AT&T’s GigaPower plans turn privacy into a luxury that few would choose
gigaom.com
gigaom.com
What is more concerning is how AT&T actually serves those targeted ads. Are they injecting ads into pages and modifying HTML? That seems like an incredibly disastrous procedure which would hopefully get them into trouble with content providers and even the FCC. I surely hope that's not the case.
I have also been unable to discern ATT's gigapower ads from other ads.
If they are doing ad injection, it is unclear whether or not they could be successfully sued. Some browser plugins with very large user bases inject/modify ads, and although some have received cease and desist letters from content providers, and some have been sued and settled out of court before trial, I don't believe any have gone to trial and lost. The law is murky at best on that issue, and as the ISP, odds are that AT&T would be in a far stronger legal position than even the browser plugins that have been doing this for years.
AT&T is a message relayer, while the browser plugin is a specific program installed by the user to modify the messages they receive.
There's no legal question I could hire a secretary to open my mail for me, and white-out the lines I told her I didn't want to see, but it would be a little strange for a mail carrier to open messages and insert ads.
However, the plugin companies aren't in an ambiguous situation at all: someone who requests the page is explicitly requesting it to use the content to run a program which renders an image from it, and is under no contractual obligation (from merely making an HTTP request) to view the entirety of the content. They can neither complain that it's being processed (the browser inherently does that, to make an image from the text), and they can't complain that the end-user is failing to uphold their end of an agreement.
Because it's a user chosen process, and because of how content on the internet is relayed, there's no reason that the plugins are on any kind of shaky ground. (One notable exception would be interacting with dynamic content to bypass a paywall. There likely are other exceptions, but these come down to bypassing some kind of mechanism, not merely failing to load or render a particular portion of the sent content.)
Would that still hold if they inserted ads?
This is why we need to decentralize the ISPs and move to local mesh networks.
Now, let's talk solutions.
My pipe dreams are about a series of tubes.
Fiber hardware at $30 each is probably not happening, since we barely get ethernet hardware in that price range, and certainly not of any quality.
It really needs to be something where they plug in a box and hot and cold running Internet comes out when they open the faucets. And if you thought disruptions were bad when some country "misconfigures" their BGP to route the entire Internet through their spy agency's offices for 15 minutes, wait until a thousand Joe Bagadonuts are doing it truly accidentally, all the time.
This made me smile. I would like to imagine that there were consensus on this point.
Now, let's talk solutions.
I think the effective solution for much of the nation will be wireless, but FCC and affiliated interests have been postponing the liberation of enough unlicensed spectrum to make that feasible. The dominant regulatory scheme creates scarcity where none should exist, and that's how all of these bastards keep the gravy train rolling. They rue the day they decided to just let the microwave ovens have 2.4 GHz, because now that frequency is proof that there is no physical reason to "license" electromagnetic radiation. If we can just pry a few more spectrum slices from their grasp, including those better suited to slightly longer ranges, that's the hole in the dike that will eventually create a market in telecom.
What do you mean by this? 2.4ghz is used for low-power, short range communication, so of course there are fewer issues with interference. You can't say the same about the FM radio bands, for example.
EDIT: In case this is still unclear: I'm talking about opening specific, limited bands of spectrum to unlicensed use. I would not nominate FM radio as the first such band. Just as wifi chips today are capable of not interfering on bands they don't use, super-wifi transmitters would not interfere on bands they don't use.
Of course I don't suggest that cognitive radio could have existed in the 1930s. Instead I suggest that it should be given more room to operate now. So they had a problem demo seven years ago: what has happened since? Is it "off-the-wall" to wonder why licensing hasn't changed in response to the invention of the integrated circuit?
EDIT: I'm talking about opening specific, limited bands ("a few more spectrum slices") to unlicensed use, in precisely the fashion in which 2.4 GHz is currently open, although at higher power. Though I do dream of the FCC folding (in much the way I dream that of the DEA or CIA), I realize that in serious conversation with serious people one must focus on the tenable.
It might have been one bad demo, but it was also a very simple, controlled experiment. The spectrum environment without FCC licensing would be orders of magnitude more challenging. The technology just isn't there yet to replace the FCC across the whole spectrum. The FCC certainly could move faster to allow the technology to develop, but your characterization of the situation and aspersions are inaccurate and unwarranted.
