<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Twisty little passages, all alike</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Fri, 05 Dec 2008 08:44:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-30053</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Sat, 01 Nov 2008 15:10:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-30053</guid>
		<description>@Jonah
&lt;i&gt;In other words does it only Profile on Port 80 or on all ports when using the HTTP Protocol?&lt;/i&gt;

See paragraph #3 of &lt;a href="http://www.cl.cam.ac.uk/~rnc1/080518-phorm.pdf" rel="nofollow"&gt;my report!&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>@Jonah<br />
<i>In other words does it only Profile on Port 80 or on all ports when using the HTTP Protocol?</i></p>
<p>See paragraph #3 of <a href="http://www.cl.cam.ac.uk/~rnc1/080518-phorm.pdf" rel="nofollow">my report!</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonah</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-30048</link>
		<dc:creator>Jonah</dc:creator>
		<pubDate>Sat, 01 Nov 2008 13:57:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-30048</guid>
		<description>Something I meant to ask some time ago, if a Web Server does this is the Phorm/Webwise System supposed to follow with Profiling or abort the Operation?

{www.anywhereh.com redirection code to www.anywherh.com:7034} 

In other words does it only Profile on Port 80 or on all ports when using the HTTP Protocol?</description>
		<content:encoded><![CDATA[<p>Something I meant to ask some time ago, if a Web Server does this is the Phorm/Webwise System supposed to follow with Profiling or abort the Operation?</p>
<p>{www.anywhereh.com redirection code to <a href="http://www.anywherh.com:7034" rel="nofollow">http://www.anywherh.com:7034</a>} </p>
<p>In other words does it only Profile on Port 80 or on all ports when using the HTTP Protocol?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonah</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29604</link>
		<dc:creator>Jonah</dc:creator>
		<pubDate>Fri, 18 Jul 2008 15:19:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29604</guid>
		<description>Richard I fully understand the implications of doing this but BT have a contract with me to provide WWW internet access &#38; as far as I know they do NOT have the right to intercept my traffic.

The moment I am blocked from access to the WWW I will politely ask BT to properly reconnect me to the WWW or give me a MAC to go elsewhere as "they have broken their contract to provide WWW access"!

Since BT intercepted my traffic in 2006 &#38; 2007, I am very likely to have that happen again!</description>
		<content:encoded><![CDATA[<p>Richard I fully understand the implications of doing this but BT have a contract with me to provide WWW internet access &amp; as far as I know they do NOT have the right to intercept my traffic.</p>
<p>The moment I am blocked from access to the WWW I will politely ask BT to properly reconnect me to the WWW or give me a MAC to go elsewhere as &#8220;they have broken their contract to provide WWW access&#8221;!</p>
<p>Since BT intercepted my traffic in 2006 &amp; 2007, I am very likely to have that happen again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29482</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Fri, 04 Jul 2008 17:51:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29482</guid>
		<description>@Jonah

If you do #1 then, because of the way Phorm works, you will not be able to browse to any website.  I don't think that the ISP is likely to "remedy this" by any other method than telling you that putting 127.0.0.1 in your hosts file for the webwise.net domain is anything other than a damn fool thing to do. The other entries are unlikely to have any practical effect one way or another. Have a further read of how the system works!</description>
		<content:encoded><![CDATA[<p>@Jonah</p>
<p>If you do #1 then, because of the way Phorm works, you will not be able to browse to any website.  I don&#8217;t think that the ISP is likely to &#8220;remedy this&#8221; by any other method than telling you that putting 127.0.0.1 in your hosts file for the webwise.net domain is anything other than a damn fool thing to do. The other entries are unlikely to have any practical effect one way or another. Have a further read of how the system works!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonah</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29480</link>
		<dc:creator>Jonah</dc:creator>
		<pubDate>Fri, 04 Jul 2008 15:08:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29480</guid>
		<description>If such a System goes "live", I would actually recommend #1.

Your ISP has a contract with you to provide access to the Internet through their switching device, the moment they cut off your Browsing they have cut off your Access &#38; they are obliged to remedy this!</description>
		<content:encoded><![CDATA[<p>If such a System goes &#8220;live&#8221;, I would actually recommend #1.</p>
<p>Your ISP has a contract with you to provide access to the Internet through their switching device, the moment they cut off your Browsing they have cut off your Access &amp; they are obliged to remedy this!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29424</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Sat, 28 Jun 2008 13:29:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29424</guid>
		<description>@v4vendetta

#1 no don't do this, it will break things
#2 this should work (and if it doesn't I expect they'll fix it)
#3 this is rather over the top and will affect your browsing in other ways

might I suggest #4, which is to change ISP ?  though even that may not be needed since no-one has rolled the 'service' out yet.</description>
		<content:encoded><![CDATA[<p>@v4vendetta</p>
<p>#1 no don&#8217;t do this, it will break things<br />
#2 this should work (and if it doesn&#8217;t I expect they&#8217;ll fix it)<br />
#3 this is rather over the top and will affect your browsing in other ways</p>
<p>might I suggest #4, which is to change ISP ?  though even that may not be needed since no-one has rolled the &#8217;service&#8217; out yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: v4vendetta</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29423</link>
		<dc:creator>v4vendetta</dc:creator>
		<pubDate>Sat, 28 Jun 2008 11:47:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29423</guid>
		<description>Phorm counter-measures

1)

Edit your 'Hosts' file...

