Re: Anyone know if this news is true ? Airtel spying ...

Abhijit Gadgil <[email protected]> Thu, 11 Jun 2015 17:07:31 +0530
Newsgroups gmane.org.telecom.india-gii
Message-ID <CAOFWafjUDkn0EEPi5eMKT7yc6Q4cRvhST6oRS=U6e9rX=Nt=WQ@mail.gmail.com>
Injecting Javascript or for that matter HTML elements that are not
otherwise served by the original server are very common - In fact
there are companies - that show Advertisements based on this concept
alone (crazy agreed! search for html overlay Ads) . This is not even
like cookies. This is actually modification of the 'content'.

So, yes I'd not be surprised if airtel or any operator is doing that.
Heck - there are public domain documents that one can find (Cisco
manuals) - that Cisco allows one to 'insert' HTTP headers (called
X-HTTP headers) on HTTP requests (again possible only on plain HTTPnot
on HTTPS). I am pretty sure competitors must also be allowing such!

The way many of the websites are dealing with it is - through https.
So with https - that's just not possible for any intermediary
(trivially of course) to 'inject' content on the fly on web pages.
Unless of course when the originator (eg. Google, yahoo ) has some
deal with the telco (even then it's complicated, because they need to
get certificates for SSL and host content on behalf of the end guy and
so on) - but in that case it's much easier to get any 'user data' in
Out of Band manner than meddling with the web pages. I think this was
originally the idea in Airtel-0 where flipkart could underwrite the
data for participating in 'Network API' program (which in layman's
terms means - selling subscriber data). But back then people were too
much infatuated with 'net-neutrality' nobody paid attention to real
issue, which was of privacy (This is just my guess though, not far
fetched).

There's an initiate called 'https://letsencrypt.org/' which makes it
easier for any website to be https enabled.

There are downsides to end-to-end encryption though - eg. majority of
the content on the Internet (including your dog's video) is inherently
cacheable and hence can be served without wasting network bandwidth,
but thanks to end-to-end encryption - HTTP caching is nearly 'dead'
(except in end-host). There are ways to deal with that, but they are
non-standard.

So yes one is left to choose 'lesser of the evils'

On Tue, Jun 9, 2015 at 9:21 PM, Banibrata Dutta
<[email protected]> wrote:
> Things moved quickly since...
>
> Update:
> http://timesofindia.indiatimes.com/tech/tech-news/Airtels-mystery-code-raises-privacy-concerns/articleshow/47599548.cms
>
> On Tue, Jun 9, 2015 at 12:44 PM, Banibrata Dutta <[email protected]>
> wrote:
>>
>> http://www.storypick.com/airtel-sends-legal-notice-indian-coder/
>>
>> As per the above article:
>> Airtel (& Vodafone, but not clear if in India) are customers of services
>> provided by an Israel based company called Flash networks, who apparently
>> inject references to a Javascript that then tracks user behaviour, and
>> perhaps such information is shared back with the customers.
>>
>> An Indian hacker based in Bangalore found this and did an expose, but has
>> got a "Cease and Desist" letter from the Israel based company !! What
>> gives...
>>
>> --
>> regards,
>> Banibrata
>> http://www.linkedin.com/in/bdutta
>> http://twitter.com/edgeliving
>
>
>
>
> --
> regards,
> Banibrata
> http://www.linkedin.com/in/bdutta
> http://twitter.com/edgeliving
>
> _______________________________________________
> India-gii mailing list
> [email protected]
> https://lists.india-gii.org/mailman/listinfo/india-gii
>



-- 
अभिजीत

[ http://oltsm.wordpress.com ]

_______________________________________________
India-gii mailing list
[email protected]
https://lists.india-gii.org/mailman/listinfo/india-gii