You're also ignoring how expensive this equipment is. Simple white spaces devices are pretty cheap, but the kind of radio that would could freely operate over a large part of the spectrum is still very expensive. Just the analog frontend capable of tuning to a wide range of frequencies is expensive. Retrofitting existing devices with the technology, at the scale that would facilitate deregulation, would be quite impractical right now.
It's a really interesting space, and I think it has tremendous potential, but there is a lot of development to be done before the technology lives up to the libertarian fantasy. I think we're at the stage where it would make sense to have an unlicensed band that allowed "smart" devices only, which followed a minimum set of rules. The challenge here is getting someone to give up their spectrum.
Then we agree on the only point that matters.
The challenge here is getting someone to give up their spectrum.
That is indeed a challenge. In one case, this effort included updating every television in the nation. Yet still, five years after the digital transition, from the WIA Spectrum Policy [0] page:
Rural areas continue to be the most underserved market in terms of wireless reach and innovation. However, the abundance of white spaces in these regions provides a unique opportunity for rural wireless providers to use this unused spectrum to promote coverage through high-capacity service. While the advantages to expanding this expansion remain undisputed, firm action has not been taken as of yet in order to allow the operation of higher powered spectrum in these areas. At present, TV band devices are not permitted to operate at power levels greater than 4 watts EIRP, even though expanding this power limit would pose virtually no threat of interference to current broadcast bands. The delay in the advance of power limits only serves to hinder wireless progress in rural areas of the country.
That seems wasteful: usable white space was one of the selling points of the digital transition, and yet giant blocks remain unusable for no publicly-acknowledged reason. I mean, I hesitate to even ask what the military are doing with all their spectrum while this is still going on.
[0] http://www.wirelessinnovationalliance.org/index.cfm?objectid...
I'm a big proponent of having minimum interference tolerance requirements for receivers, and there's work happening on that front: http://transition.fcc.gov/bureaus/oet/tac/tacdocs/WhitePaper.... But we'd be talking about another round of updating every television in the nation...
When I enter "Los Angeles CA" on the FCC reception map site [0], there are 23 green/strong broadcasters listed. When I enter the location of my home, there are two. Are we to believe devices that can handle the presence of 22 "competing" signals in one situation will be completely overwhelmed by the presence of one or two extra signals in the other situation?
One of the most complex aspects of doing this sort of thing is various permutations of the "hidden node" problem. Essentially, the problem is that a "smart" transmitter may not hear a dumb one, and use an in-use channel, interfering with a dumb receiver, which otherwise could hear the dumb transmitter. This tends to happen because geographic obstacles can cause individual nodes to have a different view of the spectrum environment.
Even if we were limited to listen-before-talk, the linked study recommended 10 W rather than 4 W, and that was in the urban context of Baltimore-DC, rather than out here in the hills where we rural people would like a choice in ISPs.
I think trying to change that might cause a few problems!
TIL another reason why Ma Bell doesn't like neutrality. If they get their way we can expect performance on unobfuscated VPNs to suffer.
One can imagine ways to tunnel VPN traffic over ISP-approved traffic, but that arrangement might have other drawbacks.
Yes, you could tunnel VPN traffic over an HTTPS connection. I have built VPNs using ppp over ssh tunnelling before, and that works fine.
You can expect it because VPNs are overwhelmingly used by technologists and 'business' users. In general, these people have an ability to pay (much) more, so ISPs would like to charge them more.
Anyone know of a portable, travel wifi router that supports VPN and fails closed?
As a result of this bugginess, I'm no longer willing to use untrusted wi-fi networks even with VPN. It's really too bad that Apple is not fixing this, because it renders the Connect on Demand feature useless from a security point of view, and it nullifies the functionality of Cloak. Cloak is otherwise an awesome app and service, and it's not their fault as they can't control this code.
That being said, I also have an Xposed module to get rid of the confirmation prompt entirely (I use Tasker to enable the VPN automatically when my phone connects to unsecured wifi networks).
I can't speak to how Apple does it, so maybe it's just an OpenVPN vs IPsec thing. If you setup your own IPsec VPN you could possibly have it activated automatically. There was a post on HN a few months ago with a script to basically setup an IPsec VPN automatically for you.