Start --&#62; Run --&#62; Type:

notepad "c:\windows\system32\drivers\etc\hosts"

Add the following line to the bottom of the file:

127.0.0.1       oix.net
127.0.0.1       oix.com
127.0.0.1       phorm.com
127.0.0.1       webwise.net
127.0.0.1       webwise.com
127.0.0.1       sysip.net
127.0.0.1       qkilbdr.net
127.0.0.1       121media.com
127.0.0.1       openinternetalliance.com
127.0.0.1       openinternetalliance.net
127.0.0.1       youcanoptin.com
127.0.0.1       youcanoptin.net
127.0.0.1       youcanoptout.com
127.0.0.1       youcanoptout.net

File --&#62; Save

File --&#62; Exit

(You may, at first, have go into the file's temporary and untick the 'Read-only' box).

(HEY MOD! Have I got the first bit right, this time)?

2)

Visit http://www.dephormation.org.uk/ and Download the Dephormation v2.1 Firefox Add On.

"The Dephormation Add On ensures that your decision to permanently opt out of Phorm profiling cannot be undone in Firefox.

Optionally, the Add On can also alert you to sites using Phorm/ Webwise/ OIX profile based advertising.

With each page you view in your browser, a Phorm 'opt out' cookie is set automatically, and the Phorm UID cookie is randomised. Even if you delete all your cookies regularly".

3)

Visit http://www.torproject.org/ and install TorBrowser, a Windows Browser Bundle (Containing Tor, Torbutton, Polipo, and Firefox).</description>
		<content:encoded><![CDATA[<p>Phorm counter-measures</p>
<p>1)</p>
<p>Edit your &#8216;Hosts&#8217; file&#8230;</p>
<p>Start &#8211;&gt; Run &#8211;&gt; Type:</p>
<p>notepad &#8220;c:\windows\system32\drivers\etc\hosts&#8221;</p>
<p>Add the following line to the bottom of the file:</p>
<p>127.0.0.1       oix.net<br />
127.0.0.1       oix.com<br />
127.0.0.1       phorm.com<br />
127.0.0.1       webwise.net<br />
127.0.0.1       webwise.com<br />
127.0.0.1       sysip.net<br />
127.0.0.1       qkilbdr.net<br />
127.0.0.1       121media.com<br />
127.0.0.1       openinternetalliance.com<br />
127.0.0.1       openinternetalliance.net<br />
127.0.0.1       youcanoptin.com<br />
127.0.0.1       youcanoptin.net<br />
127.0.0.1       youcanoptout.com<br />
127.0.0.1       youcanoptout.net</p>
<p>File &#8211;&gt; Save</p>
<p>File &#8211;&gt; Exit</p>
<p>(You may, at first, have go into the file&#8217;s temporary and untick the &#8216;Read-only&#8217; box).</p>
<p>(HEY MOD! Have I got the first bit right, this time)?</p>
<p>2)</p>
<p>Visit <a href="http://www.dephormation.org.uk/" rel="nofollow">http://www.dephormation.org.uk/</a> and Download the Dephormation v2.1 Firefox Add On.</p>
<p>&#8220;The Dephormation Add On ensures that your decision to permanently opt out of Phorm profiling cannot be undone in Firefox.</p>
<p>Optionally, the Add On can also alert you to sites using Phorm/ Webwise/ OIX profile based advertising.</p>
<p>With each page you view in your browser, a Phorm &#8216;opt out&#8217; cookie is set automatically, and the Phorm UID cookie is randomised. Even if you delete all your cookies regularly&#8221;.</p>
<p>3)</p>
<p>Visit <a href="http://www.torproject.org/" rel="nofollow">http://www.torproject.org/</a> and install TorBrowser, a Windows Browser Bundle (Containing Tor, Torbutton, Polipo, and Firefox).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: popper</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29284</link>
		<dc:creator>popper</dc:creator>
		<pubDate>Thu, 05 Jun 2008 06:23:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29284</guid>
		<description>more twists today richard, from Alexander's new NoDPI page

http://digg.com/tech_news/BT_commited_113_million_allegedly_illegal_acts_in_8_days

"BT commited 113 million allegedly illegal acts in 8 days
nodpi.org — [EXCLUSIVE] An article summarising an internal report by BT regarding their covert trials of PageSense (Phorm) in September 2006. IP addresses were used (despite BT assuring the public and ICO that no personally identifiable data was used) and 130 000 charity ads were hijacked and replaced with Phorm's ads.

