9 ms·
Yes, ISPs can snoop on you to a degree, but I don't see how it's worse than Facebook or Google. ISPs have to work around widespread (and growing) encryption, wh
by ereyes01 9y ago
Yes, ISPs can snoop on you to a degree, but I don't see how it's worse than Facebook or Google. ISPs have to work around widespread (and growing) encryption, while Google/Facebook have your _actual_ data... plus, they know way more about you in minute detail via their mobile apps and devices. My home internet is VPN'ed and unless my ISP is expending undue effort on monitoring me, it can't see much detail about what I do on the Internet. However, Google/Facebook break all the security layers because we explicitly _trust_ them with all our data. Unless something fundamentally changes (maybe via net neutrality somehow allowing ISPs to penalize encrypted traffic or something), I don't see how Facebook/Google don't run away with all the power here.
- throwawayjava 9y ago> ISPs have to work around widespread (and growing) encryption, while Google/Facebook have your _actual_ data. Today. But in terms of risk moving forward, I think ISPs are way worse. Two reasons: 1) I really can choose not to use Google/Facebook. There exist very solid, privacy-respecting alternatives for every service these two companies offer. It's a matter of consumer choice. This is not the case for ISPs. If my (one) local "high-speed" ISP demands that I install a new root cert so they can MITM all my traffic, my choices are to a) capitulate, or b) find a way to live with very low-speed DSL/dial-up. Monopoly power backed up by a vast network of cables has way more staying power than monopoly power backed up by social network effects (FB) or superior software offerings (Gmail). 2) You might argue that history demonstrates we don't have to worry about ISPs demanding to MITM customer traffic. But Historically, ISPs weren't incentivized to snoop because of regulatory barriers that prevented collection/use of data for advertising purposes. In the case of US ISPs, changes in regulator landscape suggest that past behavior doesn't guarantee future behavior.
- mehrdadn 9y ago> If my (one) local "high-speed" ISP demands that I install a new root cert so they can MITM all my traffic I don't see what sense it makes to worry about that before it actually happens. Especially when there's no reason to believe it is going to happen.
- throwawayjava 9y agoSee (2) from my post. Also, from another top-level comment ATM: >>I recently received a "terms of service" update from Comcast, with the notification that they can now "monitor and record anything going through the network. Including, but not limited to: audio recording, video recording, ..." I mean, look, if they're not going to do it, then why did they lobby so hard and successfully to do it? Frankly, I have a had time imagining that this won't eventually happen. And sooner rather than later.
- paulie_a 9y agoYou can't choose to not use Facebook unless you just go completely offline
- throwawayjava 9y agohttps://gist.github.com/thomasbilk/1506210/2d20f47bbcca75b2f78d6909c1637501000d846f https://gist.github.com/thomasbilk/1506210/2d20f47bbcca75b2f... Not to mention there's a LOT of useful stuff on the internet that's not hosting on sites with Facebook trackers.
- walshemj 9y agoSo choose a different ISP not all countries have the USA's broken telco regulation LLU is what you need.
- ocdtrekkie 9y agoYou just admitted you do have the same choice for ISPs: You can choose to live with a degraded option/experience. In the same way, many would argue leaving Google or Facebook requires they give up on key features and benefits of living on the Internet. Like, you know, talking to your friends.
- drawkbox 9y agoCouple devil's advocate points on what ISPs can do to get encrypted traffic, since they are your network gateway there is more instilled trust: - ISP offered 'apps'. Get people to agree to an install of some monitoring app for some [insert random marketing benefit] from ISP. Maybe if you install the app you get more data cap space etc and they can monitor browser access. Further, install this in known apps or as add-ons on setup for other apps. - ISP offered 'VPN client' that again, gives some cheaper monetary benefit like more data cap space or more speed 'free', strips out other advertising or tracking as a benefit. - ISP offered 'email client' that does all of the above. - Check for subsequent request after page loads to known ad networks and replace with their own in HTTPS - ISPs like you said may start throttling encrypted content down, or charging extra to allow it. - ISP level proxy MITM, modem customization for 'fast lanes' that are actually slow lanes. - DNS level data collection not to inject but to sell marketing profiles via metadata and correlate with other data from apps. Since ISPs are your 'gateway' to the internet and you pay them, most people assume trust and privacy, most don't know they bribed their way into the tracking/ad business, many didn't know cable tv modems had mics either. With that assumption of trust since people are paying them, they'll more easily fall for any of the possible attack/tracking vectors listed and more probably. With the ISP privacy protections removed [1], my guess is most ISPs, due to lack of competition, end up more like hotel wifi where tracking/injection is the norm [2] as it is completely legal now. With the removal of privacy protections and net neutrality, we have killed the pristine, non tracked, private gateways to the internet we cherish. [1] https://www.flake.senate.gov/public/index.cfm/2017/3/flake-introduces-resolution-to-protect-consumers-from-overreaching-internet-regulation https://www.flake.senate.gov/public/index.cfm/2017/3/flake-i... [2] https://medium.com/@nicklum/my-hotel-wifi-injects-ads-does-yours-6356710fa180 https://medium.com/@nicklum/my-hotel-wifi-injects-ads-does-y...
