Phorm attacks critics over 'illegality' claims

NEWS

The company behind an ISP-based web-advertising user-tracking system has denied claims that what it is doing is illegal.

Phorm — whose Webwise and Open Internet Exchange (OIX) technologies were used by BT in a secret trial on its customers — says the Foundation for Information Policy Research (FIPR) is wrong to say the use of Phorm's technologies constituted unlawful interception under the Regulation of Investigatory Powers Act (RIPA).

Nicholas Bohm, the FIPR's general counsel, said on Sunday that "the illegality stems… from the fact that the system intercepts internet traffic". "Interception is a serious offence, punishable by up to two years in prison," he added. "Almost incidentally, because the system is unlawful to operate, it cannot comply with data-protection principles."

On Wednesday, a statement from Phorm argued there was "no interception issue in the Phorm system".

"FIPR asserts — under a very narrow interpretation of RIPA — that although we obtain user consent, without the explicit consent of each website, there is an unlawful interception under RIPA," the statement read. "We would point to the many important and valuable consumer internet services such as Gmail or spam filters where data from one side of the 'communication' is analysed for the purpose of showing ads or blocking spam. Under FIPR's interpretation such services would be deemed illegal."

On Tuesday the Information Commissioner's Office (ICO) issued a statement on Phorm's activities, in which it said any allegations of RIPA non-compliance were a matter for the Home Office, rather than the ICO. The ICO also said Phorm had already approached the Home Office to check it was complying with RIPA — a point that Phorm reiterated in its Wednesday statement.

"Our extensive consultations have led to only one conclusion — that Phorm's systems are legal under any full interpretation of the law," Phorm's statement read. Also in the statement, Phorm's chief executive, Kent Ertugrul, pointed out that FIPR had campaigned against RIPA when it was drawn up eight years ago, but was now using it to attack Phorm.

"We're delighted to have a dialogue with FIPR but it has to be in the context of how today's online world actually works and how to improve it for the future," said Ertugrul. "Our objective is to ensure the internet continues to be a vibrant and thriving community, where new developments can contribute greatly to user experience and safety."

Richard Clayton, FIPR's treasurer, told ZDNet.co.uk on Thursday that FIPR's issues with RIPA — such as the "way that police could self-authorise [interception]" — remained, but had nothing to do with the elements of RIPA forbidding the use of services such as Phorm.

"[Phorm's statement] is a wonderful piece of PR, but it had very little basis in reality," said Clayton. "[Phorm asked] the Home Office a rather general question about the way the things could be done," he added. "[The Home Office] gave an opinion, not a legal opinion, of their understanding of how the law was [to be applied] — it was essential to get opt-in permission from people whose outgoing traffic was being intercepted."

Clayton criticised the Home Office's view that incoming traffic from websites was publicly available, making it legal to intercept. "We agree to a large extent, but there are quite substantial areas of the internet which are not publicly available, but that Phorm will intercept," he said. "If, for example, you put up a webpage and publish the URL to your friends, asking them not to tell anyone else what the URL is, you have an expectation that no-one else will look at that page because you trust your friends. Phorm will be able to see your page, so we feel that for that reason they are intercepting traffic."

Clayton was also keen to point out that FIPR was not suggesting that Phorm itself was breaking the law. "What Phorm are doing is legal," he said. "It is the ISPs who are intercepting the traffic and giving it to Phorm — it is that that is illegal."

Intercepting traffic for spam-filtering purposes or for blocking denial-of-service attacks was a different matter, Clayton added, because RIPA contains an exemption for technologies that are needed to protect the functioning of an ISP's service.

Talkback

My initial response to this news item is 'Phorm over my dead body', so I will vote with my feet. Actually, I am suspicious that my ISP is already installing the additional hardware.

I have read a technical brief here

http://www.cl.cam.ac.uk/~rnc1/080404phorm.pdf

about how it works and, even if (and that's a big if) it's not objectionable now, it could easily be extended to be so. In addition, it seems we must take a great deal on trust, something that is in short supply these days. Furthermore I would object to any take it or leave it change to my agreement with my ISP's.

Surely Phorm can also be compromised, possibly without much difficulty.

Can anyone clarify, is Phorm really blocked if its cookie is blocked, as suggested in the above technical brief, or will Phorm still have a look but then just deliver random adverts rather than targetted ones.

For those interested there is a meeting in London University with Phorm next Wednesday, see here for details

http://www.8020thinking.com/events.html

Moley 10 Apr 08 18:02 Reply

The meeting is on Tuesday, not Wednesday. Details below.

The Phorm system: a Town Hall dialogue and briefing

Tuesday April 15th, 18.30-20.30

The Lecture Theatre, Brunei Gallery, School of Oriental & African Studies, University of London, Thornhaugh Street, Russell Square, WC1H 0XG

Moley 10 Apr 08 18:15 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

lezlow

it is only greedy[microsoft]?

1 hour ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

2 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

2 hours ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

4 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

4 hours ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

miyabi81

Chatter preview http://www.zdnet.co.uk/news/application-development/2010/03/17/salesforce-opens-up-chatter-developer-preview-40088348/

cybfor

US gov t considers undercover social networking: [zdnet.co.uk] The Obama administration has considered sending... http://dlvr.it/Kh3L

sudipta_vodafone

Please give me chance in the vodafone essar Ltd as back office executive

11 hours ago by sudipta_vodafone on Vodafone culls 375 'mainly back-office' jobs
sudipta_vodafone

I want to get a back office job in vodafone direct payroll

11 hours ago by sudipta_vodafone on Vodafone culls 375 'mainly back-office' jobs
Xwindowsjunkie

I also find it harder to use. It used to scale properly in Firefox. Text would size up and down without dragging all the right edge debris with it....

14 hours ago by Xwindowsjunkie on ZDNet UK: faster, smarter, still IT all the way
dava4444

that comment bot is a nutter, it just referred me to the moderator on my own blog. shocked look. please help thank you Dava I'm afriad to...

18 hours ago by dava4444 on Welcome to the new ZDNet UK community!
dava4444

Hi Rupert! Don't think I could fill the above shoes... but if your ever looking for a consumer rights Tech blogger..tip me the wink lol peace Dava

19 hours ago by dava4444 on Fancy working for ZDNet UK?
dava4444

Hi Rupert My photo is gone from my profile and I just got told i was a spammer by the comment bot. the navigation is gone for my profile. :O on...

19 hours ago by dava4444 on Welcome to the new ZDNet UK community!
ator1940

With windows it is always more bloat, and a lot of that seems to be duplicated in various places. I've noticed that you will have freed space on...

1 day ago by ator1940 on Can you believe it - 2765 kB will be freed?
BuzzMyStat

Buzz My Stat : New search for http://www.zdnet.co.uk Take a look: http://www.buzzmystat.com/site/zdnet.co.uk

Karen Friar

Hi Jamie, I'm sorry your comment got caught in the spam filter. We use an industry standard blacklist for this. I suspect that the comment may...

1 day ago by Karen Friar on Spam? Filter Changed?
J.A. Watson

Pop - Neither have I. Ever, under any circumstances. I'm much more accustomed to Windows slowly, but inexorably, consuming more and more disk...

1 day ago by J.A. Watson on Can you believe it - 2765 kB will be freed?

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now