are not ISPs,' but rather other large edge providers."
I think that, while "large edge providers" may presently collect user information, there is greater potential for ISPs if left unchecked and harder for users to avoid.
Either way, I think you hit the nail on the head with this statement: "there is greater potential for ISPs if left unchecked and harder for users to avoid."
The CTIA's logic here can be reduced to "they do it so we want to do it too", seemingly framed within their long-time disposition of not considering themselves the "dumb pipes" that they are. Giving residential ISP's access to use this information, combined with what they already have on file for accounting purposes, is a situation just ripe for abuse. The article then goes on to say "What's less clear is whether the FCC will have any authority over ISPs' privacy practices after the rules are eliminated" - so there there may very well be no recourse whatsoever through either the FCC or FTC if or when widespread abuse were to occur. And of course, that's not even to start the age-old discussion about how & where the data is stored (plaintext on an insecure FTP server), who has access to it (all employees & contractors), etc.
I am confident that this change from the FCC will only serve to screw over individual people at the gain of large corporations.
Asterisk what?