Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Web Page Tracking

  • 17-06-2005 8:05pm
    #1
    Registered Users Posts: 316 ✭✭


    I'm with Eircom, Any idea how to trace what pages I have visited? I can see the bandwidth usage alright, But I'm interested in the actual sites?

    Or is it even possible?


«1

Comments

  • Closed Accounts Posts: 109 ✭✭pingoo


    Well in all theory in order to track down the sites visited you'll need a Proxy server which applies with Internal network for example like Microsoft ISA Server. I wouldn't say they can, even if they did it might represent far too much data


  • Closed Accounts Posts: 1,033 ✭✭✭beller b


    I think EIRCOM are more interested on what YOU would be uploading/donwloading using file sharing etc...................


  • Registered Users, Registered Users 2 Posts: 1,562 ✭✭✭Snaga


    Cant you use your browsers 'History' for that?


  • Registered Users, Registered Users 2 Posts: 2,299 ✭✭✭PixelTrawler


    does the eircom guardian product track this for parents to keep an eye on their kids usage - if so maybe you could use this


  • Closed Accounts Posts: 2,464 ✭✭✭Kristok


    yea i think its the history button your looking for, eircoms servers keep track of what youve been to but its only for their records incase your doing dodgy crap.


  • Advertisement
  • Moderators, Technology & Internet Moderators, Regional South East Moderators Posts: 28,501 Mod ✭✭✭✭Cabaal


    Kristok wrote:
    yea i think its the history button your looking for, eircoms servers keep track of what youve been to but its only for their records incase your doing dodgy crap.

    ...and the records are stored for 3 years...yipee!!


  • Registered Users, Registered Users 2 Posts: 9,472 ✭✭✭AdMMM


    Well then surely you can get a copy of their records under the Freedom of Information act...


  • Registered Users, Registered Users 2 Posts: 4,479 ✭✭✭wheres me jumpa


    just as a metter of interest, do eircom study everybodys history and report any dodgy dealings or is it a case of, if for example the guards, believe your up to no go, then your history will be consulted?


  • Registered Users, Registered Users 2 Posts: 9,472 ✭✭✭AdMMM


    just as a metter of interest, do eircom study everybodys history and report any dodgy dealings or is it a case of, if for example the guards, believe your up to no go, then your history will be consulted?
    the latter


  • Registered Users Posts: 316 ✭✭Mossess


    to be honest I've noticed some activity while I know the PC has been off. think someone may be patching in. Not interested in tracking them down, as was my own fault for not being secure enough, but would be interested to see what was visited for the heck of it.


  • Advertisement
  • Closed Accounts Posts: 1,033 ✭✭✭beller b


    Mossess wrote:
    to be honest I've noticed some activity while I know the PC has been off. think someone may be patching in. Not interested in tracking them down, as was my own fault for not being secure enough, but would be interested to see what was visited for the heck of it.
    Silly question.....when you turn your computer off why would you leave your modem/router on?


  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    beller b wrote:
    Silly question.....when you turn your computer off why would you leave your modem/router on?

    Most people do. Its a pain in the arse to be switiching them on and off they are designed for 24/7 on.


  • Registered Users, Registered Users 2 Posts: 804 ✭✭✭TimTim


    beller b wrote:
    Silly question.....when you turn your computer off why would you leave your modem/router on?


    Because its a seperate device meant to be left on constantly? Isn't that the whole point of a router so your not reliant on one pc being on constantly on to use the internet?


  • Registered Users Posts: 316 ✭✭Mossess


    beller b wrote:
    Silly question.....when you turn your computer off why would you leave your modem/router on?

    It's wireless and is off in another part of the house, it's a pain in the behind having to first go turn on the router, then boot up the PC. then do the reverse each time I shut down. The router stays on to save me buying new shoes from all the running around the house.


  • Registered Users, Registered Users 2 Posts: 22,231 ✭✭✭✭Sparky


    use your wireless security, and if you think someone has been patching in there should be some sort of log.

    AFAIK, to be really secure aswell as using WEP you can restrict computers to the router by mac address


  • Registered Users Posts: 316 ✭✭Mossess


    Have WEP running now, but still curous about the other connections when I know for a fact the PC has been off.


