back to article Amazon's Silk looks creepily Phorm-ulaic

A trick question for you... What's the difference between Phorm's controversial WebWise system, and the kind of giant web proxy unveiled by Amazon yesterday? Technically, there isn't one. WebWise and Silk are doing exactly the same thing. Both intercept private web traffic – and massage it. Both also aggregate enormous amounts …

COMMENTS

This topic is closed for new posts.
  1. The Taft Hotel
    Flame

    The Fire is Renamed

    The SpyPad

  2. JeffyPooh
    Pint

    Simple solution to maintain privacy in the modern world...

    Browse websites and topics that you actually have no interest in whatsoever. They'll build a model of the insides of your head that will be completely wrong.

    For example, I pretend to like tech news, the space program, and pr0n.

    See?

    1. Dave 142

      Once on an airline questionaire I said I was a housewife on a business trip.

    2. Adam T
      Coffee/keyboard

      And then they'll try to sell you crap that you *really* don't want :p

    3. Rovindi
      Devil

      Mess with their heads...

      A mate of mine used to do a similar thing, pre Internet days. He´d pay a few pennies more on each utility bill, vote randomly and join various political parties, as well as express interest in publications such as People´s Friend (always good for a laugh), Readers Digest (Not Wives) a few more esoteric ones...

      Not sure what the net effect of this was, but he certainly enjoyed the sporting aspect of it, as his demographic would be entirely off kilter to any marketing company with access to his data.

    4. Voland's right hand Silver badge

      You underestimate the power of Bayes

      Trust me, you seriously underestimate how much a well written set of Bayes stats can get out of seemingly random information.

  3. Maurice Shakeshaft

    I trully don't understand why...

    Our regulators and politicians tolerate this.

    Even if there are no votes or £'s in it surely there is a moral and personal intrusion/privacy aspect to this. Have we suspended principled action in favour of expediency and pragmatism?

    'There is no point in fighting this battle because we can't win and the electorate don't really care, even if we think that in the long run the company is acting dangerously and in bad faith".

    Clearly I'm approaching this simplistically or I live in a different world. What have I missed, please?

    1. Anonymous Coward
      Anonymous Coward

      Because the politicians would love to have all that private and behavioural info on everyone but know they would be linched if they tried to collect it themselves.

      Rather let big corps keep going down this route and when the time is right just mandate that chosen governmemt regulator/quango gets access to all the info collected - for the good of the people you understand..

      ;-)

    2. MH Media

      Easily understood

      ..don't understand why... Our regulators and politicians tolerate this

      Because neither of these expensively-financed numpty squads have got a clue about the technical side. This is why we keep reading about millions of ciizens data being lost on CDs, or filing cabinets buried in landfill sites.

      The regulators have no teeth because they're driven/steered by the politicians.

    3. Anonymous Coward
      Devil

      Because ...

      Our politicians and regulators are owned lock, stock and barrel by huge commercial interests.

      If they were not, then existing legislation alone would have put the CEO's of all of these companies in jail and/or fined them billions.

      The fact this *never happens* is the proof they are all in the pockets of commerce.

      1. nyelvmark
        Meh

        No, no, you're not thinking this through...

        The truth is that David Cameron and Nick Clegg don't actually exist. All of our media are actually under the control of the weapons manufacturers, and they use the fake cinematography techniques that were developed in the days of the so-called Apollo landings to delude the ignorant.

        However, if you buy my patented magnesium-alloy delusion disruptor (available in all cranium sizes), the next time you see one of our leaders on TV, you will be able to see the strings.

        Why isn't there a "product placement" icon?

        1. TeraTelnet

          You are David Icke ...

          ... and I claim my £5.

  4. Anonymous Coward
    Anonymous Coward

    Why do they need it?

    I was very surprised as to why Amazon choose to do this given there's a dual core processor inside. Is the OMAP that slow?

    1. not_equal_to_null
      Stop

      Optional

      I was under the impression it's more to do with the round-trip time when requesting 100 or so assets (js, images, stylesheets, xmlhttp) to load one page. This silk stuff essentially does the actual loading of the assets server side, then squirts it all back down to you in one compressed gobbet of data.

      This removes the overhead associated with each individual request.

      This is all crap of course. If websites were written by proper, able coders instead of designers with a different hat on, the whole internet would be a better place.

      And that's the end of my rant. Cue flames.

    2. RichyS

      Bandwidth optimisation or some such nonsense, apparently. Odd, seeing as the Fire has no 3G*. Maybe future non-eInk Amazon tablets will.