...
"
http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-532.html#post34567434</description>
		<content:encoded><![CDATA[<p>more twists today richard, from Alexander&#8217;s new NoDPI page</p>
<p><a href="http://digg.com/tech_news/BT_commited_113_million_allegedly_illegal_acts_in_8_days" rel="nofollow">http://digg.com/tech_news/BT_commited_113_million_allegedly_illegal_acts_in_8_days</a></p>
<p>&#8220;BT commited 113 million allegedly illegal acts in 8 days<br />
nodpi.org — [EXCLUSIVE] An article summarising an internal report by BT regarding their covert trials of PageSense (Phorm) in September 2006. IP addresses were used (despite BT assuring the public and ICO that no personally identifiable data was used) and 130 000 charity ads were hijacked and replaced with Phorm&#8217;s ads.</p>
<p>&#8230;<br />
&#8221;<br />
<a href="http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-532.html#post34567434" rel="nofollow">http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-532.html#post34567434</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david M</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29225</link>
		<dc:creator>david M</dc:creator>
		<pubDate>Wed, 28 May 2008 00:19:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29225</guid>
		<description>BTW Richard, 
Tharrick and ravenheart both got a reply from EU Commisioner today, read it here
http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-485.html#post34560783

scans here
http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-486.html#post34560921

and a news post related to this official EU stance 
"...The data concerned in this particular matter i.e. the content of search queries, constitute communication within the meaning of this Directive and the URLs used in the packets constitute traffic data. This data should therefore be protected appropriately..."
here for a digg and link
http://digg.com/tech_news/EU_Commission_respond_to_the_publics_complaints_about_Phorm</description>
		<content:encoded><![CDATA[<p>BTW Richard,<br />
Tharrick and ravenheart both got a reply from EU Commisioner today, read it here<br />
<a href="http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-485.html#post34560783" rel="nofollow">http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-485.html#post34560783</a></p>
<p>scans here<br />
<a href="http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-486.html#post34560921" rel="nofollow">http://www.cableforum.co.uk/board/12/33628733-virgin-media-phorm-webwise-adverts-updated-page-486.html#post34560921</a></p>
<p>and a news post related to this official EU stance<br />
&#8220;&#8230;The data concerned in this particular matter i.e. the content of search queries, constitute communication within the meaning of this Directive and the URLs used in the packets constitute traffic data. This data should therefore be protected appropriately&#8230;&#8221;<br />
here for a digg and link<br />
<a href="http://digg.com/tech_news/EU_Commission_respond_to_the_publics_complaints_about_Phorm" rel="nofollow">http://digg.com/tech_news/EU_Commission_respond_to_the_publics_complaints_about_Phorm</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david M</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/18/twisty-little-passages-all-alike/#comment-29213</link>
		<dc:creator>david M</dc:creator>
		<pubDate>Fri, 23 May 2008 22:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=321#comment-29213</guid>
		<description>sorry about that, and sammy's point,just above that...

"When originally asked about Phorm- KE and Co stated that the profile created can be transfered from one ISP to another.

ie. Once a profile is created using my VM connection, I can use another PC or lets BT, and the Profile created will deliver the same ads, as if I was on my home connection.

Which clearly shows something has been missed, in respects of our analysis - to deliver this Phorm must have the capability to transfer the data from VM to BT, then BT to CPW and so on. 

To do this will depend on far more more than a mere Cookie dependant on your browser. 

IMO Phorm's System, using the methods they claim to, must Intercept clearly indentifiable PII to reference with the profile they save for the user. 
"</description>
		<content:encoded><![CDATA[<p>sorry about that, and sammy&#8217;s point,just above that&#8230;</p>
<p>&#8220;When originally asked about Phorm- KE and Co stated that the profile created can be transfered from one ISP to another.</p>
<p>ie. Once a profile is created using my VM connection, I can use another PC or lets BT, and the Profile created will deliver the same ads, as if I was on my home connection.</p>
<p>Which clearly shows something has been missed, in respects of our analysis - to deliver this Phorm must have the capability to transfer the data from VM to BT, then BT to CPW and so on. </p>
<p>To do this will depend on far more more than a mere Cookie dependant on your browser. </p>
<p>IMO Phorm&#8217;s System, using the methods they claim to, must Intercept clearly indentifiable PII to reference with the profile they save for the user.<br />
&#8220;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
