NebuAd explained

NebuAd, Inc.
Type:Privately held Company
Location:California, United States
Key People:Robert Dykes, Chairman, founder. Kira Makagon Chief Executive Officer and co-founder.[1]
Foundation:2006
Defunct:2009
Industry:Online advertising

NebuAd was an American online advertising company based in Redwood City, California, with offices in New York and London and was funded by the investment companies Sierra Ventures and Menlo Ventures.[2] It was one of several companies which originally developed behavioral targeting advertising systems, and sought deals with ISPs to enable them to analyse customer's websurfing habits in order to provide them with more relevant, micro-targeted advertising.[3] Phorm was a similar company operating out of Europe. Adzilla and Project Rialto also appear to be developing similar systems.

At one point, NebuAd had signed up more than 30 customers, mostly Internet access providers, its agreements with providers covered 10 percent of the broadband users in America.[4] Due to fallout following public and Congressional concern, NebuAd's largest ISP customers pulled out. NebuAd closed for business in the UK in August 2008, followed by the US in May 2009.[5] NebuAd UK Ltd was dissolved in February 2010.[6]

Overview

NebuAd's platform comprised three main parts: hardware, hosted within an ISP, capable of inserting content into pages, an off-site server complex to analyse and categorise the contents of users' Internet communications, and relationships with advertising networks willing to present NebuAd's targeted advertising.[7]

The system consisted of hardware device installed within an ISP client network. Each device was capable of monitoring up to 50,000 users.[8] Users could "opt-out" of NebuAd's information collection and targeted ads,[9] but there was no way for users to prevent ISPs from sending the data to NebuAd in the first place.[10]

Since ISPs route customers' traffic, it is an important vantage point from which to monitor all traffic to-and-from a consumer using Deep packet inspection (DPI). By analysing the traffic, NebuAd reported it gained more information about a customer's particular interests, than less intrusive methods.[11] NebuAd's privacy policy claimed they "specifically not store or use any information relating to confidential medical information, racial or ethnic origins, religious beliefs, or sexuality, which are tied to personally identifiable information ('sensitive personal information')." It also advises, "The information we collect is stored and processed on NebuAd's servers in the United States. As a result, that information may be subject to access requests by governments, courts or law enforcement."

At least 2 customers of a middle America ISP, WOW! noticed unexpected cookies appearing for sites such as nebuad.adjuggler.com, after using Google, which were being read and written, but when WOW's support department was contacted, WOW initially denied responsibility for the activity. After noticing problems with Google loading slowly, and the creation of these non-Google cookies, one customer spent hours trying to disinfect his machine, as he incorrectly thought it had been infected with spyware, but, when this proved ineffective, he resorted to reinstalling his machine's OS from scratch, only to discover the problem did not go away.

On July 9, 2008, WOW suspended the use of NebuAd services to its subscribers.

According to NebuAd's sales, less than 1% of users opt-out. One ISP expected to earn at least $2.50 per month for each user.[12]

NebuAd bought impressions from ad networks including Valueclick.[13]

NebuAd argued that behavioral targeting enriches the Internet on several fronts. Firstly, website owners are offered an improved click-through rate (CTR), which could increase profits, or reduce the amount of page-space dedicated to advertising. Owners of previously thought ad-unfriendly websites were offered a chance to make money not on the subject matter of their website, but on the interests of their visitors.

Advertisers were offered better targeted adverts, hence reducing the "scattergun approach" (publishing as many ads as possible, in the hope of catching a client) and users were offered more relevant adverts.

ISPs were paid for allowing NebuAd access to their network on a per-user per-active profile basis.

