Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Phorm attacks critics over 'illegality' claims

David Meyer ZDNet.co.uk

Published: 10 Apr 2008 12:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The company behind an ISP-based web-advertising user-tracking system has denied claims that what it is doing is illegal.

Phorm — whose Webwise and Open Internet Exchange (OIX) technologies were used by BT in a secret trial on its customers — says the Foundation for Information Policy Research (FIPR) is wrong to say the use of Phorm's technologies constituted unlawful interception under the Regulation of Investigatory Powers Act (RIPA).

Nicholas Bohm, the FIPR's general counsel, said on Sunday that "the illegality stems… from the fact that the system intercepts internet traffic". "Interception is a serious offence, punishable by up to two years in prison," he added. "Almost incidentally, because the system is unlawful to operate, it cannot comply with data-protection principles."

On Wednesday, a statement from Phorm argued there was "no interception issue in the Phorm system".

"FIPR asserts — under a very narrow interpretation of RIPA — that although we obtain user consent, without the explicit consent of each website, there is an unlawful interception under RIPA," the statement read. "We would point to the many important and valuable consumer internet services such as Gmail or spam filters where data from one side of the 'communication' is analysed for the purpose of showing ads or blocking spam. Under FIPR's interpretation such services would be deemed illegal."

On Tuesday the Information Commissioner's Office (ICO) issued a statement on Phorm's activities, in which it said any allegations of RIPA non-compliance were a matter for the Home Office, rather than the ICO. The ICO also said Phorm had already approached the Home Office to check it was complying with RIPA — a point that Phorm reiterated in its Wednesday statement.

"Our extensive consultations have led to only one conclusion — that Phorm's systems are legal under any full interpretation of the law," Phorm's statement read. Also in the statement, Phorm's chief executive, Kent Ertugrul, pointed out that FIPR had campaigned against RIPA when it was drawn up eight years ago, but was now using it to attack Phorm.

Read this

Feature
Corporate espionage: Not if, but when

When it comes to business-to-business theft of information, experts agree — it's best to assume it will happen to your company

Read more +

"We're delighted to have a dialogue with FIPR but it has to be in the context of how today's online world actually works and how to improve it for the future," said Ertugrul. "Our objective is to ensure the internet continues to be a vibrant and thriving community, where new developments can contribute greatly to user experience and safety."

Richard Clayton, FIPR's treasurer, told ZDNet.co.uk on Thursday that FIPR's issues with RIPA — such as the "way that police could self-authorise [interception]" — remained, but had nothing to do with the elements of RIPA forbidding the use of services such as Phorm.

"[Phorm's statement] is a wonderful piece of PR, but it had very little basis in reality," said Clayton. "[Phorm asked] the Home Office a rather general question about the way the things could be done," he added. "[The Home Office] gave an opinion, not a legal opinion, of their understanding of how the law was [to be applied] — it was essential to get opt-in permission from people whose outgoing traffic was being intercepted."

Clayton criticised the Home Office's view that incoming traffic from websites was publicly available, making it legal to intercept. "We agree to a large extent, but there are quite substantial areas of the internet which are not publicly available, but that Phorm will intercept," he said. "If, for example, you put up a webpage and publish the URL to your friends, asking them not to tell anyone else what the URL is, you have an expectation that no-one else will look at that page because you trust your friends. Phorm will be able to see your page, so we feel that for that reason they are intercepting traffic."

Clayton was also keen to point out that FIPR was not suggesting that Phorm itself was breaking the law. "What Phorm are doing is legal," he said. "It is the ISPs who are intercepting the traffic and giving it to Phorm — it is that that is illegal."

Intercepting traffic for spam-filtering purposes or for blocking denial-of-service attacks was a different matter, Clayton added, because RIPA contains an exemption for technologies that are needed to protect the functioning of an ISP's service.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
19 out of 19 people found this useful


Full Talkback thread

2 comments

  1. Correction Moley
  2. Initial Response Moley

Company/Topic Alerts

Create a new alert from the list below:







Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Did Microsoft stifle tablets and leave...

Dick Brass says so and he thinks he should know; he was the vice president of emerging technologies and launched the Tablet PC in 2002. What does he think went wrong? He blames infighting,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters