Users have reason to be concerned about forms of surveillance on their local networks beyond government monitoring. In June and July of 2007, several British Telecom (BT) Internet customers noticed strange problems with their Internet connections
that they tracked down to a spyware company, 121media. 6 BT insisted that it had
nothing to do with the suspicious behavior, and 121media refused to comment on
the grounds of customer (BT’s) privacy. 7 But in 2008, 121media, renamed Phorm, publicly announced a deal with BT to target advertising at the ISP’s customers. 8 Phorm
soon afterward admitted, in response to media reports of the 2007 activity related to
121media and BT, that it had already tried its targeted advertising on tens of thousands
of users on the BT network with BT’s help but without the knowledge of the users. 9
Phorm claims that it does not store any personally identifying information or browsing
histories in the process of targeting ads; Phorm says it only stores information about
the kinds of sites each user visits (expensive cars, rugby sites, and so on) connected to
the user only by a randomly generated unique ID. 10 Privacy advocates have reacted
strongly against Phorm’s announcement and justifications, but BT continues to push
for a full rollout of the system. 11
As with the Relakks case, user efforts to circumvent network monitoring can have
unpredictable results on the network of trusted relationships that tie together Internet
activity. In February 2008, a Pakistani ISP responded to a government request to ban a
video on YouTube.com by (probably accidentally) blocking a majority of the entire
Internet from accessing the whole site for a few hours. 12 During the few days Pakistan
was blocking YouTube.com locally, many Pakistanis bypassed the block using a tool
called Hotspot Shield. 13 AnchorFree describes Hotspot Shield as a privacy tool: ‘‘You remain anonymous and protect your privacy.’’ 14 But AnchorFree makes money by injecting ads into Web pages, and users of the tool give AnchorFree complete access to all
data exchanged while Web browsing with the tool. AnchorFree implies (but never
explicitly says) that it does not monitor its users’ traffic, but it nonetheless has both
the ability to snoop on the data at any time and a business model based on processing
user data for advertisers. Thus, Pakistan is monitoring its citizens’ Internet traffic to
block content it does not like, and citizens are accessing the blocked content by using
a tool that circumvents Pakistan’s filters. But the circumvention tool is at least potentially just a monitoring tool for the different purpose of advertising.
To make sense of these cases, we need to understand what data are available on the
network and to whom they are accessible. Three sorts of data are vulnerable to surveillance on the network: routing information, the actual content of the data stream, and
contextual signatures. All Internet data packets must include the IP address of the ultimate recipient, and most data packets (including all Web and e-mail traffic) also include the IP address of the sender. Users can hide routing information on the network
by using proxies, like Relakks or HotSpot Shield, which forward communication between a client and a server. In addition to the routing data, the packets contain both
protocol-specific data (data about the URL requested, the referring URL, the user agent,
38
Hal Roberts and John Palfrey
Précédent

- 55/635

Suivant