True, a VPN in hostile environments might be a good idea. If the termination endpoint is secure, is another question.
If my ISP has a poor path to (for example) Netflix, but my VPN provider has a good (unsaturated) path, it could be advantageous. But this requires my ISP to have a good connection to my VPN provider.
No chance of pushing any serious traffic through a VPN though unless you control it.
Unfortunately, in my case a VPN would probably put me on weaker legal ground. My ISP is not legally entitled to monitor my traffic...once it hits the VPN provider the local laws apply & I can do without US laws on the privacy front.
As another poster mentioned - if I get really paranoid, I will eventually set up a VPN, and tunnel all of my traffic through that.
I did want to add that once Google Fiber comes to my neighborhood, I will be jumping ship though. We have had two significant outages in the first month of GigaPower.
If your smartphone also uses AT&T they see that traffic also. The only place where you are hidden from them is at work.
Of course, at work we have Gigapower as well.
Our common network software should be designed with the expectation that the middlemen (including your ISP) are actively hostile, and include defenses against their attacks. Making the html stream inaccessible to them is a first step in that direction.
If you can afford a domain, you can afford an SSL certificate...
I have a bunch of domains which, frankly, I don't care enough about to pay money for an SSL certificate for.
I would suggest that an argument could be made for some sort of fraud as well, for not delivering "the internet" (would have to consult with a lawyer to be sure).
Throwing protocol changes and such will not work in the long run, because you're trying to fix this in the wrong problem domain. This is a legal and political issue, not a technical one. If there is a desire to fix this idiocy, time is best spent where it is most effective.
/I suggest political action towards hitting the big ISPs with the Sherman & Clayton Antitrust Acts. These ISPs are patently abusing monopoly power in various ways.
https://corp.sonic.net/ceo/2011/08/11/the-five-levels-of-isp...
What you're describing could be any or all of levels 4, 3, or 2.
"Section 512(a) protects service providers who are passive conduits from liability for copyright infringement, even if infringing traffic passes through their networks. In other words, provided the infringing material is being transmitted at the request of a third party to a designated recipient, is handled by an automated process without human intervention, is NOT MODIFIED IN ANY WAY, and is only temporarily stored on the system, the service provider is not liable for the transmission."
http://en.wikipedia.org/wiki/Online_Copyright_Infringement_L...
So the ISP is not necessarily interfering in O's contract with A by replacing ads or such -- at least, it doesn't necessarily work that way. I really don't know, some ISPs have been caught replacing content or injecting ads, but in principle the scheme could be managed without doing so.
(My description is from descriptions a few years ago when ISPs were sneakily trying a DPI setup)
I'm currently paying 15 EUR/mth for a 100mbit service, more bandwidth would be more expensive, but not extremely so.
And all that is because Verizon won't upgrade their equipment to handle the congestion that happens at night. It's not that they can't, but that we're "rural".
[0] Which usually gets me about 1 MB/s in practice.
I'm now paying $60/mos for 120Mbps down and 10Mbps up.
[1]: http://www.npr.org/blogs/money/2014/04/04/299060527/episode-...
Where do you live?
Here in Philly (and also in Boston, DC, and New York), RCN charges $50/month for 110 mbit service. This is apparently quite similar to similar service in Prague, London, and Dublin: http://arstechnica.com/business/2013/10/cheapest-150mbps-bro....
1000 mbps download speed to the Internet
30 mpbs upload speed to the Internet
100 mbps upload speed inside the provider's network
Uncapped traffic
20GB Cloud storage
Free Wi-Fi in public places where the ISP is present
IPv6, Dynamic DNS, Parental Control
The ISP industry doesn't feel like a free market.
That said, there's no consumer service remotely as expensive as that AT&T one here.
What do people think the ISP does with the packets? Who thinks that their browsing habits are hidden from the ISP (without using a VPN)?
So is this just an expensive opt out of targetted ads, or is it actually providing extra privacy features?
AT&T refers to the ad targeting as "Internet Preferences": http://www.att.com/esupport/article.jsp?sid=KB421828&cv=812&...
Sounds like they gather your full browsing history, and then assist 3rd-party ad networks in targeting their ads at you. Or, worse yet, just hand over your browsing history for ad networks to process. Their marketing materials don't seem to make this clear.