NebuAd used data such as Web search terms, page views, page and ad clicks, time spent on specific sites, zip code, browser info and connection speed to categorise a user's interests.[14] NebuAd did not have access to user identification information from the ISP, but may have been able to discover this through traffic monitoring (for example, email traffic may tie an email address to an ip address). Bob Dykes, the NebuAd CEO claimed in 2008; "We have 800 [consumer interest segments] today and we're expanding that to multiple thousands".[15]

Controversies

Generally, NebuAd provided an additional revenue to network operators, which may maintain or lower consumers' Internet access bills. Critics of DPI and targeted advertising believe the raw content of their internet communications are entrusted to the ISP for handling without being inspected, or modified, nor for sale.[16] Privacy advocates criticize the lack of disclosure[17] which some ISPs provided, prior to partnering with NebuAd, was a weak opt-out method, the lack of oversight over what any third-party company does with the contents of Internet communications,[18] its conflicts with United States wiretap laws, and the company's refusal to name its partner ISPs.

Consumer notification

In February 2008, one American cable operator, Wide Open West (WOW) started rolling out NebuAd. The roll-out was completed in the first week of March 2008. WOW updated its terms and conditions to include a mention of NebuAd,[19] and in some cases informed customers of the terms having been updated. However, customers were not explicitly notified about NebuAd until later, sometime after the third week of March 2008.[20]

In response to an inquiry from members of the United States House of Representatives Telecommunications Subcommittee about its pilot test of NebuAd's services,[21] Embarq said it had notified consumers by revising its privacy policy 2 weeks prior to sending its users' data streams to NebuAd.[22]

A Knology user in Knoxville, Tennessee reported she was not notified her Internet use was being monitored.[23]

In May 2008, Charter Communications announced it planned to monitor websites visited by its customers via a partnership with NebuAd.[24] [25] But after customers voiced their concerns, Charter changed its mind in June.[26]

Friction between ISP staff and management

Plans to implement NebuAd did not agree with some ISP's employees, including one employee was planned to re-route his traffic to avoid NebuAd's Deep Packet Inspection hardware, altogether.

Opt out vs. opt in

Members of US Congress, Ed Markey, chairman of the House Subcommittee on Telecommunications and the Internet, and Joe Barton, a ranking member of the House Committee on Energy and Commerce, have argued that such services must be opt-in only to comply with the provisions laid down by Section 631 of the US Communications Act, and they wrote to Charter to request them to suspend the test: "We respectfully request that you do not move forward on Charter Communications' proposed venture with NebuAd until we have an opportunity to discuss with you issues raised by this proposed venture."[27]

A writer for Wired News questioned whether Charter users could really opt out of being monitored or if they were able to opt out only of receiving targeted ads.[28] The same writer has asked if it would breach anti-wiretapping laws.

An engineer who examined the system confirmed there was no way to opt out of NebuAd's monitoring.[29] All inbound and outbound information was intercepted and sent to NebuAd's offsite server to be processed. Even if a user had opted out of the service, it did not prevent the ISP from sending the data to NebuAd.

Use of packet forgery and browser exploits

A report by Robert M. Topolski, chief technology consultant of the Free Press and Public Knowledge, showed NebuAd's devices created cookies on end-users machines by injecting a specious packet into the end of the data stream returned in response to some web page requests submitted to search engines, including Google and Yahoo. The content of this specious packet, which would be added to the end of the web page when it is rendered by the end-user's browser, contained HTML script tags which cause the browser to request Javascript from ____.[30]

Superimposing or adding advertising to webpages

Critics were concerned that NebuAd superimposed its own advertising over the ads of other advertisers, or placing additional advertising to a page. These concerns originated o the NebuAd's "Fair Eagle" operation, patent application data which mentioned such inventions, and a loose relationship to Claria Corporation whose products and history suggest such tactics, as well as by the following:

In 2007 it was reported that Redmoon, a Texas-based ISP was using a NebuAd technology to inject Redmoon's own advertising into pages visited by its users.[31] The "Fair Eagle" advertisement hardware, provided by NebuAd, inserted additional advertising alongside the content of web pages. The ads featured a window with the "Fair Eagle" title bar. The injected ads stopped appearing toward the end of June, 2007.[32]