      * I find browsing over 802.11n fast enough on an original iPad, so not sure why it wouldn't be in a Fire.

  5. Anonymous Coward
    Anonymous Coward

    Just who is on MY side?

    I do not want ANY tracking, cookies, Phorm, Faceebok, Google, etc...........[insert technology or company name here], monitoring or using my data or communications AT ALL in ANY way!

    So just who is on my side. How can I implement this without the hassle?

    I can't. Because those who are supposed to be on my side, are not!

    1. RTNavy
      Pint

      Just say no

      You could just stop browsing the web, then there is no lose of your private data. As long as your bank, credit companies, insurance companies, employer, government agencies don't lose your data due to poor security practices....So you should be safe!!!

    2. Anonymous Coward
      Anonymous Coward

      well....

      ..don't accept cookies,ever.

      Destroy all cards (loyalty, credit, debit) and pay only cash.

      Send letters, not texts and emails.

      if you must use email, use disposable account.

      It's not everything, but it's a start.

      1. The Fuzzy Wotnot
        Happy

        Yep...

        Next thing you're being followed down the street by badly dressed plain clothes officers from the anti-terrorist squad who need to know why you're not being a techno-slave like all the other good little citizens.

        Then you'll find yourself heading to room 101...sorry, Gitmo Bay and a nice comfy orange boiler suit with dark googles and matching gag!

  6. spencer

    The difference...

    The difference was that Phorm was deployed in secret - with no one's permission on top of a service that punters already paid for.

    Silk is something that is agreed to in the terms of service on the purchase of a heavily subsidised piece of hardware.

    That's the difference, and I think it's quite a large one.

    1. Anonymous Coward
      Anonymous Coward

      That's no difference

      It was deployed in secret as part of a trial. This is entirely separate (though reprehensible for different reasons) from the intended production deployment.

      Do you honest believe the only problem with for was a lack of open-ness ?

      Even opt in was rejected by those that were there.

      1. spencer

        Incentive

        Disregarding the lack of openness then:

        What was the incentive for Phorm? I can't remember there being one. It was a service which would snoop on your browsing habits and serve you up ads and in exchange the user got nothing.

        Silk has the incentive of a peice of hardware that is subsidised, and in exchange you use Silk, which may *or* may not snoop on your browsing habits (I don't think that's actually been established that it's the case).

        Also, if you read below it's an optional service anyway.

  7. Tom Reg

    There is a way out - your own silk server

    You could run your own silk on your own ec2 instance, and have all company machines use that as a proxy.

    Could also be a private service, but it would depend on how cheap of a machine you could run silk on.

    They don't have to open source it, just provide an installer for Linux.

    Of course the other way is for open source software to do make something with the silk API, then point your fire tablet at that.

    If its a good idea, then this will be done. The AWS team have good API, so it's likely the silk API is also easy to understand.

    1. Anonymous Coward
      Anonymous Coward

      or..

      they could just run the browser on the tablet, you know just like the others do? No need for Silk or snooping your web browsing.

  8. James 51
    Stop

    Would it be possible to buy the cheap hardware then put custom firmware on it? You could get the $199/£250 (just my guess at the £ price) tablet and then put a clean andriod install on. Or buy a $70/£89 kindle and put something on that lets you read .epub natively.

  9. dephormation.org.uk
    Big Brother

    Passive enforcement

    Its not passive acceptance... but passive enforcement that is the problem.

    Don't characterise people as gullible fools if, when they do take the trouble to complain to regulators, they are met with corruption and incompetence.

    This spyware is an obvious abuse of private/confidential communications. In effect mass personal & industrial espionage, illegal interception, and copyright theft.

    It should put people in jail.

    But here's a challenge Andrew... Complain to the Police. Complain to the ICO. Complain to the Home Office. Complain to the European Commissioners.

    And suffer the same shameless corruption people like me experienced when we railed against the crooks in BT/Phorm.

  10. Anonymous Coward
    Anonymous Coward

    Remarkably Gmail has continued to grow

    Which is probably why yahoo has jumped on the band wagon. When I was forced to accept the new T&Cs to access my mail I deleted everything and won't use yahoo again. The dozen or so pictures I have on flickr can stay until I get round to removing them also.

    1. Anonymous Coward
      Anonymous Coward

      So, I'm not the only one.

      The only @yahoo account I have left is the one I use as a spam trap.

  11. Adam T

    Low Price

    In other words, Fire is cheap because information about you is far more valuable.