- ereyes01 9y agoThis makes sense, though I don't see how various "carrots" like faux-value-add spyware will penetrate the market significantly, since they likely can't beat Google/Facebook in actual delivered value. Also, spyware / crapware already has a pretty bad rep, and will likely be flagged by system scanning tools on traditional PCs (maybe not mobile devices though). Your other points about how they can (ab)use their position as the gateway to chip away the effect of encryption by laying various roadblocks (I guess the proverbial "stick" in the "carrot/stick" trope) seems like it could have some teeth if the ISPs really doubled down on this strategy. I expect they will have to overcome significant controversy in order to be successful on a mass scale (but we'll see I guess). Encryption has gotten much easier and more widespread in recent years, and is growing. If the ISPs had really focused on attacking it a few years ago, they could've nipped their surveillance competition in the bud, but now it's a harder problem for them to deal with. Not 100% insurmountable, as parent explained.
- fulafel 9y agoIf your isp colludes with advertisers, they can associate the vpn traffic using traffic analysis.
- bogomipz 9y agoCan you explain how this works?
- fulafel 9y agoI don't know if it's being done. The web requests your browser sends to ad networks (or other colluding web properties) from vpn exit addresses, when analyzed as an aggregate, can be identified based on their time/length signatures. These would be correlated by the isp with traffic between vpn termination addresses and customer addresses. ISP can resolve a customer address to person. Advertisers could add unique timing and size features to make this easier.
- closeparen 9y agoThey know the address they provide service to.
- jka 9y agoFor the layman user (likely 99%+ of these ISP user populations), using an ISP essentially provides near-entire browser history to them, at least to the granularity of domain name. A surprising number of sites (and/or assets, images, etc) still don't use TLS, and so for those it's also possible for an ISP to understand what the user was reading/accessing. Even for sites which do support TLS, if the ISP hypothetically had a partnership with a single data broker / advertiser which was also on the page, it's likely not hard to have a pretty precise idea of their interests/viewing. You're right that Google and Facebook will continue to have very narrow and precise information about people's daily lives; it's simultaneously true that ISPs will continue to have broad & ongoing profiling information across any touchpoints as people use the internet.
- closeparen 9y agoFacebook and Google are not repositories to which you entrust your data for private safekeeping. The point of Facebook is to communicate with other people. The point of Google is to interact with shared repository of knowledge that learns from its own utilization. There is inherently a multi-party interest in everything Google or Facebook has about you, except for maybe never-shared Google Docs. Bank vault analogues for private data do exist: iCloud, Dropbox, Crashplan, etc. If “your data” needs to leave your physical possession, that’s the sort of service it should go to.
- HenryBemis 9y agoiCloud: Apple has the keys :( Dropbox: Dropbox has the keys :( Crashplan: I have the keys :)
- oarsinsync 9y ago> Crashplan: I have the keys :) Do you really? They offer a web interface with access to your data. Do you enter the encryption keys when you access the web interface, or do you enter a username and password which then provides access to the encryption keys? In that situation, who really has the keys?
- username223 9y agoIIRC, with Crashplan (RIP) you get a choice of whether to encrypt everything with a local key, in which case you're SOL if you lose it, or to encrypt with a key known to Crashplan, in which case you can reset your password and they can see your data. That seems like a reasonable trade-off to me, where different users will make different choices.
- closeparen 9y agoCrashplan still works fine, you just have to get the business-branded version.
- ThoAppelsin 9y agoI, too, use encrypted VPN, but we are just a minority. Many people use the services provided as-is without taking any extra measures, and I think that those are the people more likely to be influenced by the influencers anyway. We, the ones that they'll have to spend undue effort to sniff out a profile about, are not targets to them. We are much too resistant to it that we have gone all through the effort of setting up a private VPN with good encryption.
