cross-posted from: https://covert.nexus/post/27235

The FTC released a staff report in 2021 analyzing the privacy practices of six major U.S. Internet Service Providers. The report found that these ISPs collect as much, if not more, data on their customers’ browsing habits than popular advertisers like Google and Facebook. Additionally, some of these ISPs either operate their own advertising businesses or sell the data to third parties, such as the NSA.

  • Peffse@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    Maybe I’m just not getting it, but if we’ve mostly transitioned to HTTPS and encrypted DNS… what exactly can the ISP learn other than the address they serve and MAC of your gateway? Is this report for those who use their ISP’s DNS?

  • Sunny' 🌻@slrpnk.net
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    Observations

    • Many ISPs in Our Study Amass Large Pools of Sensitive Consumer Data.
    • Several ISPs in Our Study Gather and Use Data in Ways Consumers Do Not Expect and Could Cause Them Harm.
    • Although Many ISPs in Our Study Purport to Offer Consumers Choices, These Choices are Often Illusory.
    • Many ISPs in Our Study Can be At Least As Privacy-Intrusive as Large Advertising Platforms.

    Oh how lovely…

    • Em Adespoton@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      And this is why you never ever use ISP DNS, run DNS over HTTPS in the browser, and always use encrypted networking.

      And use VPNs appropriate to the activity, when appropriate.

      Oh, and never turn on ISP-supplied WiFi, as that gives them full access to the traffic from every device on your LAN, what physical hardware you own, and even where it is located in your home (and when it leaves and comes back to your home).

      • inspxtr@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        never turn on ISP-supplied WiFi

        maybe I’m missing something here, how do you get access to the internet for all devices (mobiles, laptops, …) without wifi then?

        • jacksilver@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          You can get your own modem (what plugs into the wall) or your own wifi router (you’d plug this into the isp modem). Your own modem is better, but ISPs can give you grief about “supporting” them.

      • Sunny' 🌻@slrpnk.net
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        All good! It’s about the use of free VPNs and how they may impact user privacy and security. But I do mention that VPNs is a one of the reasons as to why some people choose to use them in the first place. And this is a good source to have as it shows exactly the reasons as to why people flee to VPNs (be it paid or free).

        Spoiler, in the majority of the cases free vpn’s are not good to use, but there isn’t too many documented articles on the topic, only some. So wanted to contribute on that field :)

  • MediaSensationalism@covert.nexusOP
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    This information, although not new, sheds light on the misconception prevalent even amongst industry professionals today that ISPs only retain customer usage data related to IP address assignment. If they were to sell browsing data with corresponding timestamps to government agencies, it could theoretically allow them to perform large-scale traffic correlation attacks on unsuspecting Tor and VPN users.

    • taladar@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      However VPNs are exactly the same as ISPs, especially when it comes to actions forced by the government in the jurisdiction they are in.

      • fishos@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Which is why good vpns are hosted in countries with extremely high privacy laws. And some can even be bought and used without giving any personal info. And why most vpns are RAM only and literally can’t log any records.

        But you knew this before you spouted off, right?

        • taladar@sh.itjust.works
          link
          fedilink
          arrow-up
          0
          ·
          7 months ago

          If you think your VPN provider is more immune to legal authorities than your ISP you are deluding yourself.

          • Scolding0513@sh.itjust.works
            link
            fedilink
            arrow-up
            0
            ·
            7 months ago

            if you think that every VPN in the world handles legal situations the same way regardless of jurisdiction then you are a total nonce

    • Rentlar@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      7 months ago

      Isn’t it great when the US’ FTC does something other than lick corporate boot?

      • pdxfed@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        Almost like presidential appointment powers matter! If only Democrats would have realized that before giving Trump 3 lifelong SCOTUS appointments.