Relationship with Claria Corporation

Some senior staff members of NebuAd had worked previously at a (now defunct) ad company, named Claria Corporation (formerly, the Gator Corporation), which was well known for ad software known as Gator.[33] Both Claria and NebuAd were located in Redwood City, California. The June 2006 creation[34] of nebuad.com coincides with timing of Claria's decision to shut down[35] the Gator service. NebuAd repeatedly denied any corporate connection to Claria, describing its hiring of Claria employees as a result of that company shedding employees in a tight market for experienced advertising sales staff in the Valley.

ISP partners

ISPs that tried out or deployed or prepared to deploy Nebuad included the following:

The following ISPs are listed in legal documents[43] related to the class action notice (see below) as having deployed NebuAd hardware:

All ISPs ended or suspended their relationship with NebuAd.

Closure

NebuAd was closed down in the UK in August 2008 and in the US in May 2009.

Class-action lawsuit

A proposed settlement for a class-action lawsuit against NebuAd was underway in October 2011. All subscribers to the ISPs listed above between January 1, 2007, and July 1, 2008, were to be considered mandatory class members and so did not have to opt in and could not choose to opt out. Under the terms of the proposed settlement, NebuAd would create a settlement fund of approximately $2,410,000, to be used for administration of the settlement, covering legal fees, an incentive award of $5,000 to the individual who brought the complaint, providing up to $1000 for other named representatives, with most of the money going to support non-profits providing consumer education and privacy research.