Who thinks their browsing habits are hidden from anybody? The internet is a packet-switched routed network that sends almost everything in clear text. Anybody who receives or forwards a packet can mine it for data.
AT&T never says they will not inspect the packets nor keep the Government from inspecting the packets. They just give a lower priced option where they target you with ads/or sell your browsing history, etc. NSA is splitting off the packets 100% at the major uplinks regardless of what AT&T or any other provider does.
I'm currently using tethered wifi cellphone as my only home internet because I refuse to give money to either of my only two broadband options, AT&T or Time Warner.
> I'd happily pay $62/month for spyware-free Facebook.
You'd pay $744 per year to use Facebook? You don't say.
> And they're making billions from it, too.
I don't find this argument wildly compelling in light of Facebook's 25% profit margin, versus AT&T's 11% margin.
> You'd pay $744 per year to use Facebook? You don't say.
As a 30-something with a kid, I have to admit my primary use of Facebook is sharing pictures of my daughter and my friends' kids. But Facebook benefits from powerful network effects. It's the only site my parents, my wife's parents, and my family in Bangladesh regularly check, and they demand regular baby updates. As a practical matter, I have more ISP choices than social-networking choices.
Google already "snoops" on you, FB snoops on you, so why not AT&T for a discount? Google and FB offer "free" services as long as they snoop on everything you do, AT&T offers a discount. Capitalism at its best. Don't like the cheaper snooping offer? Pay more. Or don't choose AT&T.
The average users stands no chance of avoiding Google between the search, Youtube, Analytics, Adsense, Doubleclick, Android etc etc...More or less, 100% of sites have one of those installed. So why shouldn't AT&T make you an offer too? Take it or leave it. Surely Google would still be wildly profitable if they tracked you 30% less and /or if they showed less ads.
Shocking how something coming from AT&T seems a lot like well-established, if unwelcome, practice of "the phone company".
At least for wireless users they already do. It's only a matter of time before they do the same with land-line users.
http://online.wsj.com/news/articles/SB1000142412788732346370...
http://www.attpublicpolicy.com/privacy/our-updated-privacy-p...
Personally, I would never use AT&T for broadband at home again. I'll always go with their competitor and I wish other people would do the same. Their motto should be: monopolize and do evil whenever possible.
Even CenturyLink (my current ISP, who happens to be the only choice here besides Comcast) is starting to piss me off lately, but what the hell am I going to do about it...
This is why I don't think we're ready to pass net neutrality legislation.
Fiber's privacy notice: https://fiber.google.com/legal/privacy.html
It looks like the same snooping that's in all the other google apps (whether to serve you ads or otherwise). I'm glad that it's out in the open, and hopefully it causes people to think about the value of their privacy (and feel a little bit more paranoid about their lack of it)
I'm not sure who said it first, or where I heard it, but the belief that "everything google does is a loss leader for adwords" holds true here -- this is why I believe they're going to snoop-by-default, and not think twice about using your data as it flows through their fiber.
If AT&T presented this as $179 + $50 for normal, or $150 + $0 "with special offers" (think kindle model), I think people would be much less worried.
Sure, now they're all about unicorns and rainbows, and talking the good game to get into what is a very capital heavy market. I can easily see Google switching to this exact same model to inject Adwords and extract even more money from subscribers once they're hooked. The difference is Google won't let you opt out.
It's the difference between tracking only by server/client tricks (IP, cookies, hit logs etc.) vs. tracking by the ISP. The former can be avoided by client config, the latter only with a VPN.
Even if they let you supposedly opt out of the DPI, who trusts a corporation like this? And as adestefan notes, where do people get the assumption that Google is not doing the same?
Edit: I finally found ATT's (semi-) disclosure about this: http://www.att.com/esupport/article.jsp?sid=KB421828&cv=812
It says that if you don't opt out they collect " webpages you visit, the time you spend on each, the links or ads you see and follow, and the search terms you enter" - but there is no statement that they're not collecting that info if you opt out. All they promise for opting out is not targeting ads with that data.
Google dominance in the ISP market will probably have its own share of problems for consumers, but I hazard that they will be different and less infuriating problems than what we get with the current status quo.
Nope.