These Web sites know who you are

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Brian Dunham has a hot Internet business idea, but he worries that someone will steal it. So last month, the 31-year-old San Franciscan blocked potential competitors from finding his brand-new Web site. When the rest of the world clicks on eframes.com, it sees a Web business that frames and ships digital photographs overnight. But four firms that Mr. Dunham views as likely rivals get only a dummy site sporting this message: "Coming in time for Christmas!" Known to insiders as Web-access blocking, this maneuver is made possible by the growing ability of computer programs to identify Internet users. In a little-known trick -- technically called "domain-name identification" -- Web sites can secretly see where visitors are coming from the moment they click on. The site can then choose to let them in or not. Or it can put up a substitute site. Or it can send them somewhere else altogether. Some companies are using this technique to elbow out competitors. Others are displaying customized ads that only some viewers can see. For a month or so earlier this year, DoubleClick, an Internet advertising firm based in New York, furtively put up three different editions of its home page. Most visitors saw one version, highlighting the firm's accomplishments. Employees of a rival firm could see only another version, with a special press release touting DoubleClick's capture of one of the rival's customers. Clients being wooed saw only a third version. "It's very stealth," says Christopher Saridakis, a DoubleClick vice president. It also offers a reminder that going online is hardly a private affair. "Most people think that browsing the Web is as anonymous as watching TV or reading a newspaper. But it's becoming more like wandering around a trade show with your name tag on," says Jason Catlett, president of Junkbusters, a privacy advocacy and consulting firm based in Green Brook, New Jersey. Even venture capitalists have to worry. New Internet firms have surreptitiously watched which investors visit their sites, and how often. This tracking tells them who is the most enthusiastic about their venture, and thus whom they should pursue for money. "Absolutely, it was helpful," says Flint Lane, the president of a firm that in January began offering an online bill-paying service called Paytrust. Companies also use this intelligence to size up potential suitors in acquisitions. "They huff out of the room, saying they're done, and then the company sees lots of hits on their site from those same people. They can predict they will be back," says Brad Burnham, general partner at AT&T Ventures. "It's interesting how naive people are about the footprints you leave in cyberspace," Burnham adds. Indeed, a sizable portion of the Australian government left footprints on one hot site. To protest a new Internet content law, sex-site owner Bernadette Taylor this summer posted a long list of agencies -- from the Nuclear Science Department to Tourism Tasmania -- whose Internet addresses showed up in her logs. Like all Web site operators, she could tell how much time each agency visitor spent on her site. "Viewing patterns suggest this was NOT research," she wrote about one agency. The White House and many government agencies also gather the Internet addresses of everyone who visits them. They say it improves their Web sites. Some also acknowledge that the data can help catch hackers and terrorists, who can be traced to their Internet service providers. One federal agency has grown skittish. The Internal Revenue Service says it has stopped collecting its viewers' addresses because of concerns that it was risking an unwarranted invasion of personal privacy. For companies, however, this viewer information has endless possibilities. Entire ad campaigns have been spun from viewing Web site viewers. For example, Al Noyes, senior vice president of marketing and sales at SmarterKids.com, says he discovered that contrary to expectations, people were shopping at his children's products site from office computers. "So we focused our ads on working mums and not housewives," he says. Blocking -- and its related tactics -- begins with the digits that identify every Web user. These unique numbers can't always be traced, and an estimated 30 percent of Internet users remain anonymous by using big services like America Online, which effectively shields its customers behind one Internet access point. One AOL user looks just like another to the digit tracers. But government agencies, organizations and companies often have their own Internet hookups, and when their employees go to the Web from their desks at work, they might as well shout out their employer's name. Operators of the Web site they are visiting can simply look up the visitor's Internet address in any of several reverse directories available free online (www.arin.net is one) and see the corporate name or agency behind the address. Conversely, the site operator can look up a rival company's Internet number and instruct its Web site to block any visitors coming from that address. It takes only five minutes to fix up a Web site to do this. No special software is needed, just simple codes that are familiar to most Web site administrators. When specified numbers come knocking, the computer can block, steer or misdirect the visitor in a matter of milliseconds. Some of the first to use this blocking technology were child pornographers, followed by hate groups and people who sell stolen goods. They looked up the digits used by government investigators and then programmed their Web sites to screen them out. But law enforcement officials soon caught on to the tactic, and a cat-and-mouse