External links

Notes and References

  1. News: NebuAd CEO quits. The Register . 2008-09-03 . 2008-09-04.
  2. Web site: Management & Investors. 2008-04-26. dead. https://web.archive.org/web/20080502215808/http://www.nebuad.com/company/management.php. 2008-05-02.
  3. News: American ISPs already sharing data with outside ad firms. The Register . 2008-04-10 . 2008-04-18.
  4. News: Every Click You Make. washingtonpost. 2008-04-04 . 2008-05-14 . Peter . Whoriskey.
  5. Web site: Case Closed: NebuAd Shuts Down . MediaPost . 2009-06-18 . 2010-08-06 . https://web.archive.org/web/20101108114826/http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=106277 . 2010-11-08 . dead .
  6. "http://wck2.companieshouse.gov.uk/c3aac31df2e47117900ab23b5d4530e6/companysearch?disp=1&frfsh=1281110903#result"UK Companies House website
  7. Web site: Juniper Networks partners with NebuAd to enable ISPs to participate in online advertising revenues on the web . 2008-06-28 . juniperamspmarketing.com . https://web.archive.org/web/20080713030851/http://www.juniperamspmarketing.com/NebuAD.htm . 2008-07-13.
  8. News: NebuAd Observes 'Useful, but Innocuous' Web Browsing. The New York Times. 2008-04-07. 2008-04-18. Saul. Hansell. https://web.archive.org/web/20080411020036/http://bits.blogs.nytimes.com/2008/04/07/nebuad-observes-useful-but-innocuous-web-browsing/. 2008-04-11. dead.
  9. Web site: NebuAd / Privacy . 2008-06-28 . dead . https://web.archive.org/web/20080611102442/http://www.nebuad.com/privacy/servicesPrivacy.php . 2008-06-11 .
  10. Congressmen Ask Charter to Freeze Web Profiling Plan . Singel . Ryan . 2008-05-16 . Threat Level from Wired.com .
  11. Web site: Robert Dykes (CEO) presenting NebuAd at OnMediaNYC-01/28/2008 . https://archive.today/20120722060619/http://vator.tv/pitch/show/transforming-online-ad-industry?play=false . dead . July 22, 2012 . 2008-02-18 . vator.tv . 2008-07-03 .
  12. Web site: Infighting At ISPs Over Using NebuAD. Broadband Reports. 2008-05-28. Bode . Karl .
  13. Web site: Questions for Bob Dykes, NebuAd CEO. clickz. 2008-01-03. 2008-05-14. https://web.archive.org/web/20080419011030/http://www.clickz.com/showPage.html?page=3628009. 2008-04-19. dead.
  14. Web site: Charter Cable to Spy on its Broadband Users to Serve Targeted Ads via NebuAd. Digital Destiny. 2008-05-14. 2008-05-14. dead. https://web.archive.org/web/20080517172521/http://www.democraticmedia.org/jcblog/?p=586. 2008-05-17.
  15. Web site: ISPs Collect User Data for Behavioral Ad Targeting. ClickZ. 2008-01-03. 2008-05-14. https://web.archive.org/web/20080612182415/http://www.clickz.com/showPage.html?page=3628004. 2008-06-12. dead.
  16. Web site: CDT Urges Stronger Guidelines for Behavioral Advertising . 2008-06-12 . 2008-06-19 . dead . https://web.archive.org/web/20080905204536/http://www.cdt.org./headlines/1126 . September 5, 2008 .
  17. Web site: Wide Open West Using NebuAD Users don't get much of a heads up... . 2008-03-11 .
  18. Web site: ISP Data Collection — Congress Investigation Urged (NebuAd-CDT Press Release) . 2008-06-20 . 2008-06-06 .
  19. Web site: WOW Terms and Conditions . 2008-04-30 . https://web.archive.org/web/20080414150154/http://www1.wowway.com/wow/wow.aspx?ConIdent=28&RCView=False&TermID=11#TPA . 2008-04-14 . dead .
  20. News: Data pimping catches ISP on the hop. The Register. 2008-04-22 . 2008-04-23 .
  21. Web site: Congress goes after NebuAd... again . 2008-07-15 . Anderson . Nate . ArsTechnica.com .
  22. Web site: Customers Shoulda Read the Privacy Policy, Says Embarq . 2008-07-23 . MarketingVOX: The Voice of Online Marketing . dead . https://web.archive.org/web/20110714041114/http://www.marketingvox.com/embarq-pleads-the-fifth-on-disclosing-nebuad-test-to-customers-040002/ . 2011-07-14 .
  23. Web site: Ready — Fire — Aim: NebuAd and Charter Shellacked -- Right Idea, Wrong Targets . 2008-07-21 . Topolski, Robb . Public Knowledge Policy Blog . dead . https://web.archive.org/web/20080804010535/http://www.publicknowledge.org/node/1664 . 2008-08-04 .
  24. News: Charter Will Monitor Customers' Web Surfing to Target Ads . The New York Times . Saul . Hansell . 2008-05-14 . 2010-05-20.
