Given enough opposition, Verizon, Comcast, etc, could strongly embrace personal data privacy and still continue as companies. Yes, they'd lose a business opportunity, but they still make a lot of money selling you internet access and that wouldn't go away. The same is not really true of companies like Google or Facebook. Collecting and making money off your personal data is the foundation of their business. Strongly protecting your privacy would require them to change their entire way of making money.
I think you could argue either way whether Google or Verizon has more ability to spy on you, but Google absolutely has a stronger business motivation to collect your data than Verizon does.
For Facebook maybe, but Google was a large and successful business before its 'personalized' targeting was really that advanced. AdWords ran for a full four years without any kind of search personalization, and up until 2012, it was possible to turn off search personalization entirely. Google made $37bn in 2011. [1] Google Display Network, the area of Google's business that would most obviously be disrupted by a move toward strong user privacy, only makes a fraction of that still. [2]
While I completely agree that Facebook would struggle without behavioral targeting, being able to buy ads on a PPC basis for users with 'intent' will always be a valuable product for advertisers, regardless of targeting.
[1] https://www.wordstream.com/blog/ws/2012/01/23/google-revenue...
[2] https://www.statista.com/statistics/266245/advertising-reven...
But as a company it never really needed to do those. Heck, Google doesn't even need to be in the self-driving business.
I think it's a failure of competition and anti-trust laws that companies are allowed to grow this big to get their fingers into all the pies out there. The only reason they even go into all of these different industries is because they've made so much money they don't know what to do with it.
Sooner or later we're going to have to deal with this rampant increase in monopolies and we'll have to take some drastic measures to do it. We may even have to break-up companies such as Google, Amazon, Facebook, Walmart, Comcast, Disney, Goldman Sachs, and others, because they were never supposed to turn into such large conglomerates. The fact that they did was a failure of competition laws to stop them from growing this big in the first place.
Comcast, AT&T, and Verizon are now allowed to spy on you, then buy media and ad companies, and then use that data to manipulate you for political purposes so you end-up voting for the candidates that will help them further consolidate their power. We should have put a stop to that along the way.
Per Thiel's "theory" (as seen in Zero to One) most of Google's "failures" are a cover for their search monopoly.
You can also be targeted with ads based on emails you receive in Gmail - it was possible to target down to keywords in emails, but that was discontinued. Now, the emails you receive, domains your getting them from etc. influence signals, that puts you into an 'audience' that can be used for targeting across the Google network.
Without the ability to do targeting, or personalization, as Google calls it, their business will fall apart. Everything they do is geared to collecting more information about users to improve "personalization" - from Google Assistant, to Google Home [2]. It's so advanced that your experience (results) on their platfrom, especially within Search -- will be unique to you.
Google will fight alongside AT&T, Comcast, etc to protect their business model, in-fact Google is trying to reach their ranks with the 5G war [3]
[1] https://searchengineland.com/google-adwords-in-market-audien...
[2] https://twitter.com/benthompson/status/864293485439893505
[3] https://www.bloomberg.com/news/articles/2018-03-29/google-le... - (search for: Spectrum Access System )
If ISPs are going to monetize customers traffic then their terms of use better damn well call that out.
There is potential here for new business model for privacy based ISPs (ex: think duckduckgo for ISP) where customers pay a premium for such an offering.
Mind you many of them have no idea, but as their goto I could make a smart recommendation and they would likely follow.
Oh! And package it with a better than average 2FA. Maybe a Yubikey or similar.
More or less sec in a box. Perhaps not 100% complete and bulletproof but better than the current situation.
But from what I've heard practically anywhere in Europe, and definitely in Japan.
as an american living in a major city, this exceeds my wildest dreams of internet service.
It's one of the negative consequences of mainstream media / political free market rhetoric considering regulation harmful.
Well regulation can be harmful if it protects the incumbents and prevents the introduction of new players. Lobbyists are usually pushing for more regulation, not the opposite.
It's not about regulation or not regulation, it's about what kind of regulation makes sense for a free market.
A surprising number of sites (and/or assets, images, etc) still don't use TLS, and so for those it's also possible for an ISP to understand what the user was reading/accessing.
Even for sites which do support TLS, if the ISP hypothetically had a partnership with a single data broker / advertiser which was also on the page, it's likely not hard to have a pretty precise idea of their interests/viewing.
You're right that Google and Facebook will continue to have very narrow and precise information about people's daily lives; it's simultaneously true that ISPs will continue to have broad & ongoing profiling information across any touchpoints as people use the internet.
I think if the article was written in the spirit of "watch out for the ISPs too" instead of "the ISPs are so much worse" I would have been more onboard.
I think it's a bit apples and oranges: all my traffic with low resolution or just my social traffic in high resolution. I don't clearly see one being far more dangerous/valuable than the other.
Bank vault analogues for private data do exist: iCloud, Dropbox, Crashplan, etc. If “your data” needs to leave your physical possession, that’s the sort of service it should go to.
Dropbox: Dropbox has the keys :(
Crashplan: I have the keys :)
Do you really? They offer a web interface with access to your data. Do you enter the encryption keys when you access the web interface, or do you enter a username and password which then provides access to the encryption keys?
In that situation, who really has the keys?
It's easily blockable for people who care, but still many don't, and for those people it makes all the pretty transport encrytpion a sham.
Seriously, companies afford third parties JavaScript execution on pages where they expect me to enter CC or other sensitive info. Half of the web at this point is a joke when it comes to security and privacy.
We, the ones that they'll have to spend undue effort to sniff out a profile about, are not targets to them. We are much too resistant to it that we have gone all through the effort of setting up a private VPN with good encryption.
For example
* On NordVPN through US servers you can't access Amazon (!) Although through Canadian servers you are ok.
* Costco, Apple store, Business Insider, YouTube, google, netflex, dell, consumer reports, ebay - either don't work, or are a pain to make work
* On PureVPN you can't send email - until you have your domain whitelisted
* On PureVPN it's a crap shoot if you get a connection
More detail on experiences with PureVPN and NordVPN are here..
https://www.toytheory.com/?p=295
https://www.toytheory.com/?p=273
https://www.toytheory.com/?p=321
(edit: formatting)
You're right that VPN usage is technically a minority [1], but it is well beyond fringe usage.
[1] https://cdn2.hubspot.net/hubfs/304927/Downloads/VPN-Usage-Ar...
1- I did not audit the script myself, and they may have injected various malware to the VPN server it spun up during the setup. I am not concerned enough to not trust them, but I could just read the script thoroughly to eliminate the necessity for trust.
2- DigitalOcean has the access to hardware, so it might be doing whatever while I am not looking, and I just never look. Similarly, I could monitor the activity on the server to assume some control.
I chose DO for being the cheapest ($5/month).
The only company I know of that puts everything in public so to speak is google.
So VPN traffic is very common.
Most hotspot providers are probably tracking your physical locations by MAC address, which can be linked with other data. It looks like Peet's recently started doing that as well.
I used a fake address yesterday without issue.
- ISP offered 'apps'. Get people to agree to an install of some monitoring app for some [insert random marketing benefit] from ISP. Maybe if you install the app you get more data cap space etc and they can monitor browser access. Further, install this in known apps or as add-ons on setup for other apps.
- ISP offered 'VPN client' that again, gives some cheaper monetary benefit like more data cap space or more speed 'free', strips out other advertising or tracking as a benefit.
- ISP offered 'email client' that does all of the above.
- Check for subsequent request after page loads to known ad networks and replace with their own in HTTPS
- ISPs like you said may start throttling encrypted content down, or charging extra to allow it.
- ISP level proxy MITM, modem customization for 'fast lanes' that are actually slow lanes.
- DNS level data collection not to inject but to sell marketing profiles via metadata and correlate with other data from apps.
Since ISPs are your 'gateway' to the internet and you pay them, most people assume trust and privacy, most don't know they bribed their way into the tracking/ad business, many didn't know cable tv modems had mics either. With that assumption of trust since people are paying them, they'll more easily fall for any of the possible attack/tracking vectors listed and more probably.
With the ISP privacy protections removed [1], my guess is most ISPs, due to lack of competition, end up more like hotel wifi where tracking/injection is the norm [2] as it is completely legal now. With the removal of privacy protections and net neutrality, we have killed the pristine, non tracked, private gateways to the internet we cherish.
[1] https://www.flake.senate.gov/public/index.cfm/2017/3/flake-i...
[2] https://medium.com/@nicklum/my-hotel-wifi-injects-ads-does-y...
Your other points about how they can (ab)use their position as the gateway to chip away the effect of encryption by laying various roadblocks (I guess the proverbial "stick" in the "carrot/stick" trope) seems like it could have some teeth if the ISPs really doubled down on this strategy. I expect they will have to overcome significant controversy in order to be successful on a mass scale (but we'll see I guess).