    Someone's on the ball.

  12. jayp
    Thumb Up

    Silk via EC2 seems to be optional...

    and by optional, I mean opt-out.

    From their T&C (section 1, 4th paragraph)

    http://www.amazon.com/gp/help/customer/display.html/?nodeId=200775270

    "You can also choose to operate Amazon Silk in basic or “off-cloud” mode. Off-cloud mode allows web pages generally to go directly to your computer rather than pass through our servers. As such, it does not take advantage of Amazon’s cloud computing services to speed-up web content delivery."

    1. Anonymous Coward
      Anonymous Coward

      Should be opt in.

      1. jayp
        Meh

        good point - should've used this icon

    2. spencer

      amazing

      All this analysis and complaining and it turns out you can browse normally after all!

      Can't say I'm surprised, the webkit layout engine is pretty small and I'm sure it'd run fine given the specs.

    3. Dan 10
      Thumb Up

      Interesting...

      A performance comparison between the two methods could be enlightening.

  13. thejackle
    Big Brother

    Sounds great

    Now'll they'll be able to send my stuff without me having to go to the trouble of ordering it.

  14. Tim 94

    Sophos' own products do a man in the middle attack to sniff SSL traffic for web filtering. Why are they so alarmed by this?

    Opera has been proxying and shrinking web data for mobile devices for years and it was never a problem. This makes business sense for the consumer (faster page loads) and Amazon as less data will be sent over their 3G network.

    And the article should note this can be turned off, unlike Phorm.

    1. Anonymous Coward
      Anonymous Coward

      Some defence; mentioning sophos: whataboutery.

      Saying Phorm couldn't be switched off. It could.

      This has way more in common with phorm than people really want to admit. Why ?

      "But I like amazon, they wouldn't do anything nasty".

      1. system

        IIRC, Phorm required a cookie being set before it would switch off. That, in itself, was an issue, given that the only way your browser would send that coookie was if it thought you were requesting something from the relevant domain. So, with Phorm, what we actually had was a bunch of boxes sitting in the ISP, injecting fake redirects in to all requests and passing them through a seperate domain, checking the cookies, and then allowing traffic to pass unmonitored if the right cookie existed. You could never be certain that your traffic was not being monitored. It also meant that you had to "opt out" of phorm with every device on your network.

        With this system, what you have is a web browser set to use a proxy server. Switch off the proxy setting, none of your traffic goes to the proxy server. No fake redirects, no promises to not look at your data, no effect on other machines attached to your network, just a complete lack of connection to those proxy servers in the first place.

        So the two are actually quite different.

  15. Mike Brown

    thats why its so cheap

    this is almost a non story. "shock horror": company offers dicounted product, that is subsidized using adverts! Do you refuse to watch ITV too?

    there is a reason ipads and android tablets are £400 and this is £200. And data collection is that reason.

    1. Anonymous Coward
      Anonymous Coward

      > Do you refuse to watch ITV too?

      Hell yes! Although that's at least partly to do with their scintillatingly bad programs.

  16. JDX Gold badge

    Some people seem so very obsessed with forcing privacy upon me. They turn it into some huge idealistic idol and tell us anyone is EVIL who wants to use our data to make money.

    I'd trade that privacy for better service, but the privacy zealots seem hell-bent on taking away that freedom to choose.

    1. Anonymous Coward
      Anonymous Coward

      @ JDX

      "I'd trade that privacy for better service, but the privacy zealots seem hell-bent on taking away that freedom to choose."

      You missed the troll icon.

      No one has taken away your right to trade in your own personal data - the problem is when it is taken by default without the choice being made.

      If the advertising said "You can buy this device for £200, but we will monitor everything you do and use that knowledge to track your buying habits, which we will then sell to advertisers for a fortune" - you can make a choice.

      However, if the ad says "Buy our cool device for £200" then you cant make a choice about your privacy. At least not an informed one.

      Privacy cant be forced upon anyone but it can be taken away.

      By the way, in future can you end all posts with your full name, address and telephone number please. It will enhance your life experience.

  17. Anonymous Coward
    Anonymous Coward

    As a self-respecting geek...

    ... if the Kindle Fire has decent enough specs and when it inevitably gets 'rooted' and something like Cyanogenmod is available for it, I'll buy it, trash the Amazon install and snag myself a cheap Android tablet.

    That's assuming the CPU & Ram is decent enough...

