4 ms·
In fact, it's already possibly (and easy) to obtain the un-anonymized browsing history of millions of people. I was part of a (journalistic) team that got their
by wotstowaway 10y ago
In fact, it's already possibly (and easy) to obtain the un-anonymized browsing history of millions of people. I was part of a (journalistic) team that got their hands on a free sample from a company that offers "website traffic analytics", and which uses browser extensions as well as mobile apps as their main surveillance tools.
The data set contained the complete browsing history of almost 3 million German Internet users, and except for a few popular sites (like Facebook), no URL cleaning/anonymization was performed at all.
So here we have a single provider that is able to capture the browser traffic of 5 % of the population already, and is ready to disseminate this data to anyone who can pay the price (even giving out months of data for free). As there are dozens more companies that collect data using a variety of ways, it wouldn't be surprising to me if you could stitch these individual data sets together to get the traffic of > 50 % of all Internet users, without having any central point of data collection.
So although the government is a real threat to citizens privacy, unregulated private actors are much more dangerous in my opinion.
- pmlnr 10y ago> So although the government is a real threat to citizens privacy That's not privacy which is under threat any more. Say you visit a website of random content in January. Website goes out of business, someone else buys the domain and puts flagged content on it in September. Now... how do you prove you were visiting a different site? Trigger an archive.org call on each and every site I visit? Dig up domain name changes? I've been dealing with DNS for 10+ years and I have no idea how to dig up historical domain owners, especially not with the hide options. This goes way, way beyond privacy issues.
- wotstowaway 10y agoConcerning historical domain data, there are several vendors (e.g. Domaintools) that provide this kind of information, and domain registrar information usually contains the registration date for the domain, so proving it was a different site is possible. You're absolutely right though that it's highly problematic if we use automated tools to analyze this kind of data, as many people can end up in the wrong category due to either flawed analysis methods or faulty data. Again I'd say that currently the greater threat comes from private companies that will use this data to build "shady" rating systems which will affect the daily lives of many people, without giving these people a chance to verify or oppose the data being used against them.
- pmlnr 10y agoNever before I protected private companies, but looking at the history if Europe, I fear governments more.
- pawelk 10y agoOr what if someone, say on an innocent blog, places an invisible iframe pointing to a flagged website? Now every visitor has that website in their logs without ever willingly visiting the URL and seeing any of the content.
- pbhjpbhj 10y agoWhich is why the measure used for criminal law is beyond reasonable doubt: if there is no other evidence than an historic visit to a domain that the police can't show contained criminal content then there's not going to be a conviction (indeed the CPS wouldn't even entertain carrying such a case). If on looking at your hard drive the police then find a cache of content supporting criminal activity you're certainly going to have a hard time if you're innocent. Do you know of any UK caselaw covering situations where people were convicted on the basis of having visited a particular domain and no corroborating evidence was found? Would be interested in reading how that went down.
- pawelk 10y agoI was trying to point out that: 1. It wouldn't be hard to pollute the logs with noise, and 2. At the ISP level there's no distinction between "browsing a website" and accessing the URL unknowingly. So let's assume no one will monitor these logs to fight thoughtcrime in real time, and it'll only be analyzed once someone becomes a suspect in a criminal investigation. Would it present as valuable evidence considering the points above? As to your question: no I don't, but it isn't unheard of for law enforcement around the globe to set up honeypots. But then again there's no need to look into ISP logs because they control the server.
- ebbv 10y agoSome portion of people who choose to install a browser extension being traceable is worlds different from the government mandating that ISPs track all internet activity of all U.K. citizens. That distinction should be plainly obvious.
- wotstowaway 10y agoBut most people don't know what happens to their data, and many don't even know that they're being tracked when the opt in to provide "anonymized usage statistics". Of course it's a completely different if the government forces total surveillance, but the impact on people's privacy can be just as bad or even worse.
- pbhjpbhj 10y ago>mandating that ISPs track all internet activity // Isn't it 'just' domains visited? I don't know if that's web or internet or what though.
- grey-area 10y agoSo although the government is a real threat to citizens privacy, unregulated private actors are much more dangerous in my opinion. Companies don't have a monopoly on violence and complete control over you life as governments do, also, they are not unregulated or above the law - this company for example is probably breaking several laws. Spy agencies on the other hand, regularly break laws with impunity or have the laws rewritten to allow unlimited storage (as recently in the UK). Governments are a much bigger worry when it comes to saving internet history as they have greater capabilities for capture and storage, and a simple policy change in 20 years could make everyone who visited a certain site a criminal liable to deportation or imprisonment.