Encryption has gotten much easier and more widespread in recent years, and is growing. If the ISPs had really focused on attacking it a few years ago, they could've nipped their surveillance competition in the bud, but now it's a harder problem for them to deal with. Not 100% insurmountable, as parent explained.
When you only have a handful of large ISPs where AT&T has been known to split your data to share with the NSA and authorities, that is dangerous thinking [1].
> Room 641A is a telecommunication interception facility operated by AT&T for the U.S. National Security Agency that commenced operations in 2003 and was exposed in 2006
That was over a decade ago, I am sure by now they have privilege to lots of that data and technology.
There was a #deletefacebook movement which proves that you can get rid of Facebook and people use it by choice. There cannot be a #deleteISP movement as that is the 'trusted' network gateway you can't route around.
All it takes is scaring people who use ISPs to allow in more monitoring 'for your safety' or 'more data cap space' or 'faster internet' or 'lower costs', they can legally sell that data now so there is an incentive to do these things. There is a reason they lobbied for this right and removal of net neutrality, it wasn't to play nice.
Hotel wifi like ISPs here we come.
Is it _your_ data, or is it _their_ data? I'm asking in both the literal (based on terms of service, etc) and the more abstract way? Obviously, for the latter, it is a combination. I wish the narrative was discussed with that in mind. Most of what I tend to see is a widespread assumption that the user owns the data, and has given companies like Facebook very limited powers, and that somehow Facebook is breaking that trust. That narrative is, IMO, rubbish. We gave them very broad powers, and the users should accept the consequences.
>However, Google/Facebook break all the security layers because we explicitly _trust_ them with all our data.
If we explicitly _trust_ them, then are they _breaking_ anything? It just seems silly when we explicitly say (as many of my friends have said in the past) "I don't care what Facebook does with my information" and then we talk about it as if they are doing something wrong (using words like "break").
When I give my bank all my money with the understanding that they can hold it, as well as lend it, we don't refer to it as "breaking" anything.
For example, are $US_ISP and F-Secure in the same bucket in practice?
They are worse because you are forced to use an ISP if you wish to access the internet.
>However, Google/Facebook break all the security layers because we explicitly _trust_ them with all our data.
Nobody informed who cares about their privacy ever entrusted Google or Facebook with any personal information.
Google and Facebook have detailed social graph and search query, but your ISP could piece together a lot of that information by tracking your DNS queries, unencrypted HTTP traffic, email if you use their mail servers, and offline information.
Also, Facebook and Google can both determine your home address by where your phone (and it's location tracking) idles for several hours a day.
Google buys access to credit card providers so they can link the ads displayed to you with purchases you make, to report how effective the ads are to the advertisers.
Which will include everything interesting about your identity. It literally is equivalent to using a debit or credit card
There's no 3rd party payment processor involved that could collect a bunch of my activity and then sell it to someone. With wire transfers, they'd have to go to everybody who I'm paying and ask for the data. Which is much less likely.
The others can follow you everywhere. They know where you live. They know who you phone. They know who phones you.
It's even. Death by drowning, or death by car crash is still death.
The fact that Uncle Sam isn't concerned about the intrusions tells us whose side he's on.
Liking a comment has to be tough to surmise "intent."
p.s. fwiw I'm getting to the point where I'm going to like and follow things just to leave a false trail. Can't hurt.
The fact that typically my FB feed is so shite only tells me they have a long way to go before they analyze the signals I provide them.
But there are borwser extensions to block that, yes?
Note: That's not a tit for tat counter attack but a question. Tia
The web requests your browser sends to ad networks (or other colluding web properties) from vpn exit addresses, when analyzed as an aggregate, can be identified based on their time/length signatures. These would be correlated by the isp with traffic between vpn termination addresses and customer addresses. ISP can resolve a customer address to person.
Advertisers could add unique timing and size features to make this easier.
Outside of the telecom industry itself there was quite a bit of resistance to this sort of thing, and we had to go before the US Congress to explain what we were up to. Profiling for the sake of profiling was not smooth sailing, but if it was for the purpose of "security" then it was more or less a free pass. The forcus of our DPI technology turned to the task of network-based threat detection as its primary raison d'être, with customer profiling being an opt-in service by which users could obtain the security service in exchange for targeted ads.
In the years since, I don't expect that Telecom's desire to be much more than a "dumb pipe" has diminished in the least. They view the traffic they carry on their networks to be their property, in a way. They feel entitled to inspect it, throttle it, slice and dice it any conceivable way they can to maximise their profits. Its one of the reasons I quit.