game ensued. When Detective Michael Menz of the Sacramento (Calif.) Valley Hi-Tech Crime Task Force sidestepped the block by purchasing Internet access through a local firm, for example, the pornographers tracked him down again and blocked that address as well. He now uses an undercover account, and says the last site he noticed that was blocking law enforcement agencies peddled pirated knockoffs of the film "The Blair Witch Project". Technology firms have been in the forefront of blocking competitors from sniffing around their Web sites. In August 1995, ExperTelligence, a Web development firm, noticed its trial software being openly downloaded by a rival, Allaire. "I couldn't let it go," says ExperTelligence executive vice president Robert Reali. So he looked up Allaire's Internet access code and designed a special Web site that only Allaire would see. It omitted the real Web site's list of customers, and offered only an old version of software to download. "It didn't bother us at all," says Benjamin Frueh, product manager at Allaire, which eventually discovered the block. "It's flattering for people to think you're enough of a competitor that they have to take these steps." Some blocking is pure spoof. A few months ago, Oracle employees who clicked on the Web site of their smaller rival Siebel Systems were whisked to Siebel's job opportunities page -- the only part of the Web site they could access. "It was especially funny because at the time they were trying to hire Oracle employees," an Oracle spokesman said. Siebel declined to comment. In the same vein, Cisco showed a holiday party picture to some of its competitors -- before sending them to the hiring page. Later, Cisco used a reverse-blocking technique to defend itself. A competitor was sending its Web site viewers to an outdated Cisco Web page in order to boast that its product was better. So Cisco grabbed all those referred viewers as they came in and bounced them to the updated site. "People are getting a lot more sneaky," agrees Peter Corless, an Internet services architect with Cisco. Much of the blocking that occurs is aimed at thwarting corporate espionage, and some security experts scoff at its ineffectiveness. A blocked executive can simply use a home computer to get into the site. "The good corporate spy is never going to go directly from A to B," says Mark Fabro, director of professional services of Secure Computing. "I'm going to use a private account." But often a blocker just wants to slow down any rival snoops until a new venture gets rolling. Says Dunham, the picture framer: "The longer we can keep people from jumping on it, the better." Advertisers have discovered their own uses for knowing who is visiting a Web site. They can pay for their ads to be shown only to select viewers. IBM for example recruited employees by posting ads on Web sites frequented by students. Every school -- whose Internet address would be detected by the Web sites -- got its own pitch: "Is there life after Boston College?" The technology is also allowing some very personal ads to turn up in seemingly public places. DoubleClick, the Web advertising company, once posted this banner on hundreds of sites throughout the Internet: "Congratulations on the twins, John Nardone." But the only people who could see the banner were Nardone and his colleagues at Modem Media, a DoubleClick client. "I was out for a few days and had 50 people forward me this cool thing," says Nardone. "They were seeing it all over the Web." Reali of ExperTelligence suggests that Web sites will soon be able to auction ad space based on the identity of incoming viewers. "If you can see it's really Bill Gates coming to your site, who would bid the highest to show him an ad on golfing?" he says. Web sites can't identify Gates, for now, but they can spot someone coming from Microsoft. Federal agencies only recently began posting privacy notices divulging that they gather Internet addresses. No law requires such disclosure, and only some companies have voluntarily followed suit. Inevitably, all this snooping around is prompting even casual Internet users to start masking their identity. Companies are selling services that promise to make any computer user entirely anonymous. But these programs have Internet addresses, too. And since computer hackers also use identity shields in their mischief, Web sites are starting to block these as well when they can identify the shields' own addresses. "If you're not going to show me who you really are, why should I give you any service?" says Michael Lambert, a computer security expert.

They can see you... Read about how and why in Surveillance , a ZDNet News Special.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

30 minutes ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

59 minutes ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 hour ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

2 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

2 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

2 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

3 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

6 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

7 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

7 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

8 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

9 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

10 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

19 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

1 day ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

1 day ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

1 day ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission