TalkTalk Snoops On Customers’ Web Activity

Broadband provider TalkTalk has been caught monitoring and recording its customers’ online activity without their consent.

The situation first came to light when a TalkTalk customer noticed two “guest” IP addresses appearing in his web server logs, and brought the issue up on the ISPs discussion forum. Several other users discovered they were being tracked by the same IPs, prompting a fierce privacy debate among TalkTalk customers.

TalkTalk has since admitted to the monitoring, but claims it was a necessary part of the testing process for a new anti-malware system it is developing. The system is provided by Chinese vendor Huawei, and is due to be launched before the end of 2010.

“We are developing some really exciting new security and parental control services, which will be based deep within our network infrastructure, to provide our customers with greater protection for all the devices they connect to their broadband line with,” said TalkTalk in a statement. “We’ve had considerable feedback from customers that PC-based software only deals with part of the wider security problem facing today’s Internet users, so we’ve developed these new services to help improve our customers online experience with us.”

Web-monitoring

Customers are currently not able to opt out of TalkTalk’s data collection project. As they browse the web, URLs are recorded and checked against a blacklist of sites known to be infected with malware, as well as a “whitelist” of sites that have been scanned for threats and approved in the last 24 hours.

Many people participating in the discussion on TalkTalk’s forum have likened the situation to BT’s secret trials of Phorm technology, which pledged to offer a similar filtering system alongside its controversial behavioural advertising service.

BT was forced to drop the technology in July last year, following a mass public outcry and threats from the European Commission that it would take legal action against the UK government over its failure to protect users from the software.

“Technologies like internet behavioural advertising can be useful for businesses and consumers but they must be used in a way that complies with EU rules. These rules are there to protect the privacy of citizens and must be rigorously enforced by all Member States,” said former EU telecoms commissioner Viviane Reding at the time.

Virgin Media faced similar outrage from privacy campaigners in November 2009, when it was found to be trialling new technology from Detica that would allow it to monitor file-sharing over the Internet. The trials were in response to a clause in the Digital Economy Bill – now the Digital Economy Act – which requires ISPs to combat illegal file-sharing over their networks.

No data stored

Despite the obvious privacy implications of this type of software, TalkTalk defended its decision to work with Huawei, claiming that its new system effectively just gathers an anonymous list of public website addresses.

“Our scanning engines receive no knowledge about which users visited what sites (e.g. telephone number, account number, IP address), nor do they store any data for us to cross-reference this back to our customers,” it said.

Charles Dunstone

Ironically, TalkTalk has recently become known as a champion of online privacy. Earlier this month, BT and TalkTalk called for a judicial review of the Digital Economy Act by the High Court, claiming that the measures to curb online copyright infringement did not receive sufficient scrutiny when the bill was passing through Parliament.

“Innocent broadband customers will suffer and citizens will have their privacy invaded,” said TalkTalk Group chairman Charles Dunstone at the time. “We think the previous government’s rushed approach resulted in flawed legislation.”

Sophie Curtis

View Comments

  • It is illegal, just like Phorm's BT Webwise was. My URL data is part of my private communication. They have no legal right to use it whatsoever, not without a warrant making them do it. My URL may have sensitive data like my date of birth or user ID embedded into it. They are not allowed to process it at all, not without my informed consent.

    Stop the STalking TalkTalk!!

  • From my website logs the URLs being used contain data which could allow Talktalk to access websites as if they the original authorised person. Attempts have been made here to access user's Private Message inboxes.

    There is also the question of using a website owner's copyright material for the commercial gain of Talktalk.

    The Stalkstalk system has also disobeyed robots.txt and tried to access Private areas of the website.

Recent Posts

EU Widens Investigations Into Chinese Imports, Subsidies

After the United States imposes 100 percent tariffs on certain Chinese goods, Europe widens its…

23 hours ago

Reddit Deal With OpenAI Gives ChatGPT Access To Content

OpenAI strikes deal with Reddit to train its AI tech on user posts and give…

1 day ago

Microsoft Invests 4 Billion Euros In France For AI, Cloud

Global spending spree from Microsoft continues, with huge investment for new data centre to drive…

1 day ago

Toshiba Axes 4,000 Staff In Post-Delisting Restructuring Operation

Workforce blow. Newly privatised Toshiba has embarked on a 'revitalisation plan' that will entail the…

2 days ago

European Union Opens Child Safety Probe Into Meta

European Commission opens an official child safety investigation into Facebook and Instagram-owner Meta Platforms

2 days ago