Imagine the US postal service steaming open every letter and opening every package that went through their system, so they could plug your mailbox with targeted special offers or increase the delivery fees for certain things. Its all similar BS with ISPs, but it's all techie stuff and heavily lobbied so the public gets bamboozled.
You raise a really good point about wide-spread encryption being an impediment to ISP profiling. But there is a LOT you can surmise from user traffic even if you don't know the exact content of the encrypted payloads. Just analyzing IP addresses and times can reveal a ton of information about a person. My first patent [US20100161795] was in fact a NAT session detection and tracking technique to identify and track individual users within a household through TCP/IP analysis. Using this technique someone could get a pretty clear picture of how many people were in a household, their ages, genders, interests and patterns of activity, even without delving into the http payload of the packets. We didn't, but this kind of thing is most definitely possible, and I wouldn't trust other shady entities not to do it.
Encryption doesn't matter.
Automated deep packet and encrypted packet inspection is burgeoning with advances that put the single-actor work-arounds to shame.
1). Your ISP knows your traffic is encrypted. It knows what cipher and protocol you're using, and its routing is not protocol-agnostic.
2). Your ISP knows beyond "mostly confident" the type of files your packets contain. If you don't keep your connection open and use any of the public encryption methods, your ISP will know exactly what you've downloaded to a reasonable degree.
3). HTTPS is only as good as all the different pieces combined (browser, root CA, server, site, client). And if one of those goes bad, it's worthless.
4). If you use encryption heavily, you're already flagged.
5). If you don't use your ISP's CDN, you're already flagged.
6). If you connect to any other site besides Google, YouTube, Reddit, Twitter, Facebook, Wikipedia, or Instagram your aggregate data will be quickly analyzed and compared with a threat table, and appropriately flagged.
7). Traffic analysis is trivial when you're the one routing the traffic.
Google is Dunning Kruger evil. ISPs are "pick up that can" evil. The lack of serious developments in HTTPS are "see no evil" stupid. The thought that HTTPS is anything but a red hearing is "Ivan the Fool" stupid.
Huh? What are you talking about?
>If you use encryption heavily, you're already flagged.
>If you don't use your ISP's CDN, you're already flagged.
What types of encryption? Since when did ISPs make users use a CDN? Again, I don’t get what you’re saying.
Sources and more information would be greatly appreciated.
They can certainly tell whether you're using streaming video with this type of analysis.
If people start using VPNs en masse, ISPs and/or other interested actors will develop this technology, if they have not already. (I would guess it already has been, albeit perhaps not widely deployed.)
If the ISP is the same as the ad network, or a data broker with one (and some are, see: Verizon Wireless), they can then link your IP address to a cookie-based profile. (Yes, there are counter-measures there, like disabling third-party cookies. And there are countermeasures to that, like browser fingerprinting.)
Today. But in terms of risk moving forward, I think ISPs are way worse. Two reasons:
1) I really can choose not to use Google/Facebook. There exist very solid, privacy-respecting alternatives for every service these two companies offer. It's a matter of consumer choice.
This is not the case for ISPs. If my (one) local "high-speed" ISP demands that I install a new root cert so they can MITM all my traffic, my choices are to a) capitulate, or b) find a way to live with very low-speed DSL/dial-up.
Monopoly power backed up by a vast network of cables has way more staying power than monopoly power backed up by social network effects (FB) or superior software offerings (Gmail).
2) You might argue that history demonstrates we don't have to worry about ISPs demanding to MITM customer traffic. But Historically, ISPs weren't incentivized to snoop because of regulatory barriers that prevented collection/use of data for advertising purposes. In the case of US ISPs, changes in regulator landscape suggest that past behavior doesn't guarantee future behavior.
In the same way, many would argue leaving Google or Facebook requires they give up on key features and benefits of living on the Internet. Like, you know, talking to your friends.
I don't see what sense it makes to worry about that before it actually happens. Especially when there's no reason to believe it is going to happen.
>>I recently received a "terms of service" update from Comcast, with the notification that they can now "monitor and record anything going through the network. Including, but not limited to: audio recording, video recording, ..."
I mean, look, if they're not going to do it, then why did they lobby so hard and successfully to do it?
Frankly, I have a had time imagining that this won't eventually happen. And sooner rather than later.
Not to mention there's a LOT of useful stuff on the internet that's not hosting on sites with Facebook trackers.