Not-phorm

Ian Batten ukcrypto at chiark.greenend.org.uk
Tue, 18 Mar 2008 19:34:07 +0000


On 18 Mar 2008, at 18:36, Ben Laurie wrote:

> Caspar Bowden wrote:
>> Purely hypothetically, has anyone any thoughts on the legal/ 
>> technical feasibility of designing a box for a "triple-play" Phish- 
>> begone/Ad-tastic/Snoop-o-matic service.
>> It would
>> a) do Phishing filters
>> b) do the Ad-targeting thing
>> c) implement lawful access requirements for ISP interception under  
>> RIPA
>> ...there is the intriguing possibility that ISPs could cross- 
>> subsidize the costs of (c) with revenue from (a) ?
>
> Why would this be any more legal than Phorm?

Hmm, I suspect the play would be ``well Mr Home Office, you can have  
this Layer-7 intercept capability we've previously claimed is too  
expensive and difficult, so long as we can keep the revenue from the  
adverts and have the spurious Phish-guard capability to soften up our  
customers''. If the Home Office, who ultimately are the gate-keepers  
of RIPA compliance, object to the adverts, well, they don't get the  
intercept capability.  Not hard to see how that then gets spun on the  
front page of the Daily Wail into ``civil liberties campaigners help  
terrorists plot on Interwebthing''.

Of course, that's not to say this hasn't happened already.  The Phorm  
box is clearly in exactly the right place to do LI, has roughly the  
right structure, and has had a surprisingly public imprimatur given by  
the Home Office.  Perhaps it's a double bluff: customers are softened  
up to accept the advertising by the purported Phish functions, while  
the Home Office is made complaisant (and I do like that word) by the  
promise of an intercept capability...

ian