Detail Analysis of Phorm Modus Operandi (technical and business)

John Wilson ukcrypto at chiark.greenend.org.uk
Wed, 19 Mar 2008 17:05:31 +0000


On 3/19/08, Ian Batten <igb@batten.eu.org> wrote:
> http://yro.slashdot.org/comments.pl?sid=489948&cid=22777122

Interesting, thanks.

All the discussion I have read so far has resolved around browsers as
clients. However it's now quite common for HTTP to be used by other
programs for other purposes (XML-RPC, SOAP, REST clients, for
example).

I think it's almost impossible to argue that intercepting the Atompub
transaction I use to update my private Google calendar is legitimate.
Or, indeed, to argue that Google implicitly gives permission for the
conversation to be intercepted by exposing an endpoint for such a
transaction.

I wonder if the messing that Phorm does with the HTTP traffic could,
in fact, stop some of these programs working.

John Wilson