ICO compares TalkTalk's anti-malware trial to Phorm
By Nicole Kobie
Posted on 7 Sep 2010 at 08:00
The Information Commissioner’s Office has issued a mild rebuke to TalkTalk, comparing its new anti-malware system to that of controversy-strewn Phorm.
TalkTalk is testing an anti-malware system on its network that looks at the websites users visit to check for malware, adding URLs to a white or black list. Any users who opt into the system will be warned before visiting malware-ridden sites on the black list, the ISP has said.
While the ICO has not publicly condemned the trial, a Freedom of Information Act request submitted by Peter White and listed on MySociety's What Do They Know site, revealed the watchdog asked the ISP for full details of the system, following concerns that consumers hadn’t been warned before the trial started.
In a letter sent to the ISP, Information Commissioner Christopher Graham said he was “disappointed” the trial wasn’t mentioned by TalkTalk at recent meetings between the two organisations, especially “in light of the public reaction to BT’s trial of the proposed Webwise service”, referencing the behavioural advertising system from Phorm.
TalkTalk can hardly plead ignorance of the privacy furore surrounding Phorm. It was one of the three British ISPs that signed a contract with Phorm, before tearing up the deal last summer.
I am concerned that the trial was undertaken without first informing those affected that it was taking place
The ICO said TalkTalk couldn't hide behind the excuse that the anti-malware measures were merely being trialled. “I am concerned that the trial was undertaken without first informing those affected that it was taking place,” Graham said in a letter to TalkTalk at the end of July.
“You will be aware that compliance with one of the underlying principles of data protection legislation relies on providing individuals with information about how and why their information will be used," he added. "You will also be aware that these principles are not suspended simply because the information is being used for the purposes of a trial.”
Mark Schmid, communications director for TalkTalk, told PC Pro that his firm saw no parallels with the Phorm trials. "Our view is that it isn't the right comparison to draw."
Schmid stressed the system looks at websites, not user data, and said the vast majority of the queries TalkTalk has fielded about the system were from website owners wondering why their sites were being scanned, not from the ISP's customers.
TalkTalk has said the system will be opt-in and not look at secure https URLs.
While TalkTalk admitted in its response to the ICO that it should have “mentioned” the test to the watchdog, it added: “No personal data has been collected or processed, and accordingly there was no need to inform customers.”
The ISP also took aim at critical reporting and privacy activists. “It is unfortunate that the media and certain individuals have, without being fully informed, viewed the network testing of the service with suspicion,” it said.
The anti-malware system is expected to be rolled out by the end of the year.
A spokesperson for the data watchdog said it was keeping an eye on the trial. “The ICO is currently looking into the process by which TalkTalk collects data about websites visited on its network. We have requested further details about how data is used and will continue to monitor this service to ensure that it complies with the Data Protection Act.”
From around the web
Given browser security...
I would be pleased if our ISP did this.
Scanning websites and informing the user that it contains malware, before they get to see the site is great. I currently have a user's laptop with over 40 viruses on it, despite active protection and despite weekly cleaning.
If he was blocked from visiting websites that were infected with malware, it would save us time.
If they are really just putting up warnings and not do any additional logging of which users are visiting the dodgy sites, I can't see what the problem is.
If they are keeping a list of the visited sites and which users are ignoring the warnings, then there is something to worry about.
I think ISPs should take a more active role in security, even firewalling infected customer machines, so that they can only visit anti-virus/anti-malware sites until they are cleaned up and not letting them use any other ports, thus reducing the infection rate.
Too many users don't have a clue about security or malware, and think that the version of Norton 2002 that came with their PC is still protecting them... Heck, I found one Windows 95 machine a couple of weeks back, with a DOS based AV package that hadn't been updated since early 1996!
By big_D on 7 Sep 2010 ![]()
Surely you are aware that all the major browsers can use optional web filtering and that there are services like OpenDNS. However privacy demands that services like this need to be opt-in.
In any of the companies I've worked for, an employee with 40 viruses on their PC would be in disciplinary procedures.
By milliganp on 7 Sep 2010 ![]()
@milliganp
That sounds a bit harsh, given the likelihood that the user may have picked up one virus and that downloaded a payload of other infections.
By Shuflie on 7 Sep 2010 ![]()
talktalk option?
I did not get an option to join, TalkTalk just went ahead with out my permission.
By rkcl1 on 9 Sep 2010 ![]()
advertisement
- How to install Internet Explorer 9
- Maintaining and supporting IE9
- Plan your deployment
- Creating a custom browser package
- Search in corporate environments
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
- Can you send a truly anonymous email?
- Is it safe to send bank details over email?
- Sainsbury's Bank bans password storage
- MobileMe triggers credit card blocks
- How to stay safe against session hijacking
advertisement
