ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Phorm accused of making web browsing 'less stable'

Tom Espiner ZDNet.co.uk

Published: 17 Apr 2008 15:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts have criticised targeted-ad company Phorm, claiming the nature of its infrastructure could increase the likelihood of successful denial-of-service attacks against its ISP customers.

Dr Richard Clayton, a security expert from the University of Cambridge, published a paper earlier this month detailing Phorm's infrastructure. Clayton found that part of Phorm's system involves mediating web-page requests between users and ISPs. A browser request is first sent via a switch to a machine on the ISP network, which then redirects the user to the Phorm Webwise server to have an anonymised cookie attached to it, allowing Phorm to serve targeted ads to the user.

In the process of attaching the cookie to the browser session, the request is bounced to the ISP machine three times. These request bounce-backs would magnify any denial-of-service attack, according to Clayton, and could also create incompatibilities with browser-security measures.

"Because they start with three redirections before users are led to the real site, browser heuristics could say that this was a dodgy site, which is unwise," said Clayton on Wednesday. "Also, by sending sufficient crafted packets to the [Phorm] web server, attackers would get more bang for their buck, and the net effect would be [that] the server would not resolve anyone to the ISP."

While Phorm could always just switch off its web server in the event of attack, said Clayton, he said the system makes browsing the internet "more complicated and less stable."

A spokesperson for Phorm denied on Thursday that users would experience any problems with the stability of their web browsing.

"We disagree that Phorm will downgrade the experience of the internet," the spokesperson told ZDNet.co.uk. "From a commercial standpoint, it would be entirely stupid for us to downgrade the user experience, as ISPs buy in[to the service]."

Phorm was also criticised by security company F-Secure in a Tuesday blog post, which drew attention to Phorm's past work and reputation. Phorm was previously named 121Media, with a brand called "PeopleOnPage", the wrapper around the ad engine ContextPlus. F-Secure said that 121Media was responsible for developing pieces of adware, including Apropos. In the blog post, F-Secure described Apropos as containing "one of the most widespread, malicious rootkits of 2005".

On Thursday, Phorm denied that Apropos had contained a rootkit but admitted that it did contain code to hide itself from other pieces of adware. "Apropos wasn't hidden; users could uninstall it," said the company's spokesperson. "Competing pieces of adware would attempt to uninstall it, so [the code was hidden] to stop the effects of unscrupulous other adware. The company is not stealth-based."

The spokesperson added that Phorm had ceased trading as 121Media, as that brand had gained a reputation for serving spyware, but said that such a reputation was undeserved.

"We have never denied that we were in the adware business," the spokesperson wrote. "Such a business is involved in the legitimate bundling of ad-serving technology with free software applications, willingly and knowingly downloaded by users. It is the very fact that people were always unable to distinguish between legitimate adware and illegitimate spyware that caused us to do something unprecedented. As the only publicly traded adware company, listed on the London Stock Exchange with Fidelity and a series of other blue-chip shareholders, and the former chairman of Microsoft UK as our chairman, we unilaterally discontinued our entire revenue stream, concluding that the spyware association was inconsistent with our long-term goals."

More technical details of how Phorm systems work can be found in a paper by Richard Clayton. 

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
8 out of 12 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

ISP Network Architect Designer 60,000 NW

My client is a leading ISP firm using only the best technology available. Minimum 5 years in a network design environment gained in an ISP or telco ...

Hosting Architect (ISP)- Leeds - 55000 + Benefits

Are you currently working for an ISP? Apply Now if you have relevant ISP industry experience. Looking for a new challenge? My client is a new and ...

ISP Specialist Productr Manager Required Manchester 40k

My client, a leading ISP in the North-West is looking for a Windows based Hostings & Co-location product manager to join their developed team. This ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation