Groups: US Ad firm used by ISPs spies on users

A new report says a targeted ad vendor used by some ISPs hijacks browsers and eavesdrops on users

A targeted advertising vendor being used by several US broadband providers hijacks browsers, spies on users and employs man-in-the-middle attacks, according to a report released Wednesday by two advocacy groups.

NebuAd, a behavioral advertising vendor being used by Charter Communications, WideOpenWest and other Internet service providers, uses also packet forgery, modifies the content of TCP/IP packets and loads subscribers' computers with unwanted cookies, according to the report, released by Public Knowledge and Free Press, two Washington, DC, groups focused on digital rights.

"NebuAd exploits several forms of 'attack' on users' and applications' security," wrote report author Robert Topolski, chief technology consultant for the two groups. "These practices -- committed upon users with the paid-for cooperation of ISPs -- violate several fundamental expectations of Internet privacy, security and standards-based interoperability."

NebuAd violates Internet Engineering Task Force standards that "created today's Internet where the network operators transmit packets between end users without inspecting or interfering with them," Topolski added.

Representatives of Charter Communications and NebuAd didn't immediately respond to requests for comment on the Topolski report. Charter, in late May, issued a statement saying it was working with concerned lawmakers to address concerns about the targeted ad service.

"Charter takes the responsibility of protecting its customers' information seriously," the company said in a May statement. "We look forward to maintaining an open communication with policymakers to alleviate any concerns."

Charter Communications, a cable television and Internet provider based in St. Louis, announced in May that it was planning to use NebuAd to roll out a targeted ad program that would track users' Web activity in order to deliver "relevant" ads. That announcement by Charter, the fourth largest cable operator in the US, sparked calls for an investigation by several privacy and consumer groups.

Two members of the US House of Representatives Energy and Commerce Committee, Representatives Ed Markey, a Massachusetts Democrat, and Joe Barton, a Texas Republican, wrote to Charter in mid-May, asking the company to delay rollout of the plan until they could have a discussion about the proposal.

Any collection of cable subscribers' personal data without their consent "raises substantial questions" about whether it is legal under the Communications Act, the two congressmen wrote.

Topolski, in his report, says he tested a connection on WideOpenWest in late May and early June. NebuAd's service injected new script into his browser session, preloaded identifying cookies on his machine, and monitored his browsing, he wrote.

Topolski compared NebuAd's methods to browser hijacking, cross-site scripting and other forms of computer attacks. NebuAd is engaged in "eavesdropping on the content of Web messages as they were being sent and received," he wrote.

"This report shows that NebuAd's Internet wiretapping is highly questionable," Marvin Ammori, Free Press general counsel, said in a statement. "Phone and cable companies should press pause on NebuAd and any similar venture until consumers and members of Congress can address the serious concerns raised by this report."

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Bitdefender 2019

This Holiday Season, protect yourself and your loved ones with the best. Buy now for Holiday Savings!

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?