Comcast says it will not sell customer browsing histories
reuters.com
reuters.com
It'll be just like the FBI v Apple saga. "We need the courts and Congress to give us some very specific powers."
"Wow, thanks for doing that! We see people are pretty mad for legitimate reasons. Don't worry, we are not going to use those powers we asked for. We're only going to use it to go after BAD GUYS. Trust us!"
They will probably buy out an ad-company (if they don't own a couple already) and the will keep the data for themselves ;)
While offering other ad networks the ability to not get their ads replaced. Since they're more likely to stay silent.
https://ghostinfluence.com/the-ultimate-retaliation-pranking...
You're definitely free to see it this way, but so far (for the most part) the people in power definitely don't agree.
Obviously, there's caveats; but for the most part those should be covered by other antidiscrimination laws, not telecom specific legislation. Telling that you call your rabbi once a week might give them clear signal that you're jewish, but they should be prevented from discriminating against you because you're jewish, and that should be enough reason to prevent them from fishing through their records to see who's a jew.
and
> ...but they should be prevented from discriminating against you because you're jewish
You can't have it both ways. Either a business can be regulated or it can't.
And why does it have to be the business itself only must be prevented from discrimination? It's certainly possible for a single employee to send likely names of Jews to hate groups, even if the business doesn't condone his behavior.
We do this already with health care providers, attorneys, crediting agencies, banks, etc.
Intent and outcome goes a long way to proving a case here.
Maybe we have reached a point where we need to permit folks (immunity against legal action) to release internal data/documents of BigTech, provided it unequivocally proves that such public statements the companies make are false.
As long as they stick to this policy, I will appreciate it given their history of not showing compassion for individual customers.
Update: it does specifically mention aggregate data.
I honestly can't come to a guess. On one hand, making the data anonymous would explain the interest in crazy fingerprinting methods and why companies that do that aren't very well known. On the other hand, I have no strong evidence to support the idea that an ISP would anonymize data given their history of activity in the name of profits and in spite of customer satisfaction.
Comcast selling any data is a concern, I will continue to assume my information is being collected and act as best as I can to prevent that (VPN, poisoning my dataflow,etc).
[1] https://www.schneier.com/blog/archives/2007/12/anonymity_and... [2] http://www.computerworld.com/article/3088179/apple-mac/what-...
It's not really aggregate data in the sense that any records about you are still individually separated. You're not anonymized by getting mixed into a bigger pool of data points.
The usual rule is that the buyer won't get your records by name but will know more or less where you live, how old you are, political leanings, hobbies and interests, etc.
So you have some anonymized ID number or set of cookies attached to you. However, if you think about it, from the perspective of the advertiser your name is one of the less valuable things about you.
So... you might be anonymous by name, but the name thing is a bit of a red herring.
IIRC, AT&T basically has said they MITM all their fiber optic customers to insert ads and track browsing history.
Before I blocked ads, ads would follow me around. The information to do that was collected, and possibly sold, probably not by my ISP. It wasn't "my browser history," but it was as a result of my browsing activity.
This news has thrown around "your browsing history," which is at once sensationalist (because, as you point out, no one is selling that) and obfuscating, because someone is collecting and selling data that comes from browsing activity.
Right now your "data persona" is mostly obfuscated by market fragmentation and the fact that advertisers wouldn't know what to do with all of the data if they had it. As someone on the "inside", the AI push scares me because it will make actually reconciling all of the disparate data sources both feasible and profitable.
It is entirely a by-product of the fact that ad slots are auctioned off while a page loads, and when someone wins that auction, they can run JavaScript in your browser.
So if they cookie you on their website, then they get to run JavaScript from winning an ad auction on a different site, they can still see their cookies and know it is "you".
Not trying to downplay any privacy implications here, but ad networks and sites where ads are placed don't actually need any of your browsing history to make this work.
(I simplified this somewhat by ignoring the relationship between the actual advertisers and retargeting providers, but that is just more of an economies of scale/arbitrage thing.)
They aren't using your web history specifically, because it's actually pretty hard to do a good job inferring things about you in the few milliseconds you have to make a bid. Instead, there are multi-billion dollar companies including Google and Facebook who do the intetpreting for you and sort of offer a taxonomy of audience groups for you to choose from.
So the cookie check at bid time is usually asking one of these middlemen data processing companies for their read on you, which is derived from your browsing history or your Facebook post contents or even what you write in Gmail.
Only thing I'd add is that there are many heuristics for deciding how valuable you are as a pair of eyes. Retargeting is about getting an ad to follow you around the internet. But there's also geographical and demographic targeting, which depends on the advertiser having a hypothesis about which target audience is worth engaging.
That said, here are a few terms to search as a starting point:
* Ad exchange
* Real time bidding
* Search retargeting
* Data management platform
* Demand side platform
Here are some product names:
* Doubleclick Bid Manager
* Google tag manager
* Google AdX
* Adobe Media Optimizer
And some companies to look up:
* AppNexus
* Bluekai
* Excelate
* Celtra
Finally, I'd set up your own AdWords and Facebook advertiser accounts to play around.
So the way that this works is that you submit a request to Verizon asking about an IP address, Verizon sends it back to you, and then you decide whether to bid on the ad in a marketplace.
The problem arises when some shyster sends a request to Verizon asking, "Does this household both hit Christian sites and gay porn?" Gets a yes, serves an ad for a seminar "to use the power of God to drive homosexuality out of someone close to you", and triggers a very bad conversation between a closeted gay teenager and his very conservative parents...
https://fahrplan.events.ccc.de/congress/2016/Fahrplan/events...
The data may not say John Doe, but it's tied to John Doe's device. You can already identify that a user saw an ad on their laptop at home and showed up at a physical location because the mobile device is tied to the laptop and the mobile device spits out GPS data.
So yeah, they might not sell data that says this is John Doe, but it's John Doe and we know where he lives, where he travels, when he travels, etc.
1) Come buy our trueTarget analytic service - add a keyword search and out comes the name of every one interested in say "Evening college" (Comcast also has the address on file obviously)
2) Political observers - This Zipcode has the most mentions for "Climate change hoax"
3) Porn/Medical/<other potentially embarrassing stuff> : Too many services here -
None of this sells individual browsing history yet which of these would be certainly illegal? This is a complete red herring to distract from the Republicans completely disgraceful sell out to big business.
If not illegal which of these would be ok under "we do not see your browsing history"?
They can do all of those things and in addition sell your history to make more money.
They've just released this statement today because everyone is so upset, they're going bide their time, wait for this to blow over and then quietly start selling more and more invasive customer information. You don't spend millions on a law you have no intention of utilising.
They bring up their "targeted ad network" which you can "opt out" of in the same blog post. I wonder what "nonsensitive" information they'll be providing their ad partners about you? And what is stopping Ad Partners from cross-referencing several ad networks?
[0] http://resistancereport.com/class-war/comcast-congress-brows...
I am astonished that a company can lobby successfully in the name of "consumer interest" when ranked the worst in customer satisfaction (for years).
https://www.exede.com/documents/master/exede-subscriber-priv...
Gonna guess no. This seems like an empty promise designed to fool people who just don't understand how "selling browser history" is actually implemented.
He didn't say "we won't". He said "we aren't currently" which means "we're keeping the option open but we're trying to sound good right now".
A promise by a for-profit company is hilariously useless unless they bake it into a contract. The leadership have an obligation to shareholders to break promises if it improves profitability.
Officers of a corporation have a responsibility to act in good faith for the best interest of its members. But that can include acting in long-term best interests too.
Contrary to what you may believe, no one will indict Comcast leadership for not harvest and selling info.
Also, remember "good faith". E.g. MS shareholders can't indict leadership for Windows 8 ;)
They'll sell it one way or another -- it's too good of a revenue stream to pass up, provided you're legally allowed to pursue it.
News picked this up and Comcast said: "No, we aren't doing data caps at this time".
Months later, they formally rolled out data caps of 300GB.
[1]: https://www.engadget.com/2017/03/31/eff-verizon-will-install...
Consistently get the speeds advertised or better, no random fees on my bill, and have only had 2 service outages (both due to storms).
/s
Maybe those in control of ISPs realize that they have no individual protection from this practice, unlike other shady practices like inaccurate billing and poor customer service, and genuinely have no interest in doing so.
Update: I'm not asking sarcastically and my hope is obviously full of optimism.
Why not?
As long as it remains lawful for them to change their minds, they don't need to say that.
In America, the credit reporting agencies are required to provide a free detailed report annually and there is a legally-mandated dispute process in place for false/erroneous data. Why don't we have the same protections/process for metadata collection?
Instead of expecting data-collecting companies to police themselves, we must insist on regulation requiring free, full disclosure of all data collected and a legal process to have false/erroneous data collection challenged and removed.
The biggest danger is not that they collect this information, but that there is no AUDIT PROCESS to correct false information.
I'm not really sure what answer you're looking for here. The basic answer is that the system is corrupt and the interests of big corporations are heard much louder than the interests of individual constituents who don't have as many dollars to throw around capitol hill.
Satisfied?
The end result of all this is that the data is sold to some company that is either the end company or some intermediate company.
From that you get some creepy ad emailed, physically mailed, or you get a call on your cell phone about Solar panels and a trip to the Bahamas.
It would ideal to have a list of the end company that delivers this creep so consumers as a group to make an informed choice if they wish to do business with companies taking part in this.
If people had alternatives which touted privacy, security, speed, price, and had the right network backbone there would be a deluge of customers migrating away from Comcast, AT&T, Verizon, etc.
Also, a blog post on the recent law: https://corp.sonic.net/ceo/2017/03/29/privacy-matters/
Can you elaborate? What is this undeletable tracking cookie?
They could see my DNS requests, which I believe are in clear, even if I use Google's name servers.
They would know the sites I go to, but not the pages/bookmarks...
If name resolutions were encrypted, we would be good, or ?
a good follow up article if you're interested: https://www.teamupturn.com/reports/2016/what-isps-can-see
Even a tiny bit of data(think DNS name resolution) collected over a long period of time can be pretty invasive to a persons privacy.
No, HTTPS Server Name Identification[1] means that domain names are still sent in the clear so that multiple HTTPS sites can have one IP address.
They can also see how much data goes is transmitted to which site, when, and for how long, which lets them infer all sorts of other information about your activity
Uncharitable interpretation: Comcast is a content provider in addition to an ISP. Their interest is in using the data themselves rather than selling it.
Even if they keep their literal word and don't sell your actual history, and you use SSL so they can't see specific content, they can certainly make money by identifying traffic profiles by domains/times/frequencies/etc.
I didn't know Chief Privacy Officers were a thing. When did this start?
But remember, the Chief Human Resources Officer historically isn't on the side of employees. I'm of the view point that the CPO (*) isn't on the side of consumers. But it looks good to have one.
(Sorry to all of the Chief Petty Officers)
I digress. Anyway, lest Comcast be like Trump.
burn them all down and bathe in their ashes.