Readers: 20 | Updated: 06-19

Report: NebuAd Forges Packets, Violates Net Standards

Translate Into:

Hijackinghotspot_hmvh

An online advertising firm called NebuAd that pays ISPs to let it eavesdrop on web users doesn't just passively record traffic, but actively injects fake packets into responses from other websites in order to deliver cookies to users, according to a technical report released by the advocacy groups Free Press and Public Knowledge on Wednesday.

The report from the open net advocacy groups describes the system as a "browser hijack," comparing it with two classic hacker attacks.

NebuAd first drew widespread attention after Charter Communications, the nation's fourth largest ISP, announced it would try out the company's technology, promising that users would love having more targeted ads served to them. That announcement brought unwanted media and congressional attention to NebuAd, which had already installed monitoring boxes inside the network of at least one smaller ISP, WOW.

NebuAd has conceded that its boxes peer deep into internet packets to pull out URLs and search terms in order to classify each user's interests. That profile is then used deliver tailored ads on various partner websites.

But Free Press and Public Knowledge found that sometimes when a WoW subscriber visited Yahoo or Google, NebuAd faked an additional packet of data that appears to be the last part of the downloaded Google webpage. The extra packet included NebuAd-written JavaScript that directs users' browsers to a NebuAd-owned domain named faireagle.com, where the company drops tracking cookies from other domains and companies on the user's computer. These can be used later to deliver customized ads based off analysis of where people have gone on the web or what search terms they have used.

The report (.pdf) was written by Robb Topolski, an engineer who started consulting for Free Press after gaining fame by detecting Comcast's forgery of P2P traffic early last year. He testified about the ongoing packet forgery by Comcast at a Federal Communications Commission hearing at Stanford in April.

"NebuAd and ISPs together cooperate in this attack against the intentions of the consumers, the designers of their software and the owners of the servers that they visit," he writes.

Topolski compares the behavior of NebuAd with that of two common hacking attacks: cross-site scripting and man-in-the-middle attacks. In the former, a hacker finds a way to get his own malicious JavaScript executed on a page he does not own. In the latter, an attacker wanting to steal passwords or listen to a conversation gets access to traffic running between two parties and records it, or distorts a communication for his own benefit.

He also argues that NebuAd is violating core internet protocols, which stipulate that packets originate from devices at the edge, while devices in the middle are supposed to route the packets, not modify or initiate them.

NebuAd has been been unwilling to talk about how its technology and opt-out process works, how long it stores data, whether users can see or delete their profiles, or even whether anyone at the company has any relevant privacy policy experience. The company's only publicly available patent application is for a system that forges packets and replaces a website's banner ads with its own as the data flows from a website to a user's computer. But the company says it is not replacing other sites' ads. (The company claims to have filed for a patent for its complicated opt-out system, but it has not turned up in patent searches and the company has declined to send Threat Level a copy of the application.)

NebuAd did not respond to a request for comment or clarification of the report's findings by deadline. SEE UPDATE.

The group's report raises further interesting questions about the legality of the system, including whether the company could run afoul of trademark law by making a site like Google look as if it is installing  tracking cookies on a user's computer.

Charter has not yet begun the trials it announced for four cities in the U.S., but plans to very soon, according to a spokeswoman. Company executives also met with Congressman Ed Markey (D-Massachusetts) to discuss his concerns, and described the meeting as "productive," the spokeswoman said.

UPDATE Wednesday 3:45 p.m. PDT:

In response to Threat Level's questions about data access, retention and storage, NebuAd's VP of Marketing Janet McGraw writes:

NebuAd does not collect or use any personally identifiable information. Any non-personally identifiable information that is used is anonymous and cannot, by itself or in combination, identify a specific person.  Since a web user (ISP customer) is always anonymous within the NebuAd system, anonymous user profiles can never be linked to an identifiable web user. Therefore, we could not provide this information to a customer. However, a web user may opt-out at any time, at which time the profile would be immediately deleted.

NebuAd also took issue with the report, but did not dispute the technical conclusions. Instead, they say the report disregarded the company's policy of making sure ISP customers know the system is there and that they can opt-out.

They also defend the use of a tracking cookie calling it a standard practice of an ad network.

See Also:

Photo: Herby Hönigsperger / Flickr




From The Blogs

Internet Observation

2007
vConvert.net--视频格式转换好帮手
有很多网站都支持从YouTube和Google Video上保存你最喜欢的视频,但是除了保存到这个Flash视频外,其他你就不能做什么了。你需要下载转换器来转换视频,而且你还不能保证你能播放经过你手的... 查看全文

Persistence Unlimited

01-26
Special Report! Top 10 Time Management Booby-Traps in Goal Setting.
“Waiting is a trap. There will always be reasons to wait. The truth is, there are only two things in life,reasons and results, and reasons simply dont count.” Dr. Robert Anthony In my mind, the only w... 查看全文

KillerStartups.com - all

03-26
Maxiocio.net - The Best Music Videos
What it does If you love music videos but are looking for a bit more order than is offered from YouTube, then Maxiocio is definitely worth checking out. You’ll have to register but upon doing so, you ... 查看全文

Internet Observation

07-21
Maxiocio.net — 最好的音乐视频网站!
它是做什么的?      如果你喜爱音乐视频,但又希望能够找到一些比youtube有更多选择的视频的话,那么Maxiocio一定是值得你看得了。你需要在这个网站上注册,不过在此时候,你可以在上面上传你... 查看全文

/Film

10-09
Early Buzz Report: Oliver Stone’s W.
The reviews for Oliver Stones W. have begun to show up online, and aside from Josh Brolins magnificent performance, the buzz is pretty mild: Jeff Wells writes: Josh Brolins performance as George W. Bu... 查看全文

On Simplicity

09-17
Social Proof and Flying Without a Net
Im way more knowledgeable than the average person on a couple of pretty arcane topics. (Doesnt everyone?) Does that impress you? No? Well, in that case why dont you come to my house and check out the ... 查看全文

Business, Finance, Management

05-13
Reports on Proposals for the Project
Ⅰ. Name: NOW Legal AidⅡ. Assumption and plan:  Content of the project includes survey on the current situation of law, education to popularize legal knowledge, and legal aid.  By means of going deep a... 查看全文

Brian Kim.net

07-15
More Details on The Brand New Service BrianKim.net Will Offer
First, there was the launch of The Hidden Secret in Think and Grow Rich, the unification of the natural process of goal achievement. Then there was the DEFINITIVIE guide to finding and successfully pu... 查看全文

Thels Talk

07-15
If Porn Is Bad Why Is It The Net’s Billion Dollar Industry?
Take for instance the New York Times Magazine: It ran a cover story recently called “Naked Capitalists: There’s No Business Like Porn Business.” Its thesis: Pornography is big business–with $10 billio... 查看全文

Zen Habits

05-18
First Sprint Triathlon Completed! (Race Report)
I’m happy to report that I finished my first sprint triathlon this morning! I feel tired but really great. Here’s a report (was just posted on my training blog but thought you guys might be interested... 查看全文
More Articles