By Tom Espiner, 12 March 2009 11:09
NEWS
The inventor of the world wide web, Sir Tim Berners-Lee, has attacked deep packet inspection (DPI), a technique used to monitor traffic on the internet and other communications networks.
Speaking at a House of Lords event on the 20th anniversary of the invention of the world wide web, Berners-Lee said DPI was the electronic equivalent of opening people's mail.
"This is very important to me, as what is at stake is the integrity of the internet as a communications medium," Berners-Lee said on Wednesday. "Clearly we must not interfere with the internet and we must not snoop on the internet. If we snoop on clicks and data, we can find out a lot more information about people than if we listen to their conversations."
DPI involves examining both the data and the header of an information packet as it passes a 'black box' on a network, in order to reveal the content of the communication. Targeted advertising services, such as Phorm in the UK, use DPI to monitor anonymised user behaviour and to target adverts at those users. In addition, UK government initiatives such as the Intercept Modernisation Programme have proposed using DPI to perform mass surveillance of the web communications of the entire UK population.
Speaking to silicon.com sister site ZDNet UK at the event, Berners-Lee declined to comment about any particular company or government initiative but said internet service providers should not perform DPI.
"If [third parties] are using the data for political ends or commercial interest, there we have to draw the line," Berners-Lee said. "There's a gap between running a successful internet service and looking inside data packets."
Berners-Lee expressed concern that the UK government had taken no action over DPI, in contrast to the US government's response to the use of DPI by targeted advertising company NebuAd. Last autumn, the US Congress decided to review privacy concerns around the start-up, after which the company's chief executive, Bob Dykes, stepped down.
"I'm embarrassed, as a UK citizen and as a US resident, that the US has drawn a line firmly against DPI and this country hasn't," Berners-Lee said.
Nicholas Bohm, the general counsel for the Foundation for Information Policy Research, said the UK government may not have taken any action over DPI as it was in the process of developing the Intercept Modernisation Programme itself. "The government's desire to know all about us may be hampering it doing anything about others who are snooping," he said.
Kent Ertugral, the chief executive of Phorm, said his company had ensured that privacy principles are adhered to by anonymising the data it collects, while at the same time giving websites the ability to fine-hone their advertising. "We have created something that reconciles the need for privacy but also for commerce," said Ertugral.
Prominent cross-bench peer Lord Erroll said DPI to target adverts did not concern him as much as the UK government's plans.
"The Intercept Modernisation Programme worries me hugely more than [targeted advertising]," said Erroll. "The impact of an incorrect interpretation of communications by government means anyone could end up in jail, or worse. It's hugely dangerous."


Comments
There are 4 comments. Join the discussion
1. Dave Brown
This is something to keep an eye on. If DPI does indeed start to be used by government agencies or ISP's then we must all look at ways to scramble and annonomise our data - we ALL have something to hide - our Privacy. The intentions of the UK government have been plain to see for some time and we must all be on our guard to frustrate such efforts.
2. anonymous
I agree snooping and opening the payload is bad but not all DPI does that.
Most of it is used to optimise the existing networking infrastructure
Surely in these days of trying to keep costs and energy usage down that can't be a bad thing.
3. Richard Davies
Everyone should start heavily encrypting data that is sent over the internet.
Also, how can the data Phorm uses, be truely automonous when it manages to direct adverts back to a certain user? This must mean that there is a traceable link back to people?
4. RM
Hats off to Tim Berners-Lee for publically saying that many UK residents think. Any suggestions for good articles/books/websites about data encryption?