- troncjb 9y agoI am the same as you, but I worry the opposite. Using an encrypted VPN in a sea of unencrypted traffic paints a big target on you that says "Im doing things I don't want you to see". You can bet they are working on / can already decrypt and some three letter agency is targeting specifically VPN traffic.
- tyfon 9y agoI don'ẗ think you have to worry, I have never had a job that didn't require encrypted vpn to access the internal networks away from the office. The only company I know of that puts everything in public so to speak is google. So VPN traffic is very common.
- troncjb 9y agoGood to know , thanks
- ryandrake 9y agoHopefully no more than using an envelope instead of a postcard marks you as hiding something.
- kardos 9y ago> I, too, use encrypted VPN, but we are just a minority. You're right that VPN usage is technically a minority [1], but it is well beyond fringe usage. [1] https://cdn2.hubspot.net/hubfs/304927/Downloads/VPN-Usage-Around-the-World-Infographic.pdf https://cdn2.hubspot.net/hubfs/304927/Downloads/VPN-Usage-Ar...
- wuliwong 9y agoI mostly agree with you. From my perspective the data that Facebook has on me is far better than anything my ISP could have collected thus-far. I am in an area where I have more than one option for high speed internet and it is a pain to change but not even close to the amount of pain I would experience by deleting Facebook and Instagram. Doing that would cause fundamental changes to my social life. None of my friends are even aware that I switched ISPs last year. I think if the article was written in the spirit of "watch out for the ISPs too" instead of "the ISPs are so much worse" I would have been more onboard. I think it's a bit apples and oranges: all my traffic with low resolution or just my social traffic in high resolution. I don't clearly see one being far more dangerous/valuable than the other.
- JoshMnem 9y agoThere are other privacy problems with wireless hotspots too. A new example: you can't log in to Starbucks' wifi (via Google) without verifying a real email address through Experian's API. (Open the browser console and watch the requests -- see if you can use a fake email address.) Who knows where all that data is going. Most hotspot providers are probably tracking your physical locations by MAC address, which can be linked with other data. It looks like Peet's recently started doing that as well.
- alasdair_ 9y ago> A new example: you can't log in to Starbucks' wifi (via Google) without verifying a real email address through Experian's API. (Open the browser console and watch the requests -- see if you can use a fake email address.) I used a fake address yesterday without issue.
- JoshMnem 9y agoA fake address meaning one that you don't own, or a fake address meaning one that doesn't exist at all? You might have entered someone else's real email account that exists in Experian's databases, which could be another serious problem waiting to happen.
- BeetleB 9y ago>while Google/Facebook have your _actual_ data... Is it _your_ data, or is it _their_ data? I'm asking in both the literal (based on terms of service, etc) and the more abstract way? Obviously, for the latter, it is a combination. I wish the narrative was discussed with that in mind. Most of what I tend to see is a widespread assumption that the user owns the data, and has given companies like Facebook very limited powers, and that somehow Facebook is breaking that trust. That narrative is, IMO, rubbish. We gave them very broad powers, and the users should accept the consequences. >However, Google/Facebook break all the security layers because we explicitly _trust_ them with all our data. If we explicitly _trust_ them, then are they _breaking_ anything? It just seems silly when we explicitly say (as many of my friends have said in the past) "I don't care what Facebook does with my information" and then we talk about it as if they are doing something wrong (using words like "break"). When I give my bank all my money with the understanding that they can hold it, as well as lend it, we don't refer to it as "breaking" anything.
- cpeterso 9y agoISPs have your credit card number and home address. They can link your online and offline lives. Google and Facebook have detailed social graph and search query, but your ISP could piece together a lot of that information by tracking your DNS queries, unencrypted HTTP traffic, email if you use their mail servers, and offline information.
- ocdtrekkie 9y agoAnyone who's ever bought an Android app has also given Google their credit card number and home address. Also, Facebook and Google can both determine your home address by where your phone (and it's location tracking) idles for several hours a day. Google buys access to credit card providers so they can link the ads displayed to you with purchases you make, to report how effective the ads are to the advertisers.
- mantas 9y agoWhy would ISP have credit card number? I pay my ISP with old good wire transfer.