    There's no way I'd use one under Amazons T&C's, as it's clear it's a 'shopping' tablet, with some serious privacy concerns, as has been pointed out in this article.

    But a cheap (depending on the UK cost, which I suspect will start out equivalent in £ as it is in $) and powerful stock standard gingerbread would float my boat.

    Going a step further, assuming the device is rooted to allow for gingerbread to be installed (which I'm sure it will be), I'll get a mate to buy me one in the US - sorted.

    1. Saigua
      Gimp

      More respect.(*,incr) over there in thread 30

      Shouldn't you rather emulate success of successive simultaneous update pushes, yet distribute tablet activity across a diametric of admiration in a group so you get the benefit of diversity; additionally of course working to enforce privacy rights, profiles, personal information audit, mathematical literacy and sensibility of the IME, portability of user (and vendor) value, and free use of regexes? How about easy modal switching from shopping to browsing RCS (all kinds,) conference video editing, compatibility with your byakko workout, and craft sewing so you never run out of cargo pockets for all those Fire.

      You bought *.pfb; would you be interested in #?.abf for -£32 12p and resale rights to PsyLocke v. My Li'l Pony?

  18. Tony Luck

    It sounds like silk would disable any client ad-blocking software (since the cloud server will pick up all the pieces and render the page) - but on the flip side, it means that the advertising companies don't get direct access to the data on who is looking at a page (since all the fetches will come from Amazon's cloud). Now Amazon will most likely sell that data to anyone who writes them a cheque - but I wonder what this does to the business model of pay-per-view ad-supported sites. Probably all bad for them - while pay-per-click is still OK.

    1. Anonymous Coward
      Anonymous Coward

      For it to work properly Amazon's servers will need access to your cookies and other browser state, so they can impersonate the client. So advertisers won't notice the difference unless Amazon chooses to hide that information.

  19. Camilla Smythe

    Eh?

    "Amazon, like Phorm, is betting that you don't care enough about privacy to shop elsewhere. And from the gradual privacy ratchet, and the certain absence of opposition from rivals – nobody wants to poison the well – it may well succeed."

    In part correct but, and it is not a trick question.. Perhaps you might care to read that statement again and point out where you went wrong.

    Thanks.

    1. nyelvmark
      Thumb Down

      read that statement again and point out where you went wrong.

      Well, I'm not Andrew, but you intrigue me. I've read the passage you quote several times, and I can't see what you're objecting to. I would ask for a clue, but you seem to think it's "not a trick question".

      So, what the fuck are you talking about?

  20. Tony McAlinden
    Holmes

    Time To Coin A New Word

    And that word is Privacytard.

    Sheesh, in what way is this different from what Opera Mini has been doing (quite brilliantly I may add) for the best part of a decade?

    The most "evil" that's likely to come of this is the "Amazon recommends..." email and sidebars will target something you've been browsing. Know what, there isn't yet "No Click" ordering. No one is *making* you buy these products.

    If you're that susceptible to advertising then more fool you.

    1. Steven Roper
      Stop

      You, Tony, ARE susceptible, whether you know it or not

      Ever watched a gentleman by the name of Derren Brown? Think you've got the Jedi cojones to beat masters like him at his own game?

      Think again, buddy.

      The people behind the advertising industry have been studying human behaviour for decades, with one only objective in mind: to get inside your head and make you want to buy what they're selling, by fair means or foul. This is an industry that lacks any semblance of morals or respect for human sovereignty and dignity; if there were a means of directly controlling your mind to make you go out and buy something, they'd use it without any compunction and with smiles on their sociopathic faces.

      And these people know how to get inside your head. Why do you think all these companies are going to such incredible lengths to find out everything you do with your life? The better they know you, the better they can figure out what your weaknesses - your Achilles' heels - are, the better to exploit those weakness in ways you will not even be aware of.

      Trust me, Tony. I've worked with such people professionally. I, too, once thought as you did - that I'm immune to the kind of psychological manipulation employed by them. One of them, after talking to me for a mere 5 minutes, was able to make accurate statements about my interests, personal life and even sexual preferences despite the fact that I had volunteered none of it. He then proceeded to demonstrate - and this was with full knowledge aforethought on my part - how the advertising industry uses that information to manipulate you. After a few minutes, he had me ready to actually buy his laptop off him, despite the fact that I neither needed one nor that buying it would have meant not eating that week. Only the fact that he didn't really want to sell it stopped him - and me.

