Re: Anyone know if this news is true ? Airtel spying ...
Abhijit Gadgil <[email protected]> Thu, 11 Jun 2015 17:07:31 +0530
| Newsgroups | gmane.org.telecom.india-gii |
|---|---|
| Message-ID | <CAOFWafjUDkn0EEPi5eMKT7yc6Q4cRvhST6oRS=U6e9rX=Nt=WQ@mail.gmail.com> |
Injecting Javascript or for that matter HTML elements that are not otherwise served by the original server are very common - In fact there are companies - that show Advertisements based on this concept alone (crazy agreed! search for html overlay Ads) . This is not even like cookies. This is actually modification of the 'content'. So, yes I'd not be surprised if airtel or any operator is doing that. Heck - there are public domain documents that one can find (Cisco manuals) - that Cisco allows one to 'insert' HTTP headers (called X-HTTP headers) on HTTP requests (again possible only on plain HTTPnot on HTTPS). I am pretty sure competitors must also be allowing such! The way many of the websites are dealing with it is - through https. So with https - that's just not possible for any intermediary (trivially of course) to 'inject' content on the fly on web pages. Unless of course when the originator (eg. Google, yahoo ) has some deal with the telco (even then it's complicated, because they need to get certificates for SSL and host content on behalf of the end guy and so on) - but in that case it's much easier to get any 'user data' in Out of Band manner than meddling with the web pages. I think this was originally the idea in Airtel-0 where flipkart could underwrite the data for participating in 'Network API' program (which in layman's terms means - selling subscriber data). But back then people were too much infatuated with 'net-neutrality' nobody paid attention to real issue, which was of privacy (This is just my guess though, not far fetched). There's an initiate called 'https://letsencrypt.org/' which makes it easier for any website to be https enabled. There are downsides to end-to-end encryption though - eg. majority of the content on the Internet (including your dog's video) is inherently cacheable and hence can be served without wasting network bandwidth, but thanks to end-to-end encryption - HTTP caching is nearly 'dead' (except in end-host). There are ways to deal with that, but they are non-standard. So yes one is left to choose 'lesser of the evils' On Tue, Jun 9, 2015 at 9:21 PM, Banibrata Dutta <[email protected]> wrote: > Things moved quickly since... > > Update: > http://timesofindia.indiatimes.com/tech/tech-news/Airtels-mystery-code-raises-privacy-concerns/articleshow/47599548.cms > > On Tue, Jun 9, 2015 at 12:44 PM, Banibrata Dutta <[email protected]> > wrote: >> >> http://www.storypick.com/airtel-sends-legal-notice-indian-coder/ >> >> As per the above article: >> Airtel (& Vodafone, but not clear if in India) are customers of services >> provided by an Israel based company called Flash networks, who apparently >> inject references to a Javascript that then tracks user behaviour, and >> perhaps such information is shared back with the customers. >> >> An Indian hacker based in Bangalore found this and did an expose, but has >> got a "Cease and Desist" letter from the Israel based company !! What >> gives... >> >> -- >> regards, >> Banibrata >> http://www.linkedin.com/in/bdutta >> http://twitter.com/edgeliving > > > > > -- > regards, > Banibrata > http://www.linkedin.com/in/bdutta > http://twitter.com/edgeliving > > _______________________________________________ > India-gii mailing list > [email protected] > https://lists.india-gii.org/mailman/listinfo/india-gii > -- अभिजीत [ http://oltsm.wordpress.com ] _______________________________________________ India-gii mailing list [email protected] https://lists.india-gii.org/mailman/listinfo/india-gii