5 ms·
Legit question: What can an ISP collect when most of the time I'm going to secure "https:" websites? I mean, they can only see the website I'm going to, but not
by GoofballJones 2y ago
Legit question: What can an ISP collect when most of the time I'm going to secure "https:" websites? I mean, they can only see the website I'm going to, but not what is going on there, right?
Is just collecting where people are going that lucrative to sell?
- lordofgibbons 2y agoThere's what websites/apps you use, but also your behavior patterns. Are you a night owl? How often do you check some website or app. I'm sure there's a lot of other information they do gather based on the "metadata"
- agieocean 2y agoThat + other data can be used to build a behavorial profile so it's not what your ISP is doing necessarily but what the people they sell the data to are doing with it (or the people they sell to)
- eptcyka 2y agoDNS records and net flow data. They can also inject JS in http sites, hijack domaijs to do the same, do traffic shaping. But I am biased, I work for a VPN company.
- 112233 2y agoNot what they can, what they MUST as required by law. Assuming US, see DTA aka CALEA - at any time little green men with a warrant can ask for tranparrent packet capture of ISP client's traffic. Also, in many places (Europa) there is collection and retention requirements for ISPs.
- Spooky23 2y agoThe DNS data is super useful for developing a demographic profile. For example, they could pretty trivially assert with high confidence that a pregnant woman is in your home or that you’re shopping for a car. The tinfoil hat scenarios are interesting as well.