  25. Web site: Charter wants to track users and replace online adverts - The INQUIRER. May 16, 2008. https://web.archive.org/web/20080516010458/http://www.theinquirer.net/gb/inquirer/news/2008/05/14/charter-track-users-replace. 2008-05-16.
  26. News: The Associated Press. Charter Won't Track Customers' Web Use. June 25, 2008. via The New York Times Company. 2008-06-29.
  27. News: US Congress questions legality of Phorm and the Phormettes. The Register. Cade . Metz. 2008-05-16. 2008-05-17.
  28. Can Charter Broadband Customers Really Opt-Out of Spying? Maybe Not. Wired. Ryan . Single. 2008-05-16. 2008-05-17.
  29. Web site: Embarq: Don't all users read our 5,000 word privacy policy? . Anderson . Nate . 2008-07-23 . ArsTechnica.com . He points out that the system is essentially a massive bridge running Fedora, and that NebuAd advises ISPs to install it inline in their networks in such a way that all web traffic passes through it... opted out or not. As the engineer explains, "When we asked them about an opt-out method for our customers, they didn't have one. And unless they alter the architecture of their system drastically, they won't ever have one. Their system is a bridge, so you would need some sort of magical layer-two switching device upstream that switched frames from users that have opted out around the NebuAd appliance. How would you build a device like this without profiling your users in the first place to determine who had opted out? It's not like there is an opt-out bit you can flip in the header of an Ethernet frame." Therefore, while the data actually created and stored by NebuAd or Embarq might end up being totally anonymous and innocuous, everyone's data is still pumped into a third-party box. .
  30. Web site: NebuAd and Partner ISPs: Wiretapping, Forgery and Browser Hijacking. Free Press. Robert. Topolski. 2008-06-18. 2008-06-19. dead. https://web.archive.org/web/20080919204720/http://www.freepress.net/files/NebuAd_Report.pdf. 2008-09-19.
  31. Web site: Real Evil: ISP Inserted Advertising. Techcrunch. 2007-06-23 . 2008-04-26.
  32. Web site: benanderson.net-Fair Eagle taking over the world? ISPs being compromised or just cheap? . 2007-06-22 . 2008-06-19 . dead . https://web.archive.org/web/20071021061511/http://benanderson.net/blog/weblog.php?id=D20070622 . 2007-10-21 .
  33. Web site: NebuAd looks to 'spyware' firm for recruits . 2008-06-20 . The Register . 2008-06-20 .
  34. Web site: Whois Lookup Captcha. whois.domaintools.com.
  35. Web site: Claria Abandons Adware . TechWeb Technology News . Keizer . Gregg . Claria will exit out of the adware business by the end of the second quarter of 2006. . dead . https://web.archive.org/web/20070105194603/http://www.techweb.com/wire/security/183701933 . 2007-01-05 .
  36. Web site: Broadstripe High Speed Internet Online Privacy Policy. 2008-05-14 . https://web.archive.org/web/20080224042248/http://www.broadstripe.com/terms/privacypolicy.htm . 2008-02-24.
  37. Web site: One More ISP to add to the list of ISPs . 2008-06-26 . BroadbandReports.com . 2008-06-26 .
  38. Web site: And Even One More ISP to add to NebuAds Harem . 2008-06-26 . BroadbandReports.com . 2008-06-26 .
  39. Web site: Metro Provider Privacy Policy. dead. https://web.archive.org/web/20080507191028/http://metroprovider.com/privacy_policy.html. 2008-05-07.
  40. Web site: OnlyInternet.Net uses NebuAd for Behavioral Targeting . 2008-06-26 . BroadbandReports.com . 2008-06-26 .
  41. Web site: RTC on Line aka Rochester Telephone Company sells to NebuAd . 2008-06-26 . BroadbandReports.com . 2008-06-26 .
  42. Web site: 20/20 Communications and NebuAd . 2008-06-26 . BroadbandReports.com . 2008-06-26 .
  43. Web site: of Pendency of Class Action and Proposed Settlement in the U.S. District Court, Northern District Of California — Valentine, et al. v. NebuAd, Inc., No. 3:08-cv-05113 (TEH)(EMC). . 2011-10-24 . live . https://web.archive.org/web/20140525180344/http://www.nebuadsettlement.com/Documents/NAV0001/NAV_NOT.pdf . May 25, 2014 .
  44. News: Charter Will Monitor Customers' Web Surfing to Target Ads. https://archive.today/20130104055145/http://bits.blogs.nytimes.com/2008/05/14/charter-will-monitor-customers-web-surfing-to-target-ads/index.html?ref=business. dead. 2013-01-04. The New York Times. 2008-05-14. 2008-05-14. Saul. Hansell.