- paulie_a 9y ago> wire transfer Which will include everything interesting about your identity. It literally is equivalent to using a debit or credit card
- mantas 9y agoMy ISP already knows my name. Nothing else gets sent along. My bank account number is not useful unless they get my history from my bank. Which is not likely to happen. There's no 3rd party payment processor involved that could collect a bunch of my activity and then sell it to someone. With wire transfers, they'd have to go to everybody who I'm paying and ask for the data. Which is much less likely.
- jacquesm 9y agoIf you use a VPN then you have just moved all the access that your ISP had to your VPN service provider. It doesn't really change much.
- hsivonen 9y agoTechnically not but in terms of company practices or legal environment it can change a lot. For example, are $US_ISP and F-Secure in the same bucket in practice?
- akvadrako 9y agoI think using a VPN actually increases risk, because it makes you suspicious.
- icebraining 9y agoNowadays, not really, plenty of people use them to avoid geo blocking.
- akvadrako 9y agoPlenty like under 0,1% ? That doesn’t make it less of a target.
- icebraining 9y agoIt's hard to get reliable numbers, but Global Web Index puts it at about 5% of the US internet users, so over 10 million people.
- akvadrako 9y agoThat's an absurd number for users of any kind of geo-unblocking DNS service, especially in the US where you barely need it.
- rainsford 9y agoI agree with you, but there's also a business model aspect I think you're missing. Your ISP might be interested in monetizing your personal data to add to the ways they make money, but for companies like Google and Facebook, making money from your personal data is basically their entire business model. Given enough opposition, Verizon, Comcast, etc, could strongly embrace personal data privacy and still continue as companies. Yes, they'd lose a business opportunity, but they still make a lot of money selling you internet access and that wouldn't go away. The same is not really true of companies like Google or Facebook. Collecting and making money off your personal data is the foundation of their business. Strongly protecting your privacy would require them to change their entire way of making money. I think you could argue either way whether Google or Verizon has more ability to spy on you, but Google absolutely has a stronger business motivation to collect your data than Verizon does.
- weej 9y agoI agree with you, but there is one key difference...you are paying your ISP for the service. Google, FB, etc. provide free service offerring in exchange for your data. If ISPs are going to monetize customers traffic then their terms of use better damn well call that out. There is potential here for new business model for privacy based ISPs (ex: think duckduckgo for ISP) where customers pay a premium for such an offering.
- jiveturkey 9y agoNo there isn’t. Where in the world can you select your ISP? in a meaningful way.
- qaq 9y agoIf this is a serious question in Kiev I had a choice of 4 high speed providers at a cost of about 1/10 what equivalent xfinity service is costing me here :)
- ocdtrekkie 9y agoI have three major ISPs available where I live that can over 100+ meg service.
- throwaway59140 9y agoI was hoping to read through the comments and find someone would correct you, but it seems everyone is under the same false belief. Encryption doesn't matter. Automated deep packet and encrypted packet inspection is burgeoning with advances that put the single-actor work-arounds to shame. 1). Your ISP knows your traffic is encrypted. It knows what cipher and protocol you're using, and its routing is not protocol-agnostic. 2). Your ISP knows beyond "mostly confident" the type of files your packets contain. If you don't keep your connection open and use any of the public encryption methods, your ISP will know exactly what you've downloaded to a reasonable degree. 3). HTTPS is only as good as all the different pieces combined (browser, root CA, server, site, client). And if one of those goes bad, it's worthless. 4). If you use encryption heavily, you're already flagged. 5). If you don't use your ISP's CDN, you're already flagged. 6). If you connect to any other site besides Google, YouTube, Reddit, Twitter, Facebook, Wikipedia, or Instagram your aggregate data will be quickly analyzed and compared with a threat table, and appropriately flagged. 7). Traffic analysis is trivial when you're the one routing the traffic. Google is Dunning Kruger evil. ISPs are "pick up that can" evil. The lack of serious developments in HTTPS are "see no evil" stupid. The thought that HTTPS is anything but a red hearing is "Ivan the Fool" stupid.
- thebongoboy 9y ago>If you connect to any other site besides Google, YouTube, Reddit, Twitter, Facebook, Wikipedia, or Instagram your aggregate data will be quickly analyzed and compared with a threat table, and appropriately flagged. Huh? What are you talking about? >If you use encryption heavily, you're already flagged. >If you don't use your ISP's CDN, you're already flagged. What types of encryption? Since when did ISPs make users use a CDN? Again, I don’t get what you’re saying. Sources and more information would be greatly appreciated.