      Mate, I'm 45 years old and I didn't come down in the last shower. Those who know me describe me as intelligent, articulate, and observant, if a bit abrasive. I don't usually miss a trick. But this guy, with his years of training, ran rings around me. And it's people like him who work out how to get into your head with advertising, and make you do things you wouldn't normally do. And yes, Tony, he'd run rings around you too, whether you're prepared to admit it or not. That's not a reflection of your intelligence mate, it's simple honesty about what years of training and studying people can do. To think otherwise is deluding yourself.

      So I, like many others who harbour no false illusions about what the advertising industry is and what it's capable of, don't want these bastards building detailed profiles on me. I don't want to be profiled and analysed and decompiled as if I were some computer program, for the mere purpose of emptying my wallet. When I do buy something, I'd like it to be my own decision, rather than the result of some mindbending marketroid pushing my buttons.

      So I won't be using the Fire or Amazon's Silk service. But where I object to your stance is that if too many people approached privacy with your attitude, pretty soon those of us who still value it won't have any choice, because privacy-invasive companies like Google, Facebook, Amazon and the rest, would then be the only way to get anything done, because they - and all their customers like you - will have subsumed any alternatives.

  21. dfgraham
    Trollface

    My postal code has been H0H 0H0 for years when asked. Santa Clause gets a lot of credit card offers... (That is an actual valid, Canadian Postal code.)

    1. Anonymous Coward
      Anonymous Coward

      According to much of the Internet, I live in Beverley Hills.

  22. FIA

    Is it really a good or bad thing, or just a thing, indicative of the way society is heading? In the end it will be a success as most people don't care for the details in the face of the perceived advantages, I mean it is faster after all, a swoosh told me so. (The other day right, I blunk and when I'd finished the page hadn't even loaded, "The past tense of bl" it said, and nothing more.)

    At the end of the day, people like shiny stuff, and these things are all just used to better sell you the shiny stuff you really didn't think you knew you wanted. If you don't buy it they won't come. (Mind you, you do have to suffer the occasional odd look from shopkeep, "but, it's 20% off, and it is only your soul??")

    TBH It's things like the silent creeping network of ANPR cameras that's springing up roundabouts, I mean they're owned by the people in charge and they're incompetent enough to not think before using it. ("WE KNOW WHERE YOU PARKED LAST SUMMER!!")

    Mind you at the end of the day the proles did all seem happy, whistling away outside the windows; maybe that's the important thing.

  23. Old Handle

    I could be mistaken...

    But it looks to me like you can simply download another browser from Amazon's own app store. Certainly there's potential to be evil here (if they do prohibit other browsers, for instance, that would be a real bad sign) but let's give 'em a chance huh?

  24. Juillen 1
    Facepalm

    Apart from the new wi-fi model, none of the other new models are getting an intro to Europe or the UK.. Shame really, as they were looking interesting..

  25. Sirius Lee

    What are you lot on about?

    Take the post from @not_equal_to_null. Sure, in an ideal world there'd be a single html page. Done. The world is not simple and the reality is that people don't want simple site (try it, see how many visitor you get).

    The proxy argument is specious. Unless you have bought an actual IP address (and only large companies and telcos can afford to) you are working through a proxy. You always have done. Been irreparably harmed?

    Finally, the processors used in tablets are not up to the task of rendering a modern web page fast enough for many users. That's the tradeoff: long battery life vs speed of processor. So Amazon is using cloud services to render the page an deliver the one HTML package so the tablet only needs to render a relatively simple page.

    If you are concerned about the use of remote processing don't buy the product. BTW, since it's Android, you'll probably be able to use the native browser. See this is choice.

    I know in Britain, being a nanny state, we're not used to choice but not everyone is so sqeamish. Maybe some posting here, those who seem to prefer having everything government mandated, should lobby the government to produce a browser that's acceptable. Maybe create an ISP too. Though my guess is that the same state (the one some here want to protect them) would soon make changes to their creation that would make Phorm look like childs play (in the interests of public safety of course).

  26. VinnyR
    Big Brother

    Why do people think therer should be anything in it for them?

    Well these are businesses providing a service. If you don't want them spying on you, don't use them. As they say, nothing comes for free. If you want to use the service, you have to pay the price. In this case you give your personal browsing habits.

    It just depends what price you are willing to pay.

  27. Anonymous Coward
    Anonymous Coward

    Thank you

    for your coverage of this topic.

    For even more, see http://iheardacouplethings.blogspot.com/2011/09/we-didnt-start-fire.html

This topic is closed for new posts.

Biting the hand that feeds IT © 1998–2020