  • Registered Users, Registered Users 2 Posts: 4,003 ✭✭✭rsynnott


    Well then surely you can get a copy of their records under the Freedom of Information act...

    Well, assuming Eircom has become the government in a bloodless coup, then certainly. Otherwise no. It's a company.


  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    rsynnott wrote:
    Well, assuming Eircom has become the government in a bloodless coup, then certainly. Otherwise no. It's a company.

    Data Protection Act still applies and gives you rights to the data. (I think)


  • Registered Users Posts: 316 ✭✭Mossess


    Not bothered going down the DPA route, just thought there might be an easy way to get the data back. :cool:


  • Registered Users, Registered Users 2 Posts: 4,003 ✭✭✭rsynnott


    Rew wrote:
    Data Protection Act still applies and gives you rights to the data. (I think)

    I'm almost certain it doesn't; do you have a reference? The data protection act certainly applies, but that doesn't necessarily give you access (and in particular doesn't give you a right to ask for those records to be destroyed.)


  • Advertisement
  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    Depends a bit on the definition of personal information...

    http://www.dataprotection.ie/ViewDoc.asp?fn=/documents/rights/2.htm&CatID=16&m=r
    Right of Access

    The personal information to which you are entitled is that held on computer or in a manual filing system that facilitates access to information about you. You can make an access request to any organisation or any individual who has personal information about you. For example, you could make an access request to your doctor, your bank, a credit reference agency, a Government Department dealing with your affairs, or your employer. [view more...]

    Right of rectification or erasure and blocking

    If you find out that information kept about you by someone else is inaccurate, you have a right to have that information corrected (or "rectified"). In some circumstances, you may also have the information erased altogether from the database - for example, if the body keeping the information has no good reason to hold it (i.e. it is irrelevant or excessive for the purpose), or if the information has not been obtained fairly. You can exercise your right of rectification or erasure simply by writing to the body keeping your data.

    In addition, you can request a data controller to block your data i.e. to prevent it from being used for certain purposes. For example, you might want your data blocked for research purposes where it held for other purposes.


  • Registered Users, Registered Users 2 Posts: 4,003 ✭✭✭rsynnott


    Okay, on the face of it, that looks like it'd give you access, and possibly even right to delete. But, http://www.dataprotection.ie/viewdoc.asp?m=r&fn=/documents/rights/2di.htm

    Point 1 could apply; the major reason this data is held in the first place is to leave a paper trail for fraud, child porn etc. investigations. Not sure about that one.

    Point 3; similar to point 1; knowing exactly what had been recorded about their internet activity could potentially assist a criminal in establishing plausable deniability.

    Point 7; a lot of data retained by ISPs falls under this category; it's there for the purpose of predicting usage patterns.

    And finally, and I think this is the big one: the "Disproportionate effort" (an to an extent the Repeated Access Reqeusts; you could probably only do this once) section. Collating and sending all that data to everyone who made a request would be no joke.

    In any case, do ISPs retain this sort of data habitually, in this country? They certainly retain IP-address to phone number over time mappings, but I'm not sure that they retain HTTP traffic details.


  • Hosted Moderators Posts: 7,486 ✭✭✭Red Alert


    it's unlikely that they retain http traffic info. if they're not using a transparent proxy which IBB doesn't seem to anyway then there's nothing other than a traffic analyser which would need serious horsepower for a whole ISP.


  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    The ISP's and Telcos (O2 etc) are retaining huge amounts of data. There stuck in that they don't know if they legally have to and they don't know if the legally can keep it. European law was going to insist on massive data retension but people pointed out how un-workable it would be. Its all a bit in limbo now AFAIK.

    As for the current disscusion. Delation is not an issue, nobody said in any post they wanted to deleate data. As for criminal establishing plausable deniability, they are entitled to see any evidence against them when building a leagal defence so its not really an issue. Under the data protection act if you hold data on sombody you have to state the purpose. So if they hold it for predicting usage patterns they cannt use it for other things unless they add it to the list of reasons. This protects people who agree to allow their data to be used for one thing, thats the only thing it can be used for.