- jbros 9y agoThis sounds about right. I came to most of these conclusions myself after trying to build a secure personal VPN . Oh what a fool I was.
- jeff_tyrrill 9y ago
- written 9y agoGoogle doesn't need to break encryption for other reasons too. It has JavaScript execution access and thus access to all the client side data on at least the half of the top 1mil. websites on the internet. It's easily blockable for people who care, but still many don't, and for those people it makes all the pretty transport encrytpion a sham. Seriously, companies afford third parties JavaScript execution on pages where they expect me to enter CC or other sensitive info. Half of the web at this point is a joke when it comes to security and privacy.
- chiefalchemist 9y agoFB sees you on FB. The others can follow you everywhere. They know where you live. They know who you phone. They know who phones you. It's even. Death by drowning, or death by car crash is still death. The fact that Uncle Sam isn't concerned about the intrusions tells us whose side he's on.
- xorcist 9y agoI think you underestimate the prevalence of the like button. Facebook runs code in your browser on lot of other web pages out there. Probably second only to Google.
- chiefalchemist 9y agoYes. I agree. That said I can't remember the last time I liked something outside FB. Liking a comment has to be tough to surmise "intent." p.s. fwiw I'm getting to the point where I'm going to like and follow things just to leave a false trail. Can't hurt. The fact that typically my FB feed is so shite only tells me they have a long way to go before they analyze the signals I provide them.
- theclaw 9y agoYou don't have to explicitly like anything for FB to track your usage on practically every website that has a Facebook button. The fact that the site displays the like button in your browser is enough to give Facebook whatever info Facebook wants about your activity on the site.
- chiefalchemist 9y agoOk. Fair enough. But there are borwser extensions to block that, yes? Note: That's not a tit for tat counter attack but a question. Tia
- drderidder 9y agoSeveral years ago I joined a stealth-mode spinoff of a large telecom equipment manufacturer, and worked on deep-packet inspection (DPI) on 10Gb/s fiber-optic networks. The initial motivation for the project was a desire by telecom companies to obtain personally identifiable information and profiles for targeted advertising, and as we learned, a number of other interesting use cases, like reducing customer churn. At the NOCs there were a number of various servers in racks that were getting a feed of raw traffic for a variety of purposes. It wasn't a free-for-all, but it was eye-opening. I recall reading through a Cisco router manual for example (not the company I worked for) and seeing its port-mirroring capabilities blatantly promoted as a means for customer profiling and targeted advertising. Outside of the telecom industry itself there was quite a bit of resistance to this sort of thing, and we had to go before the US Congress to explain what we were up to. Profiling for the sake of profiling was not smooth sailing, but if it was for the purpose of "security" then it was more or less a free pass. The forcus of our DPI technology turned to the task of network-based threat detection as its primary raison d'être, with customer profiling being an opt-in service by which users could obtain the security service in exchange for targeted ads. In the years since, I don't expect that Telecom's desire to be much more than a "dumb pipe" has diminished in the least. They view the traffic they carry on their networks to be their property, in a way. They feel entitled to inspect it, throttle it, slice and dice it any conceivable way they can to maximise their profits. Its one of the reasons I quit. Imagine the US postal service steaming open every letter and opening every package that went through their system, so they could plug your mailbox with targeted special offers or increase the delivery fees for certain things. Its all similar BS with ISPs, but it's all techie stuff and heavily lobbied so the public gets bamboozled. You raise a really good point about wide-spread encryption being an impediment to ISP profiling. But there is a LOT you can surmise from user traffic even if you don't know the exact content of the encrypted payloads. Just analyzing IP addresses and times can reveal a ton of information about a person. My first patent [US20100161795] was in fact a NAT session detection and tracking technique to identify and track individual users within a household through TCP/IP analysis. Using this technique someone could get a pretty clear picture of how many people were in a household, their ages, genders, interests and patterns of activity, even without delving into the http payload of the packets. We didn't, but this kind of thing is most definitely possible, and I wouldn't trust other shady entities not to do it.
- StanislavPetrov 9y ago>but I don't see how it's worse than Facebook or Google. They are worse because you are forced to use an ISP if you wish to access the internet. >However, Google/Facebook break all the security layers because we explicitly _trust_ them with all our data. Nobody informed who cares about their privacy ever entrusted Google or Facebook with any personal information.