  45. Web site: Charter User Monitoring Plans Suspended - 'Enhanced user experience' apparently not so enhanced.... . 2008-06-25 . Bode . Karl . 2008-06-24 . BroadbandReports.com .
  46. Web site: ISP Behavioral Targeting Versus You . 2008-09-26 .
  47. Web site: ISPs still considering tracking Web use . 2008-06-25 . Salon.com . 2008-06-25 . Svensson . Peter .
  48. News: Watching What You See on the Web . The Wall Street Journal. 2007-12-06 . 2008-05-21 . Bobby . White.
  49. Web site: CenturyTel and NebuAd . 2008-06-27 . BroadbandReports.com . 2008-05-28 .
  50. Web site: CenturyTel Drops NebuAd . 2008-06-27 . BroadbandReports.com . 2008-06-27 .
  51. News: Bresnan actively intercepting ALL packets . 2008-06-18.
  52. Web site: Bresnan — Internet Privacy Update . 2008-07-01 . 2008-07-01 . John Linko (Blog) .
  53. Web site: Blackfoot Telecommunications Group, Inc. Missoula MT Nebuad . 2008-06-30 . BroadbandReports.com . 2008-06-26 .
  54. Web site: Nexicom Privacy Policy . 2008-07-02 . Beginning April 23rd, we will partner with a third party to deliver or facilitate delivery of advertisements to our users while they are surfing on the web. These advertisements will be based on those users' anonymous surfing behavior while they are online. This anonymous information will not include those users' name, email address, telephone number, or any other personally identifiable information. By opting out you will continue to receive advertisements as normal; except these advertisements will be less relevant and less useful to you. If you would like to opt out, click here. (links to http://www.nebuad.com/privacy/optout.php page) .
  55. Web site: Nexicom is using Nebuad . 2008-07-03 . Canadian Broadband Forum on BroadbandReports.com .
  56. Web site: WOW! Suspension of Nebuad Services . 2008-07-03 . DSLReports.com Forums — US Cable Support — W.O.W. . prack .
  57. Web site: Broadstripe Now Selling User Browsing History, Joins growing list of NebuAD customers . 2008-06-25 . BroadbandReports.com . 2008-05-14 .
  58. Web site: 2008-07-21 . 9. Third Party Advertisers. Knology will partner with a third party to deliver or facilitate delivery of advertisements to our users while they are surfing the web. These advertisements will be based on those users' anonymous surfing behavior while they are online. This anonymous information will not include those users' name, email address, telephone number, or any other personally identifiable information. By opting out, You will continue to receive advertisements as normal; except these advertisements will be less relevant and less useful to you. If You would like to opt out, go to: http://nebuad.com/privacy/optout.php . Knology Customer Service Agreement . dead . https://web.archive.org/web/20080703203208/http://support.knology.net/content/custService_agree_121207.pdf . 2008-07-03 .
  59. Web site: RE: Internet Advertising Inquiry . 2008-08-11 . Johnson, Rodger; CEO and Chairman of the Board, Knology, Inc. . Committee on Energy and Commerce — US House of Representatives . 2008-08-08 . dead . https://web.archive.org/web/20080829100543/http://energycommerce.house.gov/Press_110/Responses%20to%20080108%20TI%20Letter/110-ltr.080108responseKnology.pdf . 2008-08-29 .
  60. News: Jesdanun, Anick. 6 Internet providers disclose Web tracking for ads. August 31, 2008. Associated Press via Google. 2008-09-01.
  61. Web site: Ji, Philip P.. Letter, from Responses to August 1, 2008 Letters to Network Operators Regarding Data Collection Practices. PDF via Google HTML. Committee on Energy and Commerce, U.S. House of Representatives. 2008-09-01. dead. https://web.archive.org/web/20080829100350/http://energycommerce.house.gov/Press_110/Responses%20to%20080108%20TI%20Letter/110-ltr.080108responseCABLE001.pdf. August 29, 2008.
  62. News: Jesdanun, Anick . Ad targeting based on ISP tracking now in doubt . September 1, 2008 . Associated Press via Google . 2008-09-01 . dead . https://web.archive.org/web/20080904213950/http://ap.google.com/article/ALeqM5hojy5UugX8vlpZa1urv5KYVDHDjAD92TSRNG0 . September 4, 2008 .