  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    Red Alert wrote:
    it's unlikely that they retain http traffic info. if they're not using a transparent proxy which IBB doesn't seem to anyway then there's nothing other than a traffic analyser which would need serious horsepower for a whole ISP.

    How would you know if they were or weren't useing a transparent proxy if it were transparent? ;)

    There is plenty of industrial strenth telco kit out there for these types of application.


  • Registered Users, Registered Users 2 Posts: 4,003 ✭✭✭rsynnott


    Rew wrote:
    As for the current disscusion. Delation is not an issue, nobody said in any post they wanted to deleate data. As for criminal establishing plausable deniability, they are entitled to see any evidence against them when building a leagal defence so its not really an issue.


    Really? "Oh, goodness, I'm accidentally clicking on the "no WEP" option on my wireless router. I CERTAINLY hope no-one does naughty illegal things on it!"

    And unless there is a law requiring such data retention, they're probably not doing it; it would be horrifically expensive and it would certainly not cover HTTPS (where an SSL tunnel is established between the client and server).


  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    rsynnott wrote:
    Really? "Oh, goodness, I'm accidentally clicking on the "no WEP" option on my wireless router. I CERTAINLY hope no-one does naughty illegal things on it!"

    Actually i suggested that as a defence against file sharing law suits and there hav been successfully cases else where, where sombodys PC was so Trojan/Virus riddled that offences committed using their PC/Net Connection couldn't be proved.
    And unless there is a law requiring such data retention, they're probably not doing it; it would be horrifically expensive and it would certainly not cover HTTPS (where an SSL tunnel is established between the client and server).

    I didn't saw there wasn't a law jsut that the situation is very unclear. They do retain data for security reasons. To what level I dont konw but id say its quite detailed.


  • Registered Users, Registered Users 2 Posts: 4,003 ✭✭✭rsynnott


    Rew wrote:
    I didn't saw there wasn't a law jsut that the situation is very unclear. They do retain data for security reasons. To what level I dont konw but id say its quite detailed.

    I'd say the data is limited to matching phone numbers to IPs. (Which is perfectly reasonable, as it assists in tracing child porn users and such). There'd be no real POINT to recording HTTP requests; anything dodgy would generally be done over HTTPS anyway, and there's no way to see what's in a HTTP request short of a man in the middle attack (which is illegal). They'd be able to show that John Smith established an SSL connection of some sort to apossiblydodgywebsite.com, but that's it. And I really can't see how this could be done economically anyway; they do have a web monitoring thing in the US (Carnivore) but it's a very expensive federally funded project, and even it only considers certain types of traffic, on certain people; it's not a blanket monitoring system like you suggest.


  • Hosted Moderators Posts: 7,486 ✭✭✭Red Alert


    À transparent proxy is generally a giveaway when you enter a dud site - in it's default config both Squid and Microsoft ISA make up their own error messages for invalid URLS. Which means if they are using one, why hide it?

    That amount of data seems dodgy - i really don't like the idea of big brother eircom (who'd probably sell it for marketing purposes) if they could or IBB (who are just downright incompetent they'd probably leave it lying in a street or something) having all that.


  • Advertisement
  • Moderators, Sports Moderators Posts: 8,679 Mod ✭✭✭✭Rew


    rsynnott wrote:
    I'd say the data is limited to matching phone numbers to IPs. (Which is perfectly reasonable, as it assists in tracing child porn users and such). There'd be no real POINT to recording HTTP requests; anything dodgy would generally be done over HTTPS anyway, and there's no way to see what's in a HTTP request short of a man in the middle attack (which is illegal). They'd be able to show that John Smith established an SSL connection of some sort to apossiblydodgywebsite.com, but that's it. And I really can't see how this could be done economically anyway; they do have a web monitoring thing in the US (Carnivore) but it's a very expensive federally funded project, and even it only considers certain types of traffic, on certain people; it's not a blanket monitoring system like you suggest.

    They are in the middle so can sniff data no problem. Carnivore monitered alot more then the web. I didn't suggest it was blanket monitoring its up to indvidual telcos to do the logging